On Tue, Jan 5, 2021 at 12:27 PM Ed Merks <[email protected]> wrote:

> how are they IP reviewed if they've been pulled straight from some Maven
> repository somewhere?
>

Just like adding any 3rd-party jar to the dependencies, projects will still
have to verify *themselves* (ie not by delegating work to Orbit) that what
they intend to ship is conform to IP requirements (eg check with the
dash-license tool and/or open CQs).
_______________________________________________
cross-project-issues-dev mailing list
[email protected]
To unsubscribe from this list, visit 
https://www.eclipse.org/mailman/listinfo/cross-project-issues-dev

Reply via email to