hi John,

Thank you for your checking and voting.

Per your comments, we want to confirm with you before we take action,
Please correct us if we still not right, Thanks.


====
On mine I get 3 files failing

Unapproved licenses:

  DEPENDENCIES
  griffin-doc/service/postman/griffin.json
  griffin-doc/service/postman/griffin_environment.json

[Comments by William]:
we will exclude all these three files explicitly in build section of pom

Doing what I assume is the same thing as Matt (mvn apache-rat:check from
the source release folder) . In addition to what he's noted, the year in
your NOTICE file should be updated to 2018.  The resulting output files
need a little bit of work:

[Comments by William]:
we will update 2017 as 2018



- measure's JAR shows the notice for Avro.  It also packs in additional
dependencies that are not apache licensed (they're all Cat B so they're
fine).  In the next release, please create dedicated NOTICE and LICENSE
files for this JAR.

[Comments by William]:
we will create a dedicated dependencies LICENSE file for measure jar.

- Similar issues exist in the service JAR, where the spring boot JAR
includes many other dependencies, some of which carry their own NOTICE
(Jackson, Tomcat) or other licenses.  What's harder is that you're using
Hibernate, which is an LGPL Cat-X dependency and cannot be included in the
JAR.  This is going to have to come out.


[Comments by William]:
we will create a dedicated dependencies LICENSE file for service jar.

For Hibernate, I am not an expert for license issue,

Are you saying

we can use hibernate for source code but need to exclude from deliver jar?
Or
We can NOT use hibernate as JPA provider, we need to use another license
compatible provider like eclipselink?



- The resulting output from your UI build should have licenses in place for
font awesome, glyphicons.  I'm not sure whats in your vendor.min.js but
based on your node_modules you may need to call out additional
license/notice contents.

[Comments by William]:
we will create a dedicated dependencies LICENSE file for UI jar.


====


Thanks,
William

Reply via email to