This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/main/pr-3293-3c91b3942ab40ec005dfbb9fdbccea848392cccb
in repository https://gitbox.apache.org/repos/asf/iceberg-rust.git

commit 8e81f33daa31e495b94ef9e0bc5ff614355f451c
Author: Oleks V <[email protected]>
AuthorDate: Sun Oct 4 15:36:50 2026 +0000

    ci: check dependency licenses with cargo-deny on every PR (#3293)
    
    * ci: check dependency licenses with cargo-deny on every PR
    
    Run `dev/release/dependencies.sh check` in the `lint` job, so a dependency
    whose license is not allowed by `deny.toml` fails the pull request instead
    of being found at release time.
    
    Set `[graph] all-features = true` in `deny.toml`. Without it, cargo-deny
    only follows default features. Since #3143 that graph no longer includes
    the optional OpenDAL backends, so the check skipped the MPL-2.0 crates that
    `deny.toml` has exceptions for.
    
    Closes #3234.
    
    * Tighten docs/comments, reuse dependencies.sh in create_rc.sh
    
    - Trim comments and docs that over-explain.
    - Condense the CONTRIBUTING.md license guidance.
    - create_rc.sh calls dependencies.sh check so the release uses the
      pinned cargo-deny version, same as CI.
    - Drop unused bzip2-1.0.6 from the deny.toml allow-list.
    
    Co-authored-by: Copilot App <[email protected]>
    
    ---------
    
    Co-authored-by: Kevin Liu <[email protected]>
    Co-authored-by: Copilot App <[email protected]>
---
 .github/workflows/ci.yml    |  5 ++++-
 CONTRIBUTING.md             |  8 ++++++++
 Makefile                    | 10 +++++++++-
 deny.toml                   |  5 ++++-
 dev/release/README.md       |  2 +-
 dev/release/create_rc.sh    | 17 +----------------
 dev/release/dependencies.sh |  3 ++-
 website/src/release.md      |  2 +-
 8 files changed, 30 insertions(+), 22 deletions(-)

diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index 571b46fcc..2c181efd6 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -59,7 +59,7 @@ jobs:
         # Keep versions in sync with the local install targets in Makefile.
         uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff 
# v2.87.8
         with:
-          tool: [email protected],[email protected]
+          tool: [email protected],[email protected],[email protected]
 
       - name: Check License Header
         uses: 
apache/skywalking-eyes/header@a196742f472feaffafea537ce5a2a4c3c53a8de4 # v0.9.0
@@ -79,6 +79,9 @@ jobs:
       - name: Check crates package LICENSE and NOTICE
         run: make check-license-notice
 
+      - name: Check dependency licenses
+        run: dev/release/dependencies.sh check
+
       # Trusted publishing cannot create a crate 
(https://crates.io/docs/trusted-publishing),
       # so a new publishable crate must be reserved on crates.io before it is 
merged.
       # See "Adding a new crate" in website/src/release.md.
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index d1a736ed1..3b75b10a9 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -118,6 +118,14 @@ tested in CI and developers have reproducible builds.
 In `Cargo.toml`, we specify the minimum version required to use iceberg-rust. 
This allows users to choose their
 dependency versions without always upgrading to the latest.
 
+Dependency licenses must comply with the [ASF 3rd Party License 
Policy](https://www.apache.org/legal/resolved.html).
+CI checks them against `deny.toml` with `cargo deny`; run `make 
check-dependency-licenses` to check locally. If a
+license is rejected, find its category in the policy:
+
+- Category A: add the license to `allow`.
+- Category B: add a per-crate entry to `exceptions`.
+- Category X: not allowed by ASF policy; do not take the dependency.
+
 ## Code of Conduct
 
 We expect all community members to follow our [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct.html).
diff --git a/Makefile b/Makefile
index 5371c4228..bfb0c1da8 100644
--- a/Makefile
+++ b/Makefile
@@ -89,7 +89,15 @@ check-public-api: install-cargo-public-api
 check-license-notice:
        bash ./dev/check_license_notice.sh
 
-check: check-fmt check-clippy check-toml cargo-machete check-license-notice
+# Keep version in sync with the CI lint install step in 
.github/workflows/ci.yml
+# and EXPECTED_CARGO_DENY_VERSION in dev/release/dependencies.sh.
+install-cargo-deny:
+       cargo install --locked [email protected]
+
+check-dependency-licenses: install-cargo-deny
+       bash ./dev/release/dependencies.sh check
+
+check: check-fmt check-clippy check-toml cargo-machete check-license-notice 
check-dependency-licenses
 
 doc-test:
        cargo test --no-fail-fast --doc --all-features --workspace
diff --git a/deny.toml b/deny.toml
index e8c3985e5..27c3339ce 100644
--- a/deny.toml
+++ b/deny.toml
@@ -15,6 +15,10 @@
 # specific language governing permissions and limitations
 # under the License.
 
