This is an automated email from the ASF dual-hosted git repository. github-merge-queue[bot] pushed a commit to branch gh-readonly-queue/main/pr-3293-3c91b3942ab40ec005dfbb9fdbccea848392cccb in repository https://gitbox.apache.org/repos/asf/iceberg-rust.git
commit 8e81f33daa31e495b94ef9e0bc5ff614355f451c Author: Oleks V <[email protected]> AuthorDate: Sun Oct 4 15:36:50 2026 +0000 ci: check dependency licenses with cargo-deny on every PR (#3293) * ci: check dependency licenses with cargo-deny on every PR Run `dev/release/dependencies.sh check` in the `lint` job, so a dependency whose license is not allowed by `deny.toml` fails the pull request instead of being found at release time. Set `[graph] all-features = true` in `deny.toml`. Without it, cargo-deny only follows default features. Since #3143 that graph no longer includes the optional OpenDAL backends, so the check skipped the MPL-2.0 crates that `deny.toml` has exceptions for. Closes #3234. * Tighten docs/comments, reuse dependencies.sh in create_rc.sh - Trim comments and docs that over-explain. - Condense the CONTRIBUTING.md license guidance. - create_rc.sh calls dependencies.sh check so the release uses the pinned cargo-deny version, same as CI. - Drop unused bzip2-1.0.6 from the deny.toml allow-list. Co-authored-by: Copilot App <[email protected]> --------- Co-authored-by: Kevin Liu <[email protected]> Co-authored-by: Copilot App <[email protected]> --- .github/workflows/ci.yml | 5 ++++- CONTRIBUTING.md | 8 ++++++++ Makefile | 10 +++++++++- deny.toml | 5 ++++- dev/release/README.md | 2 +- dev/release/create_rc.sh | 17 +---------------- dev/release/dependencies.sh | 3 ++- website/src/release.md | 2 +- 8 files changed, 30 insertions(+), 22 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 571b46fcc..2c181efd6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -59,7 +59,7 @@ jobs: # Keep versions in sync with the local install targets in Makefile. uses: taiki-e/install-action@d438492cf8a250514fa2d34b30bc3c0dc37c65ff # v2.87.8 with: - tool: [email protected],[email protected] + tool: [email protected],[email protected],[email protected] - name: Check License Header uses: apache/skywalking-eyes/header@a196742f472feaffafea537ce5a2a4c3c53a8de4 # v0.9.0 @@ -79,6 +79,9 @@ jobs: - name: Check crates package LICENSE and NOTICE run: make check-license-notice + - name: Check dependency licenses + run: dev/release/dependencies.sh check + # Trusted publishing cannot create a crate (https://crates.io/docs/trusted-publishing), # so a new publishable crate must be reserved on crates.io before it is merged. # See "Adding a new crate" in website/src/release.md. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index d1a736ed1..3b75b10a9 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -118,6 +118,14 @@ tested in CI and developers have reproducible builds. In `Cargo.toml`, we specify the minimum version required to use iceberg-rust. This allows users to choose their dependency versions without always upgrading to the latest. +Dependency licenses must comply with the [ASF 3rd Party License Policy](https://www.apache.org/legal/resolved.html). +CI checks them against `deny.toml` with `cargo deny`; run `make check-dependency-licenses` to check locally. If a +license is rejected, find its category in the policy: + +- Category A: add the license to `allow`. +- Category B: add a per-crate entry to `exceptions`. +- Category X: not allowed by ASF policy; do not take the dependency. + ## Code of Conduct We expect all community members to follow our [Code of Conduct](https://www.apache.org/foundation/policies/conduct.html). diff --git a/Makefile b/Makefile index 5371c4228..bfb0c1da8 100644 --- a/Makefile +++ b/Makefile @@ -89,7 +89,15 @@ check-public-api: install-cargo-public-api check-license-notice: bash ./dev/check_license_notice.sh -check: check-fmt check-clippy check-toml cargo-machete check-license-notice +# Keep version in sync with the CI lint install step in .github/workflows/ci.yml +# and EXPECTED_CARGO_DENY_VERSION in dev/release/dependencies.sh. +install-cargo-deny: + cargo install --locked [email protected] + +check-dependency-licenses: install-cargo-deny + bash ./dev/release/dependencies.sh check + +check: check-fmt check-clippy check-toml cargo-machete check-license-notice check-dependency-licenses doc-test: cargo test --no-fail-fast --doc --all-features --workspace diff --git a/deny.toml b/deny.toml index e8c3985e5..27c3339ce 100644 --- a/deny.toml +++ b/deny.toml @@ -15,6 +15,10 @@ # specific language governing permissions and limitations # under the License. +[graph] +# Include dependencies from optional features. +all-features = true + [licenses] allow = [ "Apache-2.0", @@ -26,7 +30,6 @@ allow = [ "CC0-1.0", "Zlib", "CDLA-Permissive-2.0", - "bzip2-1.0.6", # Category-A: https://issues.apache.org/jira/browse/LEGAL-660 "Unicode-3.0", # Boost Software License Version 1.0 is allowed (Category-A): diff --git a/dev/release/README.md b/dev/release/README.md index 24c014b0d..93dfb4e06 100644 --- a/dev/release/README.md +++ b/dev/release/README.md @@ -62,7 +62,7 @@ Defaults: `--check_deps 1` requires `cargo-deny`. Install it with: ```shell -cargo install --locked cargo-deny +make install-cargo-deny ``` `--check_publish 1` runs `cargo publish --workspace --dry-run`, which packages and compiles every crate and needs network access to crates.io. diff --git a/dev/release/create_rc.sh b/dev/release/create_rc.sh index 8970aab7b..ae3a5207e 100755 --- a/dev/release/create_rc.sh +++ b/dev/release/create_rc.sh @@ -157,16 +157,6 @@ require_checksum_command() { fi } -require_cargo_deny() { - require_command cargo - if ! cargo deny --version >/dev/null 2>&1; then - echo "This step requires 'cargo-deny' for dependency license checks." >&2 - echo "Install it with: cargo install --locked cargo-deny" >&2 - echo "To skip this step locally, pass: --check_deps 0" >&2 - return 1 - fi -} - require_gpg_secret_key() { require_command gpg if ! gpg --list-secret-keys --with-colons 2>/dev/null | grep -q '^sec'; then @@ -317,12 +307,7 @@ check_rc_tag_available() { } check_dependency_licenses() { - require_cargo_deny - ( - trap - ERR - cd "${REPO_ROOT}" - cargo deny check license - ) + "${SCRIPT_DIR}/dependencies.sh" check } # Packages and builds every crate as `cargo publish` would, without uploading, diff --git a/dev/release/dependencies.sh b/dev/release/dependencies.sh index 85e3b29dd..e0d9e6a94 100755 --- a/dev/release/dependencies.sh +++ b/dev/release/dependencies.sh @@ -25,7 +25,8 @@ if [ "${BASH_VERSINFO[0]}" -lt 4 ]; then echo "Warning: bash ${BASH_VERSION} will not print which step failed. Use bash 4 or newer to see it." >&2 fi -# Keep this in sync with CARGO_DENY_VERSION in .github/workflows/dependencies.yml. +# Keep this in sync with the cargo-deny version in the CI lint install step in +# .github/workflows/ci.yml and the install-cargo-deny target in Makefile. # The generated DEPENDENCIES.rust.tsv files are version-sensitive, so the local # cargo-deny must match the version CI uses to avoid spurious diffs. EXPECTED_CARGO_DENY_VERSION="0.19.9" diff --git a/website/src/release.md b/website/src/release.md index 116e17564..5e8fcad2c 100644 --- a/website/src/release.md +++ b/website/src/release.md @@ -64,7 +64,7 @@ The RC creation script requires a local GPG secret key when artifact signing or Install the release tooling used by the local scripts: -- `cargo-deny` +- `cargo-deny` (`make install-cargo-deny`) - `docker` - `gpg` - `svn`
