FrankChen021 commented on code in PR #20400:
URL: https://github.com/apache/druid/pull/20400#discussion_r4071509250


##########
distribution/pom.xml:
##########
@@ -152,6 +152,11 @@
                                         
<argument>${project.parent.basedir}/licenses/APACHE2</argument>
                                         
<argument>${project.parent.basedir}/licenses.yaml</argument>
                                         
<argument>${project.parent.basedir}/LICENSE.BINARY</argument>
+                                        <!-- Contrib extensions are not 
bundled in the Apache release binary; skip
+                                             their licenses.yaml entries so 
LICENSE.BINARY does not overclaim what
+                                             ships. check-licenses.py enforces 
that every contrib entry uses this
+                                             module prefix. -->
+                                        
<argument>--exclude-module-prefix=extensions-contrib/</argument>

Review Comment:
   [P1] Keep contrib licenses for bundle-contrib-exts
   
   **Finding:** This argument is active for every `dist` build, but 
`-Pdist,bundle-contrib-exts` is a supported path used by packaging-check and 
Docker builds: it pulls contrib extension jars during `package` and then 
assembles them into the binary. Because LICENSE/NOTICE generation runs during 
`initialize`, filtering every `extensions-contrib/` entry leaves the resulting 
tarball or image containing contrib extensions such as Iceberg and Ranger 
without their license and notice text.
   
   **Suggestion:** Make the exclusion conditional on a build that does not 
activate `bundle-contrib-exts`, or generate the unfiltered license and notice 
files whenever that profile is active.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to