Skip to content

build(bindings): package complete legal metadata#561

Draft
XiaoHongbo-Hope wants to merge 18 commits into
apache:mainfrom
XiaoHongbo-Hope:fix/binding-artifact-legal-files
Draft

build(bindings): package complete legal metadata#561
XiaoHongbo-Hope wants to merge 18 commits into
apache:mainfrom
XiaoHongbo-Hope:fix/binding-artifact-legal-files

Conversation

@XiaoHongbo-Hope

@XiaoHongbo-Hope XiaoHongbo-Hope commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Generate target-specific Python and Go legal metadata from the locked dependency graph.
  • Merge required Apache dependency notices, including Apache Avro, Arrow, DataFusion, and Object Store.
  • Record statically linked XZ Utils 5.8.3 under 0BSD in every Python wheel report.
  • Package and byte-verify legal files in Python and Go release artifacts.
  • Refresh all reports on the final OpenDAL 0.58 and AWS-LC dependency tree.

Stack

The branch contains the dependency and Rust packaging commits so legal reports cannot go stale. After the stacked PRs merge, only the binding legal commits remain in this diff.

Verification

  • python3.11 scripts/release_licenses.py
  • python3.11 scripts/release_licenses.py --check
  • python3.11 scripts/dependencies.py verify
  • cargo deny --locked --all-features check --warn unmaintained advisories licenses
  • PYO3_PYTHON=python3.11 cargo check --workspace --locked
  • Python five-target and Go four-target legal artifact checks
  • actionlint, YAML parsing, and git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant