Hi Justin,

Thank you for the thorough review and the binding -1. We confirmed
each item on the current RC.

1) PathMap.js is Snap.svg code under an ASF header

Confirmed. saga/seata-saga-statemachine-designer/src/render/PathMap.js
starts with the ASF header. The original file had "copied and adjusted
from" Snap.svg src/svg.js; #7145 removed that line and left the ASF
header. Source NOTICE has no Snap.svg line. Third-party code must keep
the upstream header. We will restore it, paths-ignore the file in
licenserc, and copy the first line of Snap.svg NOTICE into ours.

2) Docker Hub published 2.7.0 before the vote; latest retargeted

Confirmed. apache/seata-server:2.7.0, 2.7.0.jdk17/21/25, and latest
were pushed 2026-09-05, before the 6 September community vote. CI
publish-docker.yml runs release-image on every *.*.* branch push.
We will remove the unreleased tags, point latest back to 2.6.0, and
stop that workflow from publishing release tags before the vote
passes.

3) Binary LICENSE line 787 maps babel-plugin-macros to the wrong file

Confirmed. Line 787 is:

  babel-plugin-emotion/node_modules/babel-plugin-macros 2.8.0 MIT
  see licenses/babel-plugin-emotion-MIT

macros is MIT, but that file is emotion's license text. We will
point it at macros' own MIT file.

4) Binary NOTICE reproduces the Apache License 2.0 terms in three places

Confirmed. distribution/NOTICE (copied into the binary root NOTICE)
embeds the full AL2 grant under fastjson-1.2.83, context-propagation,
and the micrometer jars. NOTICE should keep attribution only. We will
drop the license-term blocks and leave the copyright lines.

I have also sent a [CANCEL][VOTE] message for this thread. We will
rebuild, re-sign, and restart the vote after fixing these issues.
Thank you again. If you have any other issues, please reply here.

Best regards,
Minghua

Reply via email to