Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c61bc6a8f4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a68820d72d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 93bde1ec87
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| edges |= {normalise(d["name"]) for d in extra} | ||
| deps.setdefault(name, set()).update(edges) | ||
| source = pkg.get("source", {}) | ||
| if "virtual" in source or "editable" in source: |
There was a problem hiding this comment.
Restrict uv roots to actual project packages
When a uv dependency group contains a local, non-buildable package, uv records that package as source = { virtual = "..." }, just like the root project. This condition therefore adds the dev package to roots; its entire dependency closure becomes shipped, so dev_only_names() checks rather than excludes those development-only dependencies and can reject valid projects for their test/tooling licences. Derive roots from the actual project/workspace packages instead of treating every virtual package in the lock as shipped.
AGENTS.md reference: AGENTS.md:L106-L106
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Fixed in the current head: skips and exceptions are keyed by syft ecosystem plus name (only Python names folded), first-party discovery stops at submodules, dev-only status is computed across all uv locks and ignored for image scans, image language packages are gated, exception entries are type-checked, Poetry names are read, and the test file carries the SPDX header in the public repos.
🤖 Addressed by Claude Code
There was a problem hiding this comment.
Not changed: treating a virtual uv package as a root makes its closure count as shipped, so those packages are checked rather than skipped. That errs on the strict side (a false failure, not a bypass); if it bites, the fix is to declare the package under dev_only.
|
Superseded by 37 (the head branch was renamed to match issue #36, which closed this PR). |
Summary
Bring the shared licence check up to the current version:
curl,blessing,Zlib,PSF-2.0,PostgreSQL,BSL-1.0,CC-BY-4.0.scripts/licence-exceptions.json(empty here). An exception lets one named component through with a listed licence; another component with the same licence still fails.make sbomalso writes one SPDX SBOM per image listed inSBOM_IMAGES, andlint-licenseschecks those images: language packages against the allowlist, OS packages (the system layer) only against the outright-rejected licences such as AGPL and SSPL.scripts/test_check_licenses.py, 29 cases) run inmake check; the checker needs Python 3.11 or later.Related issue
Closes #36
Validation
make lintmake testmake lint-licensesrun locally with syft 1.52.0Risk / rollback
Checklist
<type>: <description>)*.local.mdfiles committed