Full dependency inventory across Rust/Go/npm plus Docker base images and vendored assets (776 rows, 502 unique deps), classified against AGPLv3 compatibility with real citations rather than assumptions. enterprise/ relicensed from its commercial-license stub to AGPLv3, matching core -- the one real flag (Redpanda's BSL 1.1) was evaluated against primary sources and accepted as-is rather than triggering a broker swap. CI enforcement wired up (.github/workflows/license- compliance.yml, this repo's first CI workflow), a root LICENSE file added, and every doc/comment referencing the old commercial-license boundary updated to describe it as architectural only. See /docs/compliance/ for the full report, inventory, and policy.
92 lines
3.0 KiB
YAML
92 lines
3.0 KiB
YAML
name: License compliance
|
|
|
|
# Enforces the AGPLv3-project-wide license policy from the Phase 6
|
|
# license audit (/docs/compliance/license-policy.md) on every PR --
|
|
# a new dependency with an incompatible license fails the build here,
|
|
# not months later when someone happens to re-run the one-time audit.
|
|
# See /docs/compliance/license-audit-report.md for the audit this
|
|
# policy was derived from.
|
|
#
|
|
# This is the first CI workflow in this repo. Several docs
|
|
# (architecture.md, phase-4-isolation-design.md, phase-4-rbac-design.md)
|
|
# already say "enforced in CI by hack/check-tenant-boundary.sh" -- that
|
|
# was true of the *script*, but nothing had actually wired it into a
|
|
# running CI system yet. Fixed here as part of standing up the first
|
|
# real workflow file, not left as a second gap next to this one.
|
|
|
|
on:
|
|
push:
|
|
branches: [master, main]
|
|
pull_request:
|
|
|
|
jobs:
|
|
rust-licenses:
|
|
name: Rust license check (cargo-deny)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
crate_dir: [agent, search]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: EmbarkStudios/cargo-deny-action@v2
|
|
with:
|
|
manifest-path: ${{ matrix.crate_dir }}/Cargo.toml
|
|
command: check licenses
|
|
|
|
go-licenses:
|
|
name: Go license check (go-licenses)
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
# Every Go module with real third-party dependencies -- cli,
|
|
# hack/webhook-sink, and hack/alert-load-test are stdlib-only
|
|
# (confirmed at audit time) and intentionally excluded, not
|
|
# forgotten; add them here if they ever gain a dependency.
|
|
module_dir:
|
|
- api
|
|
- ingest
|
|
- alerting
|
|
- enterprise
|
|
- deploy/operator
|
|
- terraform
|
|
- proto
|
|
- hack/benchmark-fixture
|
|
- hack/windows-fixture
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-go@v5
|
|
with:
|
|
go-version-file: ${{ matrix.module_dir }}/go.mod
|
|
- run: go install github.com/google/go-licenses@latest
|
|
- name: Check licenses
|
|
working-directory: ${{ matrix.module_dir }}
|
|
run: |
|
|
go-licenses check ./... \
|
|
--allowed_licenses=MIT,Apache-2.0,BSD-2-Clause,BSD-3-Clause,ISC,MPL-2.0,0BSD,Unlicense \
|
|
--ignore github.com/sentry/sentry \
|
|
--ignore github.com/segmentio/asm
|
|
|
|
npm-licenses:
|
|
name: npm license check (license-checker)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 22
|
|
- working-directory: web
|
|
run: npm ci
|
|
- name: Check licenses
|
|
working-directory: web
|
|
run: |
|
|
npx --yes license-checker \
|
|
--onlyAllow "MIT;Apache-2.0;BSD-2-Clause;BSD-3-Clause;ISC;0BSD;MPL-2.0" \
|
|
--excludePackages "[email protected]"
|
|
|
|
tenant-boundary:
|
|
name: Architectural boundary check
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- run: bash hack/check-tenant-boundary.sh
|