jacek-lewandowski commented on code in PR #2434:
URL: https://github.com/apache/cassandra/pull/2434#discussion_r1260674310


##########
.build/build-owasp.xml:
##########
@@ -83,4 +85,67 @@
             </fileset>
         </dependency-check>
     </target>
+
+    <target depends="init" name="license-report">
+        <exec executable="jq" osfamily="unix" dir="${basedir}" logError="true" 
failonerror="false" failifexecutionfails="false">
+            <arg value="-M"/>
+            <arg value=".dependencies[] | .fileName + &quot;=&quot; +  
.license"/>
+            <arg value="${build.dir}/owasp/dependency-check-report.json"/>
+            <redirector output="${build.dir}/owasp/license-report.txt"/>
+        </exec>
+
+        <loadfile property="wrongly-licensed" 
srcFile="${build.dir}/owasp/license-report.txt">
+            <filterchain>
+                <linecontainsregexp negate="true">
+                    <regexp 
pattern="^.*=.*(www.apache.org/licenses/LICENSE-2.0|Apache Software License, 
Version 2.0)"/>
+                </linecontainsregexp>
+                <linecontainsregexp negate="true">
+                    <regexp pattern="^.*=.*MIT License"/>
+                </linecontainsregexp>
+                <linecontainsregexp negate="true" casesensitive="false">
+                    <regexp pattern="^.*=.*(BSD.\d.Clause|BSD licen[cs]e)"/>
+                </linecontainsregexp>
+                <linecontainsregexp negate="true">
+                    <regexp pattern="^.*=.*(Eclipse Public 
License|www.eclipse.org/legal/epl-v10.html)"/>
+                </linecontainsregexp>
+                <linecontainsregexp negate="true">
+                    <regexp pattern="^.*=.*(Creative Commons)"/>
+                </linecontainsregexp>
+                <linecontainsregexp negate="true">
+                    <regexp pattern="^.*=.*(ISC)"/>
+                </linecontainsregexp>
+                <replaceregex pattern="&quot;" replace="" byline="true" 
flags="g"/>
+                <trim/>
+                <sortfilter/>
+            </filterchain>
+        </loadfile>
+
+        <echo message="${wrongly-licensed}" 
output="${build.dir}/owasp/license-report.txt"/>

Review Comment:
   build/owasp/license-report.txt contains list of those jars whose licenses 
are unknown or are not approved (there have not been filtered out by the above 
regexp filters). So this is the file the developer should look at when analysis 
fails.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to