Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Risk: Current dependencies being used by Mojaloop seem to include some viral licenses on key components (Kafka, Hapi, etc). #6

Closed
5 tasks
NicoDuvenage opened this issue May 16, 2019 · 2 comments
Assignees
Labels
To be Discussed Label to flag an item for discussion in the next DA Meeting.

Comments

@NicoDuvenage
Copy link
Contributor

NicoDuvenage commented May 16, 2019

Request:

Link to license report that was executed by @rajiv313 : https://mojaloop.slack.com/files/U87PH4C69/FCSGKAF60/screen_shot_2018-09-13_at_11.15.43.png

Artifacts:

Decision(s):

  • License scan has been completed, across all node projects, and it doesn't look too serious.

Follow-up:

Dependencies:

  • If Applicable

Accountability:

  • Owner:

Notes:

@NicoDuvenage NicoDuvenage changed the title 6 Risk: Current dependencies being used by Mojaloop seem to include some viral licenses on key components (Kafka, Hapi, etc). May 16, 2019
@elnyry-sam-k elnyry-sam-k self-assigned this May 29, 2019
@lewisdaly
Copy link
Contributor

As a part of #711, I implemented this license-scanner tool, which allows us to scan dependencies across projects with Fossa cli or exporting to a single .xlsx file locally.

Our license scan results showed only a few minor instances of GPL licenses. See attached xlsx file for the summary.

license-summary.xlsx

I'm also working on #801, which will introduce the license-scanning step into our CI workflow, and fail CI checks when new disallowed licenses are being introduced into our dependencies.

@elnyry-sam-k elnyry-sam-k added Assigned To be Discussed Label to flag an item for discussion in the next DA Meeting. labels Jul 3, 2019
@lewisdaly
Copy link
Contributor

I think we can close this ticket. We have other follow up tickets:

As far as the DA goes on this topic, I think we have the appropriate measures in place to no longer introduce GPL and other unwanted licenses into the codebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
To be Discussed Label to flag an item for discussion in the next DA Meeting.
Projects
None yet
Development

No branches or pull requests

4 participants