Add 3PP license check as part of PR CI#18
Merged
marcdumais-work merged 2 commits intomainfrom Jan 29, 2024
Merged
Conversation
b2037fa to
7c34a0d
Compare
Copied from vscode-trace-extension and adapted to run the existing tests in this repo. Signed-off-by: Marc Dumais <marc.dumais@ericsson.com>
7c34a0d to
0257b4c
Compare
0257b4c to
d11896f
Compare
2d1f523 to
144c40d
Compare
bhufmann
requested changes
Jan 29, 2024
Contributor
bhufmann
left a comment
There was a problem hiding this comment.
Looks good to me. Thanks for the contribution.
The license check can be triggered locally: yarn license:check For automatic opening of IP tickets for suspicious depedencies, set an Eclipse Foundation gitlab token as environment variable "DASH_TOKEN" and run the alternate pacakge.json script. e.g.: export DASH_TOKEN="<your token>" yarn license:check:review Closes #17 Signed-off-by: Marc Dumais <marc.dumais@ericsson.com>
144c40d to
f6b8480
Compare
bhufmann
approved these changes
Jan 29, 2024
Contributor
Author
|
The 3PP License check job found one dependency that we will need to update. I will do that in a follow-up PR. |
Contributor
Author
|
Thanks for the review @bhufmann! Will merge now. |
Contributor
Author
Done in #21 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on dash-licenses nodejs-wrapper being released on npm. (ongoing).
However, I went ahead and published a
v0.0.1so we can start using it immediately - the plan is to catch-up with the PR above and a small subsequent one that will create the GitHub release for this version.Also adds a minimalist build/test workflow that runs existing tests. For now it will be only informational, letting the committers know that some 3PPs look suspicious. Any committer can then run the dash-licenses wrapper locally to automatically create the required IP ticket(s) - see commit message for more details.
Closes #17