You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Make the legal files match the exact contents of the extracted ASF source
candidate, apache-maka-<version>-incubating-src.tar.gz.
G3 owns only the artifact voted on by the podling and IPMC. The npm and
macOS/Windows convenience artifacts have different byte inventories and are
reviewed independently under G8 and G9; they do not expand this source-release
gate.
Exit criteria
Build the source candidate with the release workflow and inventory the
bytes in the extracted archive, rather than treating the repository or a
dependency graph as the artifact.
Confirm the candidate's root LICENSE, NOTICE, and DISCLAIMER-WIP are
accurate for those bytes: Apache License 2.0 is present, third-party terms and
attributions are complete, NOTICE contains only legally required notices,
and the disclaimer's disclosures remain current.
Identify every vendored, adapted, or generated source/data input in the
candidate and record its origin, pinned revision or reproducible snapshot,
license, and any required attribution. Merged PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 covers the known
opencode adaptations and models.dev snapshot; the candidate inventory must
still establish completeness.
Confirm the source candidate contains no Category X material and no
compiled third-party binaries; handle any permitted source-form third-party
material according to ASF third-party license policy.
Re-run the release checks against the extracted candidate and obtain the
required human and mentor/PPMC review of this source-artifact closure, with ASF
Legal Affairs input where applicable.
Existing work
Merged PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 adds the known opencode/models.dev attribution and pins the
models.dev snapshot digest. Its notice generator still walks npm dependency
trees, so it is evidence for known inputs, not proof that the source inventory
is complete.
scripts/asf-source-release.mjs already creates the isolated git archive,
rejects node_modules, and requires root legal files.
Apache OpenDAL's incubating releases provide a useful practice reference: its
ASF dist directories contain one source archive plus signature/checksum, while
npm publishing is a separate post-tag workflow. Maka follows the same artifact
boundary here. This is evidence for scoping the work, not a substitute for
Maka's mentor/PPMC or ASF Legal review.
Out of scope
npm package contents and npm-specific legal files (G8).
macOS/Windows package contents and platform-specific legal files (G9).
ASF source headers and the RAT-equivalent audit (G4).
Implementing packaging behavior outside the source legal-file boundary.
English
Part of #2974 — G3: source-release legal files.
Outcome
Make the legal files match the exact contents of the extracted ASF source
candidate,
apache-maka-<version>-incubating-src.tar.gz.G3 owns only the artifact voted on by the podling and IPMC. The npm and
macOS/Windows convenience artifacts have different byte inventories and are
reviewed independently under G8 and G9; they do not expand this source-release
gate.
Exit criteria
bytes in the extracted archive, rather than treating the repository or a
dependency graph as the artifact.
LICENSE,NOTICE, andDISCLAIMER-WIPareaccurate for those bytes: Apache License 2.0 is present, third-party terms and
attributions are complete,
NOTICEcontains only legally required notices,and the disclaimer's disclosures remain current.
candidate and record its origin, pinned revision or reproducible snapshot,
license, and any required attribution. Merged PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 covers the known
opencode adaptations and models.dev snapshot; the candidate inventory must
still establish completeness.
compiled third-party binaries; handle any permitted source-form third-party
material according to ASF third-party license policy.
required human and mentor/PPMC review of this source-artifact closure, with ASF
Legal Affairs input where applicable.
Existing work
models.dev snapshot digest. Its notice generator still walks npm dependency
trees, so it is evidence for known inputs, not proof that the source inventory
is complete.
scripts/asf-source-release.mjsalready creates the isolatedgit archive,rejects
node_modules, and requires root legal files.DISCLAIMER-WIP; only material that actually enters the source candidate isin G3 scope.
Boundary rationale
Apache OpenDAL's incubating releases provide a useful practice reference: its
ASF dist directories contain one source archive plus signature/checksum, while
npm publishing is a separate post-tag workflow. Maka follows the same artifact
boundary here. This is evidence for scoping the work, not a substitute for
Maka's mentor/PPMC or ASF Legal review.
Out of scope
References
Ownership
Leave this issue unassigned until someone explicitly claims the source-candidate
legal review. Prior work in this area does not imply ownership.
简体中文
#2974 的一部分——G3:源码 release 法律文件。
目标结果
使法律文件与解压后的 ASF 源码候选
apache-maka-<version>-incubating-src.tar.gz的实际内容完全匹配。G3 只负责 podling 与 IPMC 投票的 artifact。npm 与 macOS/Windows convenience
artifacts 的字节清单不同,分别在 G8、G9 中独立审查;它们不扩大源码 release gate。
完成条件
dependency graph 代替 artifact 本身。
LICENSE、NOTICE、DISCLAIMER-WIP对这些字节准确:包含Apache License 2.0 全文,第三方条款与署名完整,
NOTICE仅保留依法必须的 notice,disclaimer 的披露仍然成立。
revision 或可复现 snapshot、许可证和必要署名。已合并 PR fix: attribute the adapted opencode sources and the models.dev snapshot #3325 处理了目前已知的
opencode 改编与 models.dev snapshot;仍须通过候选清单证明完整性。
第三方材料均按 ASF 第三方许可证政策处理。
mentor/PPMC 审查;适用时取得 ASF Legal Affairs 意见。
已有工作
digest。其 notice generator 仍遍历 npm dependency tree,因此它能证明已知输入已处理,
不能证明源码清单完整。
scripts/asf-source-release.mjs已用隔离的git archive生成候选,拒绝node_modules,并要求根法律文件存在。DISCLAIMER-WIP的有用历史;G3只处理真正进入源码候选的材料。
边界依据
Apache OpenDAL 的孵化期发版可作为实际实践参考:其 ASF dist 目录只包含一个源码归档及
签名/校验和,npm 则由独立的正式 tag 后置 workflow 发布。Maka 在这里采用同样的 artifact
边界。该实践用于界定工作范围,不能替代 Maka mentors/PPMC 或 ASF Legal 的判断。
不在范围内
参考资料
负责人边界
在有人明确认领 source-candidate 法律审查前保持 unassigned。此前参与过该区域的工作不代表
自动承担本 issue。