[ 
https://issues.apache.org/jira/browse/HDDS-5230?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17786087#comment-17786087
 ] 

Wei-Chiu Chuang commented on HDDS-5230:
---------------------------------------

I produced a thirdparty library license report (using mvn 
license:aggregate-add-third-party)

Looks to me almost fine with one exception: SpotBugs is LGPL. In the best case, 
we can only include it in provided scope. But we do have a number of compile 
time inclusion of SpotBugs and it's unacceptable.

> Select best licenses for each dual licensed dependencies
> --------------------------------------------------------
>
>                 Key: HDDS-5230
>                 URL: https://issues.apache.org/jira/browse/HDDS-5230
>             Project: Apache Ozone
>          Issue Type: Bug
>            Reporter: Justin Mclean
>            Assignee: Wei-Chiu Chuang
>            Priority: Blocker
>         Attachments: THIRD-PARTY.txt
>
>
> As [~jmclean]  [reported on the mailing list 
> |https://lists.apache.org/thread.html/rb2bbf79cf136b1c129ff7205e319223c2a780af49ed270031d676ce2%40%3Cdev.ozone.apache.org%3E]:
> bq. I notice a number of dependancies are licensed under " BSD License or the 
> GNU General Public License (GPL) Version 2.", when something is dual licensed 
> you can pick the most favourable one. Currently it's a little hard to 
> determine if this code may contain anything with a Category X license because 
> of the inclusion to the GPL license text.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to