From 856f1cbb0eaaff4c4277f8bb48bcd1a2c258a504 Mon Sep 17 00:00:00 2001 From: Andreas Maechler Date: Thu, 8 Oct 2026 12:15:13 -0600 Subject: [PATCH] fix: license check ignores transitive dependencies in dependency reports The parser path added for the newer project-info-reports format only matched the direct compile anchor and stalled after the first table, so check-licenses.py compared 68 instead of ~420 dependencies against licenses.yaml. Match both compile anchors in any state, fail when a compile table is left unparsed, map three more license spellings, and fix the licenses.yaml drift the check now reports. --- distribution/bin/check-licenses.py | 25 ++++++++++--------- licenses.yaml | 40 ++++++++++++++++++++++-------- 2 files changed, 43 insertions(+), 22 deletions(-) diff --git a/distribution/bin/check-licenses.py b/distribution/bin/check-licenses.py index 0eedd005e641..9060a36678e9 100755 --- a/distribution/bin/check-licenses.py +++ b/distribution/bin/check-licenses.py @@ -50,18 +50,23 @@ def __init__(self, druid_module_name, compatible_license_names): def parse(self, f): self.dep_to_license = {} + self.tables_started = 0 + self.tables_finished = 0 self.feed(f.read()) + if self.tables_finished < self.tables_started: + raise Exception("Parsed only {} of {} compile dependency tables".format(self.tables_finished, self.tables_started)) return self.dep_to_license def handle_starttag(self, tag, attrs): # print("current: {}, start tag: {}, attrs:{} ".format(self.state, tag, attrs)) + if tag == "a" and dict(attrs).get("id") in ("Project_Dependencies_compile", "Project_Transitive_Dependencies_compile"): + self.state = "h3_end" + self.include_classifier = False + self.tables_started += 1 + if self.state == "none": if tag == "h2": self.state = "h2_start" - elif tag == "a": - for attr in attrs: - if attr[0] == "id" and attr[1] == "Project_Dependencies_compile": - self.state = "modern_compile_anchor" if self.state == "h2_start": if tag == "a": @@ -80,10 +85,6 @@ def handle_starttag(self, tag, attrs): if attr[0] == "name" and attr[1] == "compile": self.state = "compile_start" - if self.state == "modern_compile_heading": - if tag == "h2": - self.state = "h3_end" - if self.state == "h3_end": if tag == "table": self.state = "table_start" @@ -118,10 +119,6 @@ def handle_endtag(self, tag): if tag == "a": self.state = "project_dependencies_end" - if self.state == "modern_compile_anchor": - if tag == "a": - self.state = "modern_compile_heading" - if self.state == "h2_start": if tag == "h2": self.state = "h2_end" @@ -169,6 +166,7 @@ def handle_endtag(self, tag): if self.state == "row_end": if tag == "table": self.state = "none" + self.tables_finished += 1 def handle_data(self, data): if self.state == "td_start": @@ -258,6 +256,7 @@ def build_compatible_license_names(): compatible_licenses['BSD-2-Clause'] = 'BSD-2-Clause License' compatible_licenses['BSD 2-Clause license'] = 'BSD-2-Clause License' compatible_licenses['BSD 2-Clause License'] = 'BSD-2-Clause License' + compatible_licenses['The BSD 2-Clause License'] = 'BSD-2-Clause License' compatible_licenses['BSD-3-Clause License'] = 'BSD-3-Clause License' compatible_licenses['New BSD license'] = 'BSD-3-Clause License' @@ -326,10 +325,12 @@ def build_compatible_license_names(): compatible_licenses['Bouncy Castle Licence'] = 'MIT License' compatible_licenses['SPDX-License-Identifier: MIT'] = 'MIT License' compatible_licenses['MIT'] = 'MIT License' + compatible_licenses['MIT license'] = 'MIT License' compatible_licenses['MIT-0'] = 'MIT No Attribution' compatible_licenses['The Go license'] = 'The Go license' + compatible_licenses['Go License'] = 'The Go license' compatible_licenses['Universal Permissive License, Version 1.0'] = 'Universal Permissive License, Version 1.0' compatible_licenses['-'] = '-' diff --git a/licenses.yaml b/licenses.yaml index 9f0d1ad41721..b54f80dc33be 100644 --- a/licenses.yaml +++ b/licenses.yaml @@ -1746,7 +1746,7 @@ name: Joda-Time license_category: binary module: java-core license_name: Apache License version 2.0 -version: 2.14.3 +version: 2.14.4 libraries: - joda-time: joda-time notices: @@ -1811,7 +1811,7 @@ name: jackson-jq license_category: binary module: java-core license_name: Apache License version 2.0 -version: 1.6.3 +version: 1.6.5 libraries: - net.thisptr: jackson-jq @@ -2086,17 +2086,29 @@ name: Apache Maven license_category: binary module: java-core license_name: Apache License version 2.0 -version: 3.6.0 +version: 3.9.16 libraries: - org.apache.maven: maven-repository-metadata - org.apache.maven: maven-builder-support + - org.apache.maven: maven-model + - org.apache.maven: maven-model-builder + - org.apache.maven: maven-resolver-provider notices: - maven-repository-metadata: | Maven Repository Metadata Model - Copyright 2001-2018 The Apache Software Foundation + Copyright 2001-2026 The Apache Software Foundation - maven-builder-support: | Maven Builder Support - Copyright 2001-2018 The Apache Software Foundation + Copyright 2001-2026 The Apache Software Foundation + - maven-model: | + Maven Model + Copyright 2001-2026 The Apache Software Foundation + - maven-model-builder: | + Maven Model Builder + Copyright 2001-2026 The Apache Software Foundation + - maven-resolver-provider: | + Maven Artifact Resolver Provider + Copyright 2001-2026 The Apache Software Foundation --- name: Apache Maven Artifact @@ -2148,10 +2160,14 @@ license_name: Apache License version 2.0 version: 2.0.23 libraries: - org.apache.maven.resolver: maven-resolver-transport-apache + - org.apache.maven.resolver: maven-resolver-transport-file notices: - maven-resolver-transport-apache: | Maven Artifact Resolver Transport Apache Copyright 2001-2026 The Apache Software Foundation + - maven-resolver-transport-file: | + Maven Artifact Resolver Transport File + Copyright 2010-2026 The Apache Software Foundation --- @@ -2162,10 +2178,14 @@ license_name: Apache License version 2.0 version: 2.0.23 libraries: - org.apache.maven.resolver: maven-resolver-impl + - org.apache.maven.resolver: maven-resolver-named-locks notices: - maven-resolver-impl: | Maven Artifact Resolver Implementation Copyright 2001-2026 The Apache Software Foundation + - maven-resolver-named-locks: | + Maven Artifact Resolver Named Locks + Copyright 2010-2026 The Apache Software Foundation --- name: Plexus Component Annotations @@ -2282,7 +2302,7 @@ name: Plexus Interpolation API license_category: binary module: java-core license_name: Apache License version 2.0 -version: 1.25 +version: 1.29 libraries: - org.codehaus.plexus: plexus-interpolation @@ -3375,7 +3395,7 @@ name: SLF4J API license_category: binary module: java-core license_name: MIT License -version: 2.0.18 +version: 2.0.20 copyright: QOS.ch license_file_path: licenses/bin/slf4j.MIT libraries: @@ -4233,7 +4253,7 @@ name: google-auto-value license_category: binary module: extensions/druid-google-extensions license_name: Apache License version 2.0 -version: 1.11.0 +version: 1.11.1 libraries: - com.google.auto.value: auto-value-annotations @@ -7261,7 +7281,7 @@ libraries: --- name: Kafka Schema Registry Client -version: 8.3.1 +version: 8.3.2 license_category: binary module: extensions/druid-protobuf-extensions license_name: Apache License version 2.0 @@ -7294,7 +7314,7 @@ libraries: --- name: Confluent Kafka Client -version: 8.3.1-ccs +version: 8.3.2-ccs license_category: binary module: extensions/druid-protobuf-extensions license_name: Apache License version 2.0