Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Repo needs third-party notices file #223

Closed
DaveTryon opened this issue Aug 24, 2020 · 1 comment · Fixed by #233
Closed

Repo needs third-party notices file #223

DaveTryon opened this issue Aug 24, 2020 · 1 comment · Fixed by #233
Assignees

Comments

@DaveTryon
Copy link
Contributor

Since this repo includes the dist folder (which includes 3rd party code), it needs to include a third-party notices file

@dbjorge
Copy link
Contributor

dbjorge commented Aug 24, 2020

Component Governance can generate the NOTICE file for us, but note that it relies on the "dependencies" vs "devDependencies" in package.json being an accurate description of which dependencies are distributed vs not. Those lists need to be audited before generating the NOTICE file; in particular, I don't think "webpack" should be a "dependency", not sure if there are other inaccuracies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants