From 51a36db044b1fc8a2e303e6920d2f03241021a50 Mon Sep 17 00:00:00 2001 From: Cassidy James Date: Tue, 23 Jun 2026 14:07:28 -0600 Subject: [PATCH] ci: create license-check workflows (#340) --- .github/allowed-licenses.txt | 15 +++++ .github/pip-licenses-classifiers.txt | 15 +++++ .github/workflows/license-check-node.yml | 35 +++++++++++ .github/workflows/license-check-python.yml | 60 +++++++++++++++++++ .github/workflows/license-check-rust.yml | 26 ++++++++ osprey_coordinator/Cargo.toml | 1 + .../etcd_config_derive/Cargo.toml | 2 + osprey_coordinator/metrics_derive/Cargo.toml | 2 + 8 files changed, 156 insertions(+) create mode 100644 .github/allowed-licenses.txt create mode 100644 .github/pip-licenses-classifiers.txt create mode 100644 .github/workflows/license-check-node.yml create mode 100644 .github/workflows/license-check-python.yml create mode 100644 .github/workflows/license-check-rust.yml diff --git a/.github/allowed-licenses.txt b/.github/allowed-licenses.txt new file mode 100644 index 0000000..ef29858 --- /dev/null +++ b/.github/allowed-licenses.txt @@ -0,0 +1,15 @@ +0BSD +Apache-2.0 +Apache-2.0 WITH LLVM-exception +BSD-2-Clause +BSD-3-Clause +BlueOak-1.0.0 +BSL-1.0 +CC0-1.0 +ISC +MIT +MPL-2.0 +Python-2.0 +Unicode-3.0 +Unlicense +ZPL-2.1 diff --git a/.github/pip-licenses-classifiers.txt b/.github/pip-licenses-classifiers.txt new file mode 100644 index 0000000..2251556 --- /dev/null +++ b/.github/pip-licenses-classifiers.txt @@ -0,0 +1,15 @@ +Apache Software License +Apache 2.0 +Apache License 2.0 +BSD License +BSD +3-Clause BSD License +BSD License; Public Domain +Apache Software License; BSD License +MIT License +Mozilla Public License 2.0 (MPL 2.0) +ISC License (ISCL) +CC0 1.0 Universal (CC0 1.0) Public Domain Dedication +Python Software Foundation License +Apache-2.0 OR BSD-2-Clause +BSD 3-Clause OR Apache-2.0 diff --git a/.github/workflows/license-check-node.yml b/.github/workflows/license-check-node.yml new file mode 100644 index 0000000..9bd677b --- /dev/null +++ b/.github/workflows/license-check-node.yml @@ -0,0 +1,35 @@ +name: License Check (Node) +on: + pull_request: + branches: [main] + paths: + - 'osprey_ui/package.json' + - 'osprey_ui/pnpm-lock.yaml' + - '.github/allowed-licenses.txt' +permissions: + contents: read +jobs: + check: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + - run: corepack enable pnpm + - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 + with: + node-version: "22" + + - name: Format license list + run: | + SPDX=$(tr '\n' ';' < .github/allowed-licenses.txt | sed 's/;$//') + # highcharts uses a custom proprietary license; allowed for now pending #319 + echo "ALLOWED_LICENSES=${SPDX};Custom: https://www.npmjs.com/package/highcharts-export-server" >> "$GITHUB_ENV" + + - name: Install dependencies + working-directory: osprey_ui + run: pnpm install --prod --frozen-lockfile --ignore-scripts + + - name: Check licenses + working-directory: osprey_ui + run: pnpm dlx license-checker@25.0.1 --production --excludePrivatePackages --onlyAllow "$ALLOWED_LICENSES" diff --git a/.github/workflows/license-check-python.yml b/.github/workflows/license-check-python.yml new file mode 100644 index 0000000..b119316 --- /dev/null +++ b/.github/workflows/license-check-python.yml @@ -0,0 +1,60 @@ +name: License Check (Python) +on: + pull_request: + branches: [main] + paths: + - 'pyproject.toml' + - 'uv.lock' + - 'osprey_rpc/pyproject.toml' + - 'osprey_worker/pyproject.toml' + - 'example_plugins/pyproject.toml' + - '.github/allowed-licenses.txt' + - '.github/pip-licenses-classifiers.txt' +permissions: + contents: read +jobs: + check: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + with: + python-version-file: .python-version + - uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + + - name: Format license list + run: | + # pip-licenses reports PyPI classifier names rather than SPDX IDs for some packages. + # allowed-licenses.txt is the policy (SPDX); pip-licenses-classifiers.txt is the translation layer. + SPDX=$(tr '\n' ';' < .github/allowed-licenses.txt | sed 's/;$//') + CLASSIFIERS=$(tr '\n' ';' < .github/pip-licenses-classifiers.txt | sed 's/;$//') + echo "ALLOWED_LICENSES=${SPDX};${CLASSIFIERS}" >> "$GITHUB_ENV" + + - name: Install production dependencies + run: uv sync --only-group common + + - name: Install pip-licenses + run: uv pip install pip-licenses==5.5.5 + + - name: Check licenses + run: | + # Packages ignored due to broken/missing PyPI metadata (license is known and approved): + # google-crc32c: Apache-2.0; no metadata in 1.8.0 (googleapis/google-cloud-python#16515) + # ddtrace: Apache-2.0 OR BSD-3-Clause; sets License field to a filename ("LICENSE.BSD3") + # First-party packages (no license metadata needed): + # osprey-rpc, osprey-worker, example_plugins + # Packages pending license policy review: + # unidecode: GPL v2+ (#354) + # tld: GPL v2 / LGPL / MPL 1.1 (#355) + # nostril: LGPL 2.1 (#356) + # psycopg2-binary: LGPL (#357) + # simplejson: Academic Free License + MIT (#358) + # text-unidecode: Artistic + GPL (transitive via faker) (#359) + uv run pip-licenses --allow-only "$ALLOWED_LICENSES" \ + --ignore-packages \ + google-crc32c \ + ddtrace \ + osprey-rpc osprey-worker example_plugins \ + unidecode tld nostril psycopg2-binary simplejson text-unidecode diff --git a/.github/workflows/license-check-rust.yml b/.github/workflows/license-check-rust.yml new file mode 100644 index 0000000..3c09ca6 --- /dev/null +++ b/.github/workflows/license-check-rust.yml @@ -0,0 +1,26 @@ +name: License Check (Rust) +on: + pull_request: + branches: [main] + paths: + - 'osprey_coordinator/**/Cargo.toml' + - '.github/allowed-licenses.txt' +permissions: + contents: read +jobs: + check: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Generate deny.toml + run: | + { echo '[licenses]'; echo 'allow = ['; sed 's/.*/"&",/' .github/allowed-licenses.txt; echo ']'; } \ + > osprey_coordinator/deny.toml + + - uses: EmbarkStudios/cargo-deny-action@bb137d7af7e4fb67e5f82a49c4fce4fad40782fe # v2.0.20 + with: + command: check licenses + manifest-path: osprey_coordinator/Cargo.toml diff --git a/osprey_coordinator/Cargo.toml b/osprey_coordinator/Cargo.toml index 1fe5d79..33eb739 100644 --- a/osprey_coordinator/Cargo.toml +++ b/osprey_coordinator/Cargo.toml @@ -2,6 +2,7 @@ name = "osprey_coordinator" version = "0.1.0" edition = "2021" +license = "Apache-2.0" # See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html [dependencies] diff --git a/osprey_coordinator/etcd_config_derive/Cargo.toml b/osprey_coordinator/etcd_config_derive/Cargo.toml index 02444ed..ec0f960 100644 --- a/osprey_coordinator/etcd_config_derive/Cargo.toml +++ b/osprey_coordinator/etcd_config_derive/Cargo.toml @@ -2,6 +2,8 @@ name = "osprey_coordinator_etcd_config_derive" version = "0.1.0" edition = "2021" +license = "Apache-2.0" +publish = false # See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html [lib] diff --git a/osprey_coordinator/metrics_derive/Cargo.toml b/osprey_coordinator/metrics_derive/Cargo.toml index 5dd9c4b..b1932e4 100644 --- a/osprey_coordinator/metrics_derive/Cargo.toml +++ b/osprey_coordinator/metrics_derive/Cargo.toml @@ -3,6 +3,8 @@ name = "osprey_coordinator_metrics_derive" version = "0.1.0" authors = ["osprey"] edition = "2021" +license = "Apache-2.0" +publish = false [lib] proc-macro = true -- 2.51.2