adityamparikh opened a new pull request, #245: URL: https://github.com/apache/solr-mcp/pull/245
## Summary Generates the "all items depended upon by the project are covered by approved licenses" row of the Incubator IP-clearance status document from the CycloneDX SBOM, and documents how and where it shows up. The row has to be refreshed for every release, so it is built, not hand-written. - **`generateIpClearanceLicenseReport`** (new) writes `build/generated/license/ip-clearance-licenses.xml`: a single `<tr>` in the format used by Incubator IP clearance documents (completion date, the standard checklist wording, a `<ul>` of `group:artifact — license` for every bundled dependency). It uses the same inputs as `generateBinaryLicense`: the shipped `productionRuntimeClasspath` and the SBOM. A dependency missing from the SBOM fails the task. - **`generateLicenseDocs`** (new aggregate) runs `generateBinaryLicense`, `generateBinaryNotice` and the IP-clearance task, so all license documents land in `build/generated/license/`. - **CI** (`build-and-publish.yml`): after `./gradlew build`, runs `generateLicenseDocs` and uploads `build/generated/license/` as the `solr-mcp-license-docs` artifact (30 days), next to the SBOM artifact. - **Docs**: new "Incubator IP-Clearance Row" section on the Licensing & Notices page (`docs/site/.../licensing.md`) covering how to generate it, where it shows up locally and in CI, what it contains and how to use it; plus `AGENTS.md` and `buildSrc/README.md`. - The SBOM license lookup is extracted into a shared `SbomLicenses` helper used by both license tasks. ## Design notes - Licenses are reported exactly as the SBOM reports them, with no allow-list and no Category A/B judgement, consistent with the existing "disclose, don't judge" LICENSE task. Confirming that every license is acceptable (and adding the closing sign-off sentence) is a human step, as documented. - Not wired into `check`. ## Testing - `./gradlew -p buildSrc test` — 14 tests pass, including a well-formed-XML check on the generated row. - `./gradlew generateLicenseDocs` (JDK 25) — produces `LICENSE`, `NOTICE` and a well-formed `ip-clearance-licenses.xml` listing 157 dependencies. - `./gradlew spotlessCheck` passes. ## For review Two SBOM labels look imprecise and should be checked upstream before any "Category A/B" sign-off: `org.antlr:antlr-runtime` / `ST4` are labelled "BSD licence" / BSD-4-Clause (believed to be BSD-3-Clause), and `org.springaicommunity:mcp-server-security` is labelled "Apache-1.0" (believed to be Apache-2.0). @epugh, please review. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
