Skip to content

legal: audit LICENSE and NOTICE for the first release artifacts #3270

Description

@M4n5ter
English

Part of #2974 — G3: source-release legal files.

Outcome

Make the legal files match the exact contents of the extracted ASF source
candidate, apache-maka-<version>-incubating-src.tar.gz.

G3 owns only the artifact voted on by the podling and IPMC. The npm and
macOS/Windows convenience artifacts have different byte inventories and are
reviewed independently under G8 and G9; they do not expand this source-release
gate.

Exit criteria

  • Build the source candidate with the release workflow and inventory the
    bytes in the extracted archive, rather than treating the repository or a
    dependency graph as the artifact.
  • Confirm the candidate's root LICENSE, NOTICE, and DISCLAIMER-WIP are
    accurate for those bytes: Apache License 2.0 is present, third-party terms and
    attributions are complete, NOTICE contains only legally required notices,
    and the disclaimer's disclosures remain current.
  • Identify every vendored, adapted, or generated source/data input in the
    candidate and record its origin, pinned revision or reproducible snapshot,
    license, and any required attribution. Merged PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 covers the known
    opencode adaptations and models.dev snapshot; the candidate inventory must
    still establish completeness.
  • Confirm the source candidate contains no Category X material and no
    compiled third-party binaries; handle any permitted source-form third-party
    material according to ASF third-party license policy.
  • Re-run the release checks against the extracted candidate and obtain the
    required human and mentor/PPMC review of this source-artifact closure, with ASF
    Legal Affairs input where applicable.

Existing work

Boundary rationale

Apache OpenDAL's incubating releases provide a useful practice reference: its
ASF dist directories contain one source archive plus signature/checksum, while
npm publishing is a separate post-tag workflow. Maka follows the same artifact
boundary here. This is evidence for scoping the work, not a substitute for
Maka's mentor/PPMC or ASF Legal review.

Out of scope

  • npm package contents and npm-specific legal files (G8).
  • macOS/Windows package contents and platform-specific legal files (G9).
  • ASF source headers and the RAT-equivalent audit (G4).
  • Implementing packaging behavior outside the source legal-file boundary.

References

Ownership

Leave this issue unassigned until someone explicitly claims the source-candidate
legal review. Prior work in this area does not imply ownership.

简体中文

#2974 的一部分——G3:源码 release 法律文件。

目标结果

使法律文件与解压后的 ASF 源码候选
apache-maka-<version>-incubating-src.tar.gz 的实际内容完全匹配。

G3 只负责 podling 与 IPMC 投票的 artifact。npm 与 macOS/Windows convenience
artifacts 的字节清单不同,分别在 G8、G9 中独立审查;它们不扩大源码 release gate。

完成条件

  • 用正式 release workflow 构建源码候选,并盘点解压后归档中的实际字节;不能拿仓库或
    dependency graph 代替 artifact 本身。
  • 确认候选根目录的 LICENSENOTICEDISCLAIMER-WIP 对这些字节准确:包含
    Apache License 2.0 全文,第三方条款与署名完整,NOTICE 仅保留依法必须的 notice,
    disclaimer 的披露仍然成立。
  • 识别候选中的全部 vendored、adapted、generated 源码/数据输入,并记录其来源、固定
    revision 或可复现 snapshot、许可证和必要署名。已合并 PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 处理了目前已知的
    opencode 改编与 models.dev snapshot;仍须通过候选清单证明完整性。
  • 确认源码候选不含 Category X 材料和编译后的第三方二进制;任何获准进入的源码形态
    第三方材料均按 ASF 第三方许可证政策处理。
  • 对解压后的候选重新运行 release checks,并取得该 source-artifact 闭环所需的人工及
    mentor/PPMC 审查;适用时取得 ASF Legal Affairs 意见。

已有工作

边界依据

Apache OpenDAL 的孵化期发版可作为实际实践参考:其 ASF dist 目录只包含一个源码归档及
签名/校验和,npm 则由独立的正式 tag 后置 workflow 发布。Maka 在这里采用同样的 artifact
边界。该实践用于界定工作范围,不能替代 Maka mentors/PPMC 或 ASF Legal 的判断。

不在范围内

  • npm 包内容及 npm 专属法律文件(G8)。
  • macOS/Windows 包内容及平台专属法律文件(G9)。
  • ASF 源码 headers 与 RAT 等价审计(G4)。
  • 源码法律文件边界之外的打包实现。

参考资料

负责人边界

在有人明确认领 source-candidate 法律审查前保持 unassigned。此前参与过该区域的工作不代表
自动承担本 issue。

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentation

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions