alamb opened a new issue, #2495:
URL: https://github.com/apache/datafusion-sqlparser-rs/issues/2495

   
   **Describe the bug**
   
   During the vote on the Apache DataFusion sqlparser-rs `0.63.0` RC1 release, 
Xuanwo identified two licensing-material issues in the source archive and voted 
-1 (non-binding): 
https://lists.apache.org/thread/3lnhgs0bwzl148yrdrcl5g005h9pgtmx
   
   1. **Missing `NOTICE` file**: the source archive contains `LICENSE.TXT` but 
no `NOTICE` file, which ASF releases are expected to include.
   2. **`sqlparser_bench/img/flamegraph.svg` embeds third-party licensed 
code**: the generated flamegraph embeds JavaScript from 
[Inferno](https://github.com/jonhoo/inferno), whose upstream license is CDDL 
1.0, but the archive contains no corresponding license materials.
   
   **To Reproduce**
   
   Download and unpack the 0.63.0 RC1 source archive (or check the repository 
at `v0.63.0-rc1`):
   
   ```shell
   $ ls NOTICE*
   ls: NOTICE*: No such file or directory
   
   $ grep -c -i inferno sqlparser_bench/img/flamegraph.svg
   2
   ```
   
   **Expected behavior**
   
   The source release complies with ASF licensing policy:
   
   1. Add a `NOTICE` file to the repository so it is included in source 
archives.
   2. Exclude the generated `sqlparser_bench/img/flamegraph.svg` from the 
source release
   
   
   **Additional context**
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to