Repository navigation
Conversation
cargo-about lists the Rust crates compiled into the release targets, with the features the release builds use. A small node script adds the npm packages bundled into the desktop app, from package-lock.json, and fails when one has no license file. The CLI gets a file of its own inside its crate so include_str! still works from the crates.io package.
The notices are compiled in with include_str!, so every copy of the binary carries them, including the crates.io package. A pipe closed early by head or less is not an error.
THIRD-PARTY-NOTICES.txt is a bundle resource, so every installer puts it beside the app. A Third-party licenses button in the About dialog reads it through a small command and shows it in place of About. Escape goes back.
deny.toml configures only the license check. Permissive licenses are allowed for any crate, MPL-2.0 and CDLA-Permissive-2.0 only for the crates that use them today. cargo-about and cargo-deny are installed at pinned versions and cached on them.
check-release-assets.mjs now requires the notices before a draft goes public.
linuxdeploy copies GTK, WebKitGTK, GLib, GStreamer and the rest of their dependencies into the AppImage, many of them LGPL. While the image is open for the host-library fix, each remaining library is traced to its Ubuntu package with dpkg, and the package's copyright file goes in beside a list naming the source package and version Ubuntu publishes. A library that belongs to no package fails the release.
Contributor
|
Site preview: https://pr-566.netscli-site-preview.pages.dev Built from 5d84158 with Production is unaffected: netscli.com is served from GitHub Pages via |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Until now no release file included the licenses of the code built into netscli. This PR adds them, and a CI check that fails if a dependency arrives under a license we haven't allowed.
What ships
THIRD-PARTY-NOTICES.txtcovers the CLI and the desktop app, Rust and npm.node scripts/third-party-notices.mjs(cargo-about 0.9.2, release targets only, offline).apps/netscli-cli/, because crates.io only packages files inside the crate.netscli licensesprints the CLI's notices.appimage-lib-notices.shadds each bundled library's Debian copyright file and a list of the Ubuntu source packages. A library that belongs to no package fails the release.What's in the tree
option-ext, pluscssparser,selectorsanddtoa-shortin the desktop app.webpki-roots.CI
Licensesjob, added to the CI Gate, runs two checks:cargo deny check licenses, which checks licenses only, against an allow-list.option-extMPL exception removedChecked
cargo test -p netscli(125).Decisions for you