Repository navigation
Expand file tree
/
Copy pathWARN
More file actions
271 lines (220 loc) · 12.5 KB
/
Copy pathWARN
File metadata and controls
271 lines (220 loc) · 12.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
==============================================================================
WARN -- warnings concerning LICENSE and NOTICE for the container image
Container image: docker.io/apache/openserverless-admin-api
==============================================================================
This file records warnings raised while regenerating the LICENSE and NOTICE
files beside it for the container image built from the Dockerfile. It is not
itself a license document.
ASF third-party licensing policy: https://www.apache.org/legal/resolved.html
Category A Apache-2.0 compatible. May be included in a release.
Category B May be included in BINARY form only, unmodified and as a
separate file, with the reciprocal license disclosed.
Category X MUST NOT be included in an Apache release artifact.
==============================================================================
SCOPE
==============================================================================
The Apache release artifact for OpenServerless is the SOURCE distribution,
which contains the Dockerfile and the files beside it -- all Apache-2.0
licensed. The published container image is a CONVENIENCE BINARY assembled at
build time from a third-party base image and from package repositories.
LICENSE and NOTICE now cover both: the license above the first separator
applies to the source release, and each section below a separator applies to
software bundled only in the image.
==============================================================================
WARN 1 -- LICENSE and NOTICE were regenerated, previous content replaced
==============================================================================
Severity : informational
Detail :
The previous LICENSE and NOTICE carried a summary-table inventory with
per-component license identifiers but NOT the license texts themselves;
they pointed at paths inside the image instead. They have been rewritten
in the style of the Apache Pekko LICENSE and NOTICE: Apache-2.0 text
first, then '---------------' separated sections, with the full text of
every non-Apache-2.0 license reproduced inline.
Action :
Review the diff before cutting the release.
==============================================================================
WARN 2 -- previous inventory listed packages that are NOT in the image
==============================================================================
Severity : correctness (resolved in the regenerated files)
Detail :
The previous LICENSE/NOTICE listed 59 Python packages. The Dockerfile
runs `uv pip install --requirement pyproject.toml`, which installs the
default dependency group only -- the `dev` extra is never installed.
Resolving pyproject.toml against uv.lock yields 43 packages.
The following were listed but are NOT present in the runtime image and
have been REMOVED from LICENSE and NOTICE:
asttokens, colorama, decorator, executing, ipython,
ipython-pygments-lexers, jedi, matplotlib-inline, parso, pexpect,
prompt-toolkit, ptyprocess, pure-eval, pygments, stack-data,
traitlets, wcwidth
Over-disclosure is not a license violation, but it misstates the
contents of the artifact and drags in licenses (ISC, BSD-2-Clause)
that nothing in the image actually uses.
Action :
None required. Note that if the Dockerfile is ever changed to install
the dev extra, these packages must be restored.
==============================================================================
WARN 3 -- cffi is MIT No Attribution, not MIT
==============================================================================
Severity : correctness (resolved in the regenerated files)
Category : A
Detail :
The previous inventory recorded cffi (2.0.0) as plain MIT. The license
file shipped in cffi-2.0.0.dist-info/licenses/LICENSE is "MIT No
Attribution" (MIT-0), a distinct, more permissive license. It is now
reproduced in its own LICENSE section.
Action :
None required. Both are Category A.
==============================================================================
WARN 4 -- CPython itself was never disclosed
==============================================================================
Severity : omission (resolved in the regenerated files)
Category : A
Detail :
The image is built `FROM python:3.12-slim-bookworm` and ships the CPython
runtime and standard library, which are the single largest bundled
third-party component. Neither the previous LICENSE nor the previous
NOTICE mentioned CPython or the Python Software Foundation License.
The PSF License Version 2 text is now reproduced in LICENSE and the PSF
copyright chain is recorded in NOTICE.
Action :
None required.
==============================================================================
WARN 5 -- Category X inherited from the base image (GPL-2.0-or-later)
==============================================================================
Severity : disclosure required
Category : X (as bundled)
Components:
libpam-modules, libpam-modules-bin, libpam-runtime, libpam0g
License: GPL-2.0-or-later AND BSD-3-Clause
plus further reciprocally licensed Debian userland components.
Detail :
These arrive from the python:3.12-slim-bookworm base image. The
Dockerfile does not install them: its only `apt-get install` line adds
curl, zip and unzip. They are therefore INHERITED, not added, and
nothing in this service uses PAM authentication.
The ASF does not redistribute these in source form; they are present
only in the convenience binary. This is disclosed in both LICENSE and
NOTICE.
Action :
No removal possible without changing base image. Disclosure is the
required and sufficient remedy. Do NOT add any further GPL component
deliberately.
