syncope-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Francesco Chicchiriccò <>
Subject Taking care of LICENSE and NOTICE files
Date Tue, 15 Mar 2016 16:28:23 GMT
Hi all,
today I was finally able to review and fix the various LICENSE and 
NOTICE files in the master branch [1].

I had this task long overdue in my TODO list, because it seems that 
we've been adding several dependencies to the various modules without 
even think to keep LICENSE and NOTICE aligned.

As any decent software engineer, I was pretty much full of all JAR files 
manual checking, so I've developed [2].

LNGenerator essentially does what I used to do manually:

1. after building Syncope, given a certain directory full of JAR files 
(which can be WEB-INF/lib for a web artifact, or some other directory in 
case of ZIP or Uber JAR files)
2. for all JAR files there, lookup into the local Maven repository 
(~/.m2/repository) and empower Maven's M2GavCalculator to determine 
groupId and artifactId
3. exclude all ASF dependencies
4. lookup into a local database of licenses / notices
5. append to LICENSE / NOTICE files

As a result, for all of Syncope artifacts requiring LICENSE / NOTICE 
(standalone, installer, client/cli, deb/core, deb/console, deb/enduser) 
I was able to generate such files reflecting the exact dependencies needed.

Most importantly, we can repeat this again skipping the painful process 
of starting every time from scratch, for the future.

...and please, devs, when adding any dependency, do it carefully and 
check transitive ;-)



Francesco Chicchiriccò

Tirasa - Open Source Excellence

Involved at The Apache Software Foundation:
member, Syncope PMC chair, Cocoon PMC, Olingo PMC, CXF committer

View raw message