adityamparikh opened a new pull request, #248:
URL: https://github.com/apache/solr-mcp/pull/248

   ## Summary
   Adds `dev-docs/ip-clearance-licenses.xml`, the "Check and make sure that all 
items depended upon by the project are covered by one or more of the following 
approved licenses" row of the IP-clearance status document for #216. It is a 
paste-ready XML `<tr>`.
   
   - It lists the 157 runtime dependencies bundled in the executable JAR (the 
shipped `productionRuntimeClasspath`), each as `group:artifact — license`, with 
the license the CycloneDX SBOM reports for it. It is the same data as the 
appendix of the binary `META-INF/LICENSE`.
   - It was generated once from `main` @ `93ffdb79` and dated 2026-10-05. IP 
clearance is a one-time job, so the row is committed as a file rather than 
built by a Gradle task. That task was proposed in #245 and #246, both now 
closed.
   - `dev-docs/**` is already excluded from RAT, so the fragment carries no 
license header and can be pasted as is.
   
   ## For review before sign-off
   Licenses are listed exactly as the SBOM reports them; no Category A/B 
judgement is applied. Three entries need a human look:
   - `ch.qos.logback:logback-classic` / `logback-core`: EPL-2.0 / LGPL dual 
license. EPL is Category B, so this is acceptable.
   - `org.antlr:antlr-runtime` / `ST4`: labelled "BSD licence" / BSD-4-Clause, 
believed to be BSD-3-Clause upstream.
   - `org.springaicommunity:mcp-server-security`: labelled Apache-1.0, believed 
to be Apache-2.0 upstream.
   
   ## Testing
   - `./gradlew build rat` (JDK 25): 421 tests, 0 failed, 0 skipped; RAT passes.
   - The file is well-formed XML (`xmllint --noout`).
   
   Refs #216
   
   @epugh, please review.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to