+[graph]
+# Include dependencies from optional features.
+all-features = true
+
 [licenses]
 allow = [
   "Apache-2.0",
@@ -26,7 +30,6 @@ allow = [
   "CC0-1.0",
   "Zlib",
   "CDLA-Permissive-2.0",
-  "bzip2-1.0.6",
   # Category-A: https://issues.apache.org/jira/browse/LEGAL-660
   "Unicode-3.0",
   # Boost Software License Version 1.0 is allowed (Category-A):
diff --git a/dev/release/README.md b/dev/release/README.md
index 24c014b0d..93dfb4e06 100644
--- a/dev/release/README.md
+++ b/dev/release/README.md
@@ -62,7 +62,7 @@ Defaults:
 `--check_deps 1` requires `cargo-deny`. Install it with:
 
 ```shell
-cargo install --locked cargo-deny
+make install-cargo-deny
 ```
 
 `--check_publish 1` runs `cargo publish --workspace --dry-run`, which packages 
and compiles every crate and needs network access to crates.io.
diff --git a/dev/release/create_rc.sh b/dev/release/create_rc.sh
index 8970aab7b..ae3a5207e 100755
--- a/dev/release/create_rc.sh
+++ b/dev/release/create_rc.sh
@@ -157,16 +157,6 @@ require_checksum_command() {
   fi
 }
 
-require_cargo_deny() {
-  require_command cargo
-  if ! cargo deny --version >/dev/null 2>&1; then
-    echo "This step requires 'cargo-deny' for dependency license checks." >&2
-    echo "Install it with: cargo install --locked cargo-deny" >&2
-    echo "To skip this step locally, pass: --check_deps 0" >&2
-    return 1
-  fi
-}
-
 require_gpg_secret_key() {
   require_command gpg
   if ! gpg --list-secret-keys --with-colons 2>/dev/null | grep -q '^sec'; then
@@ -317,12 +307,7 @@ check_rc_tag_available() {
 }
 
 check_dependency_licenses() {
-  require_cargo_deny
-  (
-    trap - ERR
-    cd "${REPO_ROOT}"
-    cargo deny check license
-  )
+  "${SCRIPT_DIR}/dependencies.sh" check
 }
 
 # Packages and builds every crate as `cargo publish` would, without uploading,
diff --git a/dev/release/dependencies.sh b/dev/release/dependencies.sh
index 85e3b29dd..e0d9e6a94 100755
--- a/dev/release/dependencies.sh
+++ b/dev/release/dependencies.sh
@@ -25,7 +25,8 @@ if [ "${BASH_VERSINFO[0]}" -lt 4 ]; then
   echo "Warning: bash ${BASH_VERSION} will not print which step failed. Use 
bash 4 or newer to see it." >&2
 fi
 
-# Keep this in sync with CARGO_DENY_VERSION in 
.github/workflows/dependencies.yml.
+# Keep this in sync with the cargo-deny version in the CI lint install step in
+# .github/workflows/ci.yml and the install-cargo-deny target in Makefile.
 # The generated DEPENDENCIES.rust.tsv files are version-sensitive, so the local
 # cargo-deny must match the version CI uses to avoid spurious diffs.
 EXPECTED_CARGO_DENY_VERSION="0.19.9"
diff --git a/website/src/release.md b/website/src/release.md
index 116e17564..5e8fcad2c 100644
--- a/website/src/release.md
+++ b/website/src/release.md
@@ -64,7 +64,7 @@ The RC creation script requires a local GPG secret key when 
artifact signing or
 
 Install the release tooling used by the local scripts:
 
-- `cargo-deny`
+- `cargo-deny` (`make install-cargo-deny`)
 - `docker`
 - `gpg`
 - `svn`

Reply via email to