==============================================================================
WARN 6 -- Category B components (reciprocal, binary-only)
==============================================================================
Severity : conditions must hold
Components:
certifi (2025.11.12) -- MPL-2.0
waitress (3.0.2) -- ZPL-2.1
Detail :
Category B permits inclusion in BINARY form only, unmodified and as a
separate file, with the reciprocal license disclosed. Both are installed
unmodified as separate wheels by uv and are not statically combined with
or patched by OpenServerless code. Full MPL-2.0 reference and ZPL-2.1
text are reproduced in LICENSE.
Note: certifi's own license file states it contains a MODIFIED version
of Mozilla's ca-bundle.crt. The modification is made by the certifi
project upstream, not by OpenServerless; OpenServerless ships certifi
unmodified. This satisfies Category B.
Action :
None required. Do not patch either package in the image.
==============================================================================
WARN 7 -- copyright holders that could not be verified from the artifact
==============================================================================
Severity : verify before release
Detail :
Copyright lines in LICENSE and NOTICE were extracted from the license
files actually shipped in each installed distribution. For a few
components the shipped license file is the bare Apache-2.0 text with no
copyright line, so the attribution was taken from package metadata or
source headers instead:
bcrypt -- taken from METADATA Author-email
(The Python Cryptographic Authority developers)
minio -- taken from "(C) 2015-2021 MinIO, Inc." in source headers
requests -- taken from __version__.py (__copyright__)
uv -- NOT installed locally; uv is installed by pip at image
build time. Its attribution (Astral Software Inc.,
Apache-2.0 OR MIT) was not verified against a built
image.
curl -- Debian package; its copyright range and license text
were not read from the image.
zip/unzip -- Debian packages; Info-ZIP license text was not read
from the image.
CPython -- PSF copyright chain not read from the base image.
Docker was unavailable in the environment where these files were
regenerated, so no component was verified against an actually built
image. The 43 Python packages WERE verified by resolving pyproject.toml
against uv.lock and reading each installed dist-info.
Action :
Before the release vote, build the image and confirm the Debian, uv and
CPython attributions against /usr/share/doc/<pkg>/copyright and the
base image, and adjust the corresponding LICENSE/NOTICE sections.
==============================================================================
WARN 8 -- LICENSE/NOTICE are copied to / in the image, not to a doc path
==============================================================================
Severity : minor
Detail :
The Dockerfile has:
COPY DISCLAIMER LICENSE NOTICE /
WARN is NOT copied into the image, although both LICENSE and NOTICE
refer the reader to "the WARN file beside this file". Inside the image
that reference cannot be followed.
Action :
Either add WARN to that COPY line, or drop the in-image cross-reference.
Consider also placing the files under a conventional path such as
/usr/share/doc/openserverless-admin-api/ in addition to /.
==============================================================================
WARN 9 -- dual-licensed components: no election recorded
==============================================================================
Severity : informational
Components:
cryptography (50.0.0) -- Apache-2.0 OR BSD-3-Clause
packaging (25.0) -- Apache-2.0 OR BSD-2-Clause
uv -- Apache-2.0 OR MIT
Detail :
These are offered under a choice of licenses. LICENSE reproduces both
options for each rather than electing one, which is permissible but
leaves the election implicit.
Action :
Optional: state that the ASF elects Apache-2.0 for each, which
simplifies the inventory.
==============================================================================
WARN 10 -- aiohttp is Apache-2.0 AND MIT
==============================================================================
Severity : informational
Category : A
Detail :
aiohttp (3.14.3) declares "Apache-2.0 AND MIT" -- a conjunction, not a
choice: it is Apache-2.0 licensed and vendors llhttp under MIT
(Copyright (c) 2018 Fedor Indutny). Both are disclosed.
Action :
None required.
==============================================================================
WARN 11 -- previously recorded removals are confirmed still absent
==============================================================================
Severity : informational
Detail :
The previous WARN recorded that the LGPL `psycopg`/`psycopg-binary`
dependencies and the `telnet`/`inetutils-ping` packages had been
removed. Both removals are confirmed against the current tree:
pyproject.toml and uv.lock contain no psycopg, and the Dockerfile's
apt install list is curl, zip, unzip only.
Action :
None required. Do not reintroduce them.
==============================================================================
SUMMARY
==============================================================================
Category X added deliberately by this Dockerfile : none
Category X inherited from the base image : GPL-2.0-or-later Debian
userland (disclosed,
WARN 5)
Category B components : certifi, waitress
(conditions hold, WARN 6)
Blocking issues : none
Open before release vote : WARN 7 (verify Debian /
uv / CPython attributions
against a built image)
WARN 8 (WARN not shipped
in image)