A few of upstream's dual-licensed files carry code from other projects under MIT or BSD terms. The fork redistributes it, so their licenses require the notices to travel with it. THIRD-PARTY.md reproduces them. strip.py now reads the stripped tree's comments for another copyright holder, another license, or a note that code came from somewhere else, and names any file THIRD-PARTY.md doesn't cover. It reports, never fails: the notice goes in with the merge that brings the release in. On v0.16.22 it finds 14 files, all of them covered. The rest of the report is byte-for-byte what the committed one says, so the scan disturbs nothing it already did.
Fork tooling
strip.py
Makes an Enterprise-free snapshot of an upstream release. See the docstring and docs/spec/SPEC.md §2.2 for what it does and why.
git clone https://github.com/stalwartlabs/stalwart.git ~/src/stalwart-upstream # outside this repo
git -C ~/src/stalwart-upstream fetch --tags
tools/fork/strip.py --upstream ~/src/stalwart-upstream --ref v0.16.22 --out /tmp/strip-v0.16.22
It writes OUT/tree (the stripped source) and OUT/STRIP-REPORT.md and
.json. Exit 0 means verified clean. Exit 1 means malformed markers, or
something Enterprise-only survived. Read the report's Problems section.
The report's Third-party code section lists upstream code under other
licenses. Files marked new need their notice added to THIRD-PARTY.md
at the repository root before the import is merged.
It needs Python 3.12+ (for tarfile's data filter) and git.