bharos opened a new pull request, #13578: URL: https://github.com/apache/gravitino/pull/13578
### What changes were proposed in this pull request? The three connector image dependency scripts now stage the LICENSE and NOTICE that cover what each image actually redistributes, instead of the repository-root pair: - `trino-connectors-dependency.sh` copies them from a staged plugin band, along with that band's `licenses/` directory. - `spark-connectors-dependency.sh` and `flink-connectors-dependency.sh` extract `META-INF/LICENSE`, `META-INF/NOTICE` and `META-INF/licenses/**` from a staged shaded runtime jar. `licenses/THIRD_PARTY_LICENSES.txt` is removed from all three images, and the Dockerfile comments, READMEs and `.gitignore` files are updated to match. The per-component licence texts land in `/licenses/component-licenses/`. No new text is authored — both sources already exist and are generated from the resolved dependency set. ### Why are the changes needed? The images staged the repository-root `LICENSE` and `NOTICE`, which describe the source tree rather than the connector jars each image ships, and covered the difference with a hand-written summary that stated: > This list is a summary for operator convenience and is not exhaustive. The authoritative license and notice text for every bundled component is carried inside the jar's META-INF directory. An image that redistributes those jars has to declare what they bundle. A summary that declares itself non-exhaustive and defers elsewhere does not meet the ASF LICENSE and NOTICE requirements. Raised by Justin Mclean during the 1.3.1 RC3 vote review. An issue will be filed to track it. ### Does this PR introduce _any_ user-facing change? No API or configuration property changes. The `/licenses` directory inside the Trino, Spark and Flink connector images changes content: `LICENSE` and `NOTICE` now enumerate every bundled component, `THIRD_PARTY_LICENSES.txt` is removed, and `component-licenses/` is added. ### How was this patch tested? `bash -n` and `shellcheck -S warning` are clean on all three scripts. The new staging blocks were lifted verbatim and run against the released 1.3.1 artifacts: | | Spark runtime jar | Trino plugin band | |---|---|---| | Component licence files staged | 50 | 39 | | Components enumerated in LICENSE | 21 | 4 bundle groups | | `not exhaustive` disclaimers | 0 | 0 | | Differs from the source LICENSE | yes | yes | | Matches `LICENSE.trino` | — | yes | Marked draft because the full `build-docker.sh` path has not been run end to end; that needs a Gradle build of every connector variant plus Docker. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
