Skip to content

chore: split the licence check into allowlist and component exceptions - #35

Closed
TzuH-Hsu wants to merge 4 commits into
mainfrom
chore/34-two-tier-licence-check
Closed

TzuH-Hsu wants to merge 4 commits into
mainfrom
chore/34-two-tier-licence-check

Conversation

@TzuH-Hsu

@TzuH-Hsu TzuH-Hsu commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Bring the shared licence check up to the current version:

  • Add notice-only licences to the allowlist: curl, blessing, Zlib, PSF-2.0, PostgreSQL, BSL-1.0, CC-BY-4.0.
  • Read component-level exceptions and development-only names from scripts/licence-exceptions.json (empty here). An exception lets one named component through with a listed licence; another component with the same licence still fails.
  • Skip the repository's own packages (names from package.json, pyproject.toml, Cargo.toml, go.mod) and packages reached only through uv dependency groups.
  • Let syft look licences up from the package registries, since pnpm and uv lock files carry none.
  • make sbom also writes one SPDX SBOM per image listed in SBOM_IMAGES, and lint-licenses checks those images: language packages against the allowlist, OS packages (the system layer) only against the outright-rejected licences such as AGPL and SSPL.
  • Unit tests for the checker (scripts/test_check_licenses.py, 29 cases) run in make check; the checker needs Python 3.11 or later.
  • AGENTS.md states the updated licence rule.

Related issue

Closes #36

Validation

  • L0 static — make lint
  • L1 unit — make test
  • L2 integration — make lint-licenses run locally with syft 1.52.0
  • L3 e2e / preview — n/a

Risk / rollback

RISK: lint-licenses now needs network access for the registry lookups
RISK: make check now needs Python 3.11 or later; ubuntu-latest ships 3.12
Rollback: revert this squash commit

Checklist

  • Conventional Commit PR title (<type>: <description>)
  • Linked issue using "Closes #N"
  • No secrets, no *.local.md files committed
  • Documentation updated where affected

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T14:17:03.519074Z 93bde1e New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c61bc6a8f4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-licenses.py Outdated
Comment thread scripts/check-licenses.py Outdated
Comment thread scripts/check-licenses.py Outdated
Comment thread scripts/test_check_licenses.py
TzuH-Hsu and others added 2 commits September 27, 2026 22:02
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a68820d72d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-licenses.py Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93bde1ec87

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-licenses.py
edges |= {normalise(d["name"]) for d in extra}
deps.setdefault(name, set()).update(edges)
source = pkg.get("source", {})
if "virtual" in source or "editable" in source:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restrict uv roots to actual project packages

When a uv dependency group contains a local, non-buildable package, uv records that package as source = { virtual = "..." }, just like the root project. This condition therefore adds the dev package to roots; its entire dependency closure becomes shipped, so dev_only_names() checks rather than excludes those development-only dependencies and can reject valid projects for their test/tooling licences. Derive roots from the actual project/workspace packages instead of treating every virtual package in the lock as shipped.

AGENTS.md reference: AGENTS.md:L106-L106

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in the current head: skips and exceptions are keyed by syft ecosystem plus name (only Python names folded), first-party discovery stops at submodules, dev-only status is computed across all uv locks and ignored for image scans, image language packages are gated, exception entries are type-checked, Poetry names are read, and the test file carries the SPDX header in the public repos.

🤖 Addressed by Claude Code

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not changed: treating a virtual uv package as a root makes its closure count as shipped, so those packages are checked rather than skipped. That errs on the strict side (a false failure, not a bypass); if it bites, the fix is to declare the package under dev_only.

@TzuH-Hsu TzuH-Hsu closed this Sep 27, 2026
@TzuH-Hsu
TzuH-Hsu deleted the chore/34-two-tier-licence-check branch September 27, 2026 14:17
@TzuH-Hsu

Copy link
Copy Markdown
Owner Author

Superseded by 37 (the head branch was renamed to match issue #36, which closed this PR).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

授權檢查改為兩層:擴充寬鬆授權白名單、元件層級例外、略過自家與 dev 依賴、SBOM 涵蓋容器 image

1 participant