Skip to content

Ship third-party license notices, and check dependency licenses in CI - #566

Open
fstubner wants to merge 7 commits into
mainfrom
feat/third-party-notices
Open

fstubner wants to merge 7 commits into
mainfrom
feat/third-party-notices

Conversation

@fstubner

@fstubner fstubner commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Until now no release file included the licenses of the code built into netscli. This PR adds them, and a CI check that fails if a dependency arrives under a license we haven't allowed.

What ships

  • THIRD-PARTY-NOTICES.txt covers the CLI and the desktop app, Rust and npm.
    • It is generated by node scripts/third-party-notices.mjs (cargo-about 0.9.2, release targets only, offline).
    • Identical texts are grouped, and every crate is listed with its crates.io and repository URLs.
    • A CLI-only copy lives in apps/netscli-cli/, because crates.io only packages files inside the crate.
  • netscli licenses prints the CLI's notices.
  • Desktop app: the file is bundled with the app. The About dialog gains "Third-party licenses", which shows it in a dialog with the same frame as About.
  • Release: the file is uploaded as a release asset and required by the asset check. It also ships in every npm package.
  • AppImage: it does bundle LGPL libraries (GTK, WebKitGTK, GLib, GStreamer and others). A new appimage-lib-notices.sh adds each bundled library's Debian copyright file and a list of the Ubuntu source packages. A library that belongs to no package fails the release.

What's in the tree

  • 516 crates ship: 289 in the CLI and 427 in the desktop app.
  • Licenses: MIT 485, Unicode-3.0 19, ISC 18, Apache-2.0 8, MPL-2.0 5, BSD-3-Clause 4, CDLA-Permissive-2.0 2, Zlib 2.
  • No GPL.
  • MPL-2.0 is option-ext, plus cssparser, selectors and dtoa-short in the desktop app.
  • CDLA-Permissive-2.0 is webpki-roots.

CI

  • A new Licenses job, added to the CI Gate, runs two checks:
    • cargo deny check licenses, which checks licenses only, against an allow-list.
    • The notices are regenerated, and the job fails on any difference.
  • Shown failing:
    • with the option-ext MPL exception removed
    • with ISC dropped from the allow-list

Checked

  • fmt, clippy and cargo test -p netscli (125).
  • Desktop lint, 293 unit tests and build.
  • The generator run twice gives byte-identical output.
  • The release script tests pass: 21.
  • The AppImage script was tested in an Ubuntu 24.04 container on a stand-in AppDir. A real AppImage build first runs it at the next release.

Decisions for you

  • LGPL source offer: the AppImage points at Ubuntu's copy of the library sources. That is weaker than a written offer or a copy we host.
  • Dependabot friction: every Dependabot lockfile bump now fails the notices check until someone regenerates the file.

cargo-about lists the Rust crates compiled into the release targets, with
the features the release builds use. A small node script adds the npm
packages bundled into the desktop app, from package-lock.json, and fails
when one has no license file. The CLI gets a file of its own inside its
crate so include_str! still works from the crates.io package.
The notices are compiled in with include_str!, so every copy of the
binary carries them, including the crates.io package. A pipe closed
early by head or less is not an error.
THIRD-PARTY-NOTICES.txt is a bundle resource, so every installer puts it
beside the app. A Third-party licenses button in the About dialog reads it
through a small command and shows it in place of About. Escape goes back.
deny.toml configures only the license check. Permissive licenses are
allowed for any crate, MPL-2.0 and CDLA-Permissive-2.0 only for the crates
that use them today. cargo-about and cargo-deny are installed at pinned
versions and cached on them.
check-release-assets.mjs now requires the notices before a draft goes
public.
linuxdeploy copies GTK, WebKitGTK, GLib, GStreamer and the rest of their
dependencies into the AppImage, many of them LGPL. While the image is open
for the host-library fix, each remaining library is traced to its Ubuntu
package with dpkg, and the package's copyright file goes in beside a list
naming the source package and version Ubuntu publishes. A library that
belongs to no package fails the release.
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Site preview: https://pr-566.netscli-site-preview.pages.dev

Built from 5d84158 with NETSCLI_PREVIEW=1 — noindex, and analytics disabled so it does not report into netscli.com's numbers.

Production is unaffected: netscli.com is served from GitHub Pages via pages.yml, which deploys from main.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant