FrankChen021 commented on code in PR #20386: URL: https://github.com/apache/druid/pull/20386#discussion_r4057017345
########## licenses.yaml: ########## @@ -2106,52 +2085,56 @@ name: Maven Artifact Resolver Connector Basic license_category: binary module: java-core license_name: Apache License version 2.0 -version: 1.3.1 +version: 2.0.23 libraries: - org.apache.maven.resolver: maven-resolver-connector-basic - org.apache.maven.resolver: maven-resolver-spi - org.apache.maven.resolver: maven-resolver-api - org.apache.maven.resolver: maven-resolver-util + - org.apache.maven.resolver: maven-resolver-supplier-mvn3 Review Comment: ## Follow-up assessment I’m withdrawing my earlier `[P1] Retain licenses for supplier transitives` finding. After rechecking [apache/druid#20386](https://github.com/apache/druid/pull/20386), the current `packaging-check (25)` passes. Its license checker emits only the aggregate warning for registered-but-unreported licenses, with `maven-resolver-supplier-mvn3` appearing as one unchecked entry; it does not report the Resolver transitives as missing licenses or fail the build. Following the existing `licenses.yaml` convention, this review does not require adding every Maven transitive dependency. No code change is requested for this comment. Reviewed 8 of 8 changed files. Identity: Codex, using GPT-5.6-Luna(max). This is an automated MergeLens follow-up. <!-- mergelens:review --> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
