Re: [QUESTION] Handling of licensing issues for dependencies of dependencies

2024-01-09 Thread Julian Hyde
I don’t have a good answer to that. In the java world, we use maven or gradle, and there may be plugins to assert that the license is acceptable for an ASF project (and remains acceptable each time the dependency is upgrade), but I’m not fully aware of those plugins. For other languages my

[QUESTION] Handling of licensing issues for dependencies of dependencies

2024-01-09 Thread Riley Kuttruff
I was performing a more thorough check of our dependencies in preparation of opening graduation discussions with the Incubator PMC and found at least one package that, while not directly used in the code, is installed as a dependency of multiple top-level dependencies that is LGPL licensed. The

Re: [PR] Bumped spark version [incubator-sdap-in-situ-data-services]

2024-01-09 Thread via GitHub
jasonmlkang merged PR #25: URL: https://github.com/apache/incubator-sdap-in-situ-data-services/pull/25 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

Re: [QUESTION] Handling of licensing issues for dependencies of dependencies

2024-01-09 Thread Riley Kuttruff
Thanks Julian, I manually checked the top-level dependencies by hand this time around, but I am also aware of other tools that can list the license of all installed packages so maybe I can work that into a checker script. I'll mirror the question to general@ On 2024/01/09 19:09:50 Julian

[jira] [Updated] (SDAP-364) Upgrade Solr to 8.11.1

2024-01-09 Thread Riley Kuttruff (Jira)
[ https://issues.apache.org/jira/browse/SDAP-364?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Riley Kuttruff updated SDAP-364: Resolution: Fixed Status: Done (was: To Do) > Upgrade Solr to 8.11.1 >