Hi Justin
Again - thanks for your vigilance and time to review RC4.
>All like like there may be license dependancy issues, but I’m not familiar 
>enough with sbt and the project to comment. This "sbt dependencyLicenseInfo | 
>grep GNU” shows several GPL dependancies (may be duplicated?). It may be that 
>these items are dual licensed with a license >that is comparable with the 
>Apache license?
[Kam] This analyzes jars required to build the binary artifacts - so my 
assumption is that it is not relevant to release just the source?
>I also notice that you have release downloads on your web site. [3] Please 
>make it clear that these are not Apache releases. I assume this is a work in 
>progress but you might also want to look at the branding requirements at the 
>same time and fix those as well. [4][Kam] Is this a requirement to release? We 
>were planning on adding branding (as well as your suggestion above) once we 
>release 0.8.1. (The branding issues was noted by John a few weeks ago). If 
>this is a blocking issue we can update the site now. Note - the gearpump site 
>is under https://github.com/apache/incubator-gearpump-site and is not bundled 
>with the 0.8.1 source release.
>- there a few files with incorrect Apache headers [2] (also brought up last 
>RC)[Kam] I will add the full header to  worker.js and rerun rat.
>LICENSE is still missing, in general anything that is bundled needs to be 
>added to LICENSE. [1]
>- pygments CSS[Kam] Are you referring to ./docs/css/pygments-default.css? This 
>isn't embedding any pygments source code - just defaults for the gearpump site.
>- normalize (in bootstrap)[Kam] I missed this (as you also mention in your 
>vimeo video) and will add a licenses/LICENSE-normalize.txt and related header 
>in LICENSE
>- polypill (in moderniser)
[Kam] I will add a licenses/LICENSE-polyfill.txt and related header in LICENSE
>Also What happen to the binary files that were in the the last RC? Has the 
>creative commons licensing issue been resolved?
Based on just releasing source there are no CCL related artifacts included in 
the .tgz.
ThanksKam 

    On Monday, July 25, 2016 9:59 PM, Justin Mclean <jus...@classsoftware.com> 
wrote:
 

 Hi,

Looks much better than the last release candidate, however still +0 (binding) 
due to LICENSE issues, the items brought up for the last RC have not been 
addressed and possible GPL dependancies.

All like like there may be license dependancy issues, but I’m not familiar 
enough with sbt and the project to comment. This "sbt dependencyLicenseInfo | 
grep GNU” shows several GPL dependancies (may be duplicated?). It may be that 
these items are dual licensed with a license that is comparable with the Apache 
license?

I also notice that you have release downloads on your web site. [3] Please make 
it clear that these are not Apache releases. I assume this is a work in 
progress but you might also want to look at the branding requirements at the 
same time and fix those as well. [4]

I checked:
- incubating in release name
- signatures and hashes good
- LICENSE is better, but still missing bundled items brought up last RC
- there a few files with incorrect Apache headers [2] (also brought up last RC)
- can compile from source

LICENSE is still missing, in general anything that is bundled needs to be added 
to LICENSE. [1]
- pygments CSS
- normalize (in bootstrap)
- polypill (in moderniser)

One issue here is that you’re not following the terms of the bundled licenses 
(also brought up last RC) Just mentioning the license in LICENSE is not enough, 
the full text of the license needs to be included somewhere, usually this is in 
the header, but if it’s not there you need to include it. I see you have added 
some files to the licenses directory but having "Copyright (c) <year> 
<copyright holders>” in them doesn’t really tell the whole story does it :-)

Also What happen to the binary files that were in the the last RC? Has the 
creative commons licensing issue been resolved?

Thanks,
Justin

1. http://www.apache.org/dev/licensing-howto.html#guiding-principle
2. 
gearpump-0.8.1-RC4-incubating/services/dashboard/views/cluster/workers/worker/worker.js
3. http://gearpump.apache.org/downloads.html
4. http://incubator.apache.org/guides/branding.html
---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscr...@incubator.apache.org
For additional commands, e-mail: general-h...@incubator.apache.org


  

Reply via email to