adityamparikh opened a new pull request, #245:
URL: https://github.com/apache/solr-mcp/pull/245

   ## Summary
   Generates the "all items depended upon by the project are covered by 
approved licenses" row of the Incubator IP-clearance status document from the 
CycloneDX SBOM, and documents how and where it shows up. The row has to be 
refreshed for every release, so it is built, not hand-written.
   
   - **`generateIpClearanceLicenseReport`** (new) writes 
`build/generated/license/ip-clearance-licenses.xml`: a single `<tr>` in the 
format used by Incubator IP clearance documents (completion date, the standard 
checklist wording, a `<ul>` of `group:artifact — license` for every bundled 
dependency). It uses the same inputs as `generateBinaryLicense`: the shipped 
`productionRuntimeClasspath` and the SBOM. A dependency missing from the SBOM 
fails the task.
   - **`generateLicenseDocs`** (new aggregate) runs `generateBinaryLicense`, 
`generateBinaryNotice` and the IP-clearance task, so all license documents land 
in `build/generated/license/`.
   - **CI** (`build-and-publish.yml`): after `./gradlew build`, runs 
`generateLicenseDocs` and uploads `build/generated/license/` as the 
`solr-mcp-license-docs` artifact (30 days), next to the SBOM artifact.
   - **Docs**: new "Incubator IP-Clearance Row" section on the Licensing & 
Notices page (`docs/site/.../licensing.md`) covering how to generate it, where 
it shows up locally and in CI, what it contains and how to use it; plus 
`AGENTS.md` and `buildSrc/README.md`.
   - The SBOM license lookup is extracted into a shared `SbomLicenses` helper 
used by both license tasks.
   
   ## Design notes
   - Licenses are reported exactly as the SBOM reports them, with no allow-list 
and no Category A/B judgement, consistent with the existing "disclose, don't 
judge" LICENSE task. Confirming that every license is acceptable (and adding 
the closing sign-off sentence) is a human step, as documented.
   - Not wired into `check`.
   
   ## Testing
   - `./gradlew -p buildSrc test` — 14 tests pass, including a well-formed-XML 
check on the generated row.
   - `./gradlew generateLicenseDocs` (JDK 25) — produces `LICENSE`, `NOTICE` 
and a well-formed `ip-clearance-licenses.xml` listing 157 dependencies.
   - `./gradlew spotlessCheck` passes.
   
   ## For review
   Two SBOM labels look imprecise and should be checked upstream before any 
"Category A/B" sign-off: `org.antlr:antlr-runtime` / `ST4` are labelled "BSD 
licence" / BSD-4-Clause (believed to be BSD-3-Clause), and 
`org.springaicommunity:mcp-server-security` is labelled "Apache-1.0" (believed 
to be Apache-2.0).
   
   @epugh, please review.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to