Repository navigation
Conversation
The parser path added for the newer project-info-reports format only matched the direct compile anchor and stalled after the first table, so check-licenses.py compared 68 instead of ~420 dependencies against licenses.yaml. Match both compile anchors in any state, fail when a compile table is left unparsed, map three more license spellings, and fix the licenses.yaml drift the check now reports.
FrankChen021
reviewed
Oct 9, 2026
FrankChen021
left a comment
Member
There was a problem hiding this comment.
🟢 Approval recommended
No actionable issues found in this review. The parser now recognizes both direct and transitive compile tables and fails if a recognized compile table is left unfinished; the registry updates cover the newly checked artifacts and the added license aliases normalize the report names used by those artifacts.
Reviewed 2 of 2 changed files.
Validation: git diff --check passed; Python syntax compilation, a parser smoke test covering direct and transitive tables including a classifier column, and a Ruby YAML parse check all passed. No full build or test suite was run.
This is an automated review by Codex GPT-5.6 Luna(Max)
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Since #20148 (Apache parent 25 → 39),
check-licenses.pyonly reads the direct compile dependencies from each module'sdependencies.html. Transitive dependencies are skipped entirely, so the packaging-check job compares 68 reported dependencies instead of ~420 againstlicenses.yaml. A version bump without a matchinglicenses.yamlupdate now passes CI. I noticed that on #20520 which bumpsat.yawk.lz4:lz4-javato 1.11.4 without touchinglicenses.yaml, and the check stays green.Transitive dependencies need to be covered: the binary tarball bundles them (
lib/andpull-depsboth resolve them), and ASF policy treats bundled transitive dependencies the same as first-order ones forLICENSEandNOTICE(release policy).More details from Claude analysis
Fixed the dependency report parser
The newer
maven-project-info-reports-pluginoutput marks sections with<a id="...">anchors. The parsing path added in #20148 had two problems:Project_Dependencies_compile, notProject_Transitive_Dependencies_compile.none. After the first table, the<h2>test</h2>heading moved the state machine into the legacyh2_endstate, where it waited for an<h3>that never comes.The anchor check now runs in any state, matches both compile anchors, and jumps straight to waiting for the table. This also removes the two intermediate
modern_compile_*states. I also added a guard: the parser counts the compile tables it enters and finishes, and raises if any are left unfinished, so a future format change fails loudly instead of silently shrinking coverage.Three license names that the reports use but the alias table did not know (
Go License,MIT license,The BSD 2-Clause License) are now mapped, so the license-name comparison runs forre2j,animal-sniffer-annotationsandstax2-api.Fixed the
licenses.yamldrift the check now findsWith the parser fixed, master has 15 dependencies that are reported but not registered:
maven-model,maven-model-builder,maven-resolver-provider,maven-resolver-named-locksandmaven-resolver-transport-file(notice text taken from each jar'sMETA-INF/NOTICE), andplexus-interpolation1.25 → 1.29.druid-protobuf-extensions: 8.3.1 → 8.3.2 andkafka-clients8.3.1-ccs → 8.3.2-ccs.joda-time2.14.4,jackson-jq1.6.5,slf4j-api2.0.20,auto-value-annotations1.11.1.Verification
On reports generated locally from current master with
generate-license-dependency-reports.py:licenses.yamllz4-javaregistered at the wrong versionlz4-javaThe parsed rows match every compile-table row in all 31 reports, including the ones with a Classifier column. The binary LICENSE and NOTICE generators still run cleanly on the updated
licenses.yaml.Not in this PR
Project_*_runtimetables) ship in the distribution but have never been checked, also before build(deps): bump org.apache:apache from 25 to 39 #20148. Adding them reports 28 more missing or outdated entries (for examplelog4j-slf4j2-impl,hibernate-validator,janino,hadoop-client-runtime). That needs per-artifact license and notice review, so I will send it as a separate PR.licenses.yamlentries are registered at an older version than the reports show (for example Guava 32.1.3-jre, the Confluent 6.2.15 entries,kafka-clients6.2.12-ccs and 5.5.1-ccs underdruid-avro-extensions). They only produce warnings. Some may ship fromhadoop-dependencies/, so removing them needs a check against the built tarball.This PR has: