FrankChen021 commented on code in PR #20386:
URL: https://github.com/apache/druid/pull/20386#discussion_r4056927969


##########
licenses.yaml:
##########
@@ -2106,52 +2085,56 @@ name: Maven Artifact Resolver Connector Basic
 license_category: binary
 module: java-core
 license_name: Apache License version 2.0
-version: 1.3.1
+version: 2.0.23
 libraries:
   - org.apache.maven.resolver: maven-resolver-connector-basic
   - org.apache.maven.resolver: maven-resolver-spi
   - org.apache.maven.resolver: maven-resolver-api
   - org.apache.maven.resolver: maven-resolver-util
+  - org.apache.maven.resolver: maven-resolver-supplier-mvn3

Review Comment:
   [P1] Retain licenses for supplier transitives
   
   **Finding:** Adding maven-resolver-supplier-mvn3 keeps 
org.apache.maven:maven-resolver-provider, maven-model, and maven-model-builder 
in the compile graph (at 3.9.16), and also adds maven-resolver-named-locks and 
maven-resolver-transport-file at 2.0.23. This patch deletes the only registry 
entry for the Maven provider/model artifacts and adds no entries for the two 
new resolver artifacts. distribution/bin/check-licenses.py treats 
reported-but-unregistered dependencies as an error, and the same registry 
generates the binary license and notice files, so packaging/release checks will 
fail or omit required attribution.
   
   **Suggestion:** Restore or update the provider/model license entries and add 
license/notice entries for every new supplier transitive, including 
maven-resolver-named-locks and maven-resolver-transport-file.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to