[ 
https://issues.apache.org/jira/browse/SOLR-15465?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17360671#comment-17360671
 ] 

Jan Høydahl commented on SOLR-15465:
------------------------------------

The reason I started looking into this was my work with SOLR-15423 where I add 
a new Oauth2Mock server to the tests, adding 50 more files to the licenses/ 
folder, totalling 662 (main branch). Why would a Solr user care about the 
license of a test dependency? And what if that framework happened to be GPL 
licensed, people would start worrying.

I kind of like how maven generates the dependency page (e.g. 
[http://commons.apache.org/proper/commons-math/dependencies.html)] where it is 
clear what jars are compile or test dependencies, and what licenses they have. 
Like commons-math that use OpenJDK JMH for tests (GPL) but do not ship it.

> Do not require LICENSE and NOTICE files for test-dependencies
> -------------------------------------------------------------
>
>                 Key: SOLR-15465
>                 URL: https://issues.apache.org/jira/browse/SOLR-15465
>             Project: Solr
>          Issue Type: Bug
>      Security Level: Public(Default Security Level. Issues are Public) 
>          Components: Build
>            Reporter: Jan Høydahl
>            Assignee: Jan Høydahl
>            Priority: Major
>
> Our current build (and the ant build before it) checks that every single jar, 
> even test dependencies, have a .sha1 file in licenses/ folder along with a 
> LICENSE file and optinally a NOTICE file.
> However, according to [https://infra.apache.org/licensing-howto.html] we only 
> need to supply LICENSE/NOTICE files for bits we ship, either as copy/pasted 
> source code in the source dist or jar deps in the binary dist.
> Thus, I think we can stop shipping those LICENSE/NOTICE files for deps that 
> we never distribute. Perhaps the sha1 files should remain for extra 
> validation of binaries pulled from mvn, I don't know.
> [~dsmiley] [~dweiss]
> This probably goes for the Lucene build too.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org
For additional commands, e-mail: issues-h...@solr.apache.org

Reply via email to