Skip to content

Regenerate the license inventory for the current dependency graph - #52

Merged
jcoffey-dev merged 1 commit into
mainfrom
docs/refresh-license-inventory
Sep 15, 2026
Merged

jcoffey-dev merged 1 commit into
mainfrom
docs/refresh-license-inventory

Conversation

@jcoffey-dev

Copy link
Copy Markdown
Collaborator

Brings docs/compliance/license-inventory.json and .csv up to date with the lockfiles. Dependabot merges never touched them, so they had drifted: gridstack 11.5.1, vite 8.2.1, tonic 0.12 and toml 0.8 in agent, and no rows at all for alerting.

Stacked on #51, so agent records rustls 0.23.45 and no longer lists rustls-pemfile. Merge #51 first; GitHub then retargets this PR to main.

How

The audit's own tools, run against this tree:

  • cargo deny list for agent and search
  • go-licenses csv ./... for each Go module
  • npx license-checker --json for web, after npm ci

Rows whose name and version haven't changed are left byte-for-byte alone (679 of 786), the same approach as a53c309. That also keeps every hand-written row: the segmentio/asm MIT-0 confirmations, both fonts, the favicon, and the Redpanda, ClickHouse and Postgres images. First-party github.com/cairnobs/cairnobs/... packages stay out, as before.

New rows follow the existing conventions. As a check, the same rules applied to every unchanged Rust and npm row reproduced the license text, direct/transitive, flag and classification exactly.

What changed (786 → 802 rows)

  • 52 bumped, including gridstack 13.3.0, vite 8.3.0, svelte 5.57.0, tonic/prost 0.14, axum 0.8, toml 1.1.6, reqwest 0.13.5, tantivy 0.26.2 and rustls 0.23.45.
  • 71 added: alerting's 7 packages; pgx and its dependencies in ingest; golang.org/x/crypto in api; the split go-openapi/swag packages, go.yaml.in/yaml, structured-merge-diff/v6 and randfill in the Kubernetes modules; and tonic-prost, pulldown-cmark, foldhash and others in Rust.
  • 55 removed, including rustls-pemfile, tower 0.4, the gogo/golang protobuf packages, gopkg.in/yaml.v2/v3 and ryu.
  • Nothing newly flagged. Every addition is MIT, Apache-2.0, BSD-3-Clause, Zlib, or an OR of those. Flagged rows go from 36 to 35 because ryu (Apache-2.0 OR BSL-1.0) left search. No bumped crate changed its license.

Checked

  • JSON and CSV match row for row.
  • The file format is exactly as before: one-space JSON indent with no trailing newline, CRLF line endings in the CSV.
  • No duplicate rows.

Not changed

  • Direct/transitive on some old Go rows: a few are marked transitive although go.mod requires the module directly, e.g. pgx in api and go-oidc and crewjam/saml in enterprise. Those rows are unchanged, so I didn't rewrite them. New rows take the label from go.mod.
  • license-audit-report.md counts: its summary table (440 Rust / 255 Go / 75 npm rows, "774 of 776") describes the audit on 2026-08-16 and was already behind before this PR.

Dependabot merges update lockfiles but never the inventory, so it had
drifted: gridstack was recorded at 11.5.1 and vite at 8.2.1, the agent
still listed tonic 0.12 and toml 0.8, and alerting -- named in the
audit's methodology -- had no rows at all.

Regenerated with the audit's own tools against this tree: cargo deny
list for agent and search, go-licenses csv per Go module, license-checker
for web. 52 versions bumped, 71 rows added, 55 gone, 786 -> 802 rows.
Everything added is permissive (MIT, Apache-2.0, BSD-3-Clause, Zlib or
an OR of those), so nothing is newly flagged; flagged rows go 36 -> 35
because ryu (Apache-2.0 OR BSL-1.0) left search's graph with reqwest
0.13. No bumped crate changed its license.

Built on the rustls update, so agent records rustls 0.23.45 and no
longer lists rustls-pemfile.

As last time, rows whose name and version are unchanged are left
byte-for-byte alone -- 679 of them -- so the diff is only the real
change. That also keeps every hand-written row: the segmentio/asm MIT-0
confirmations, the fonts, the favicon, and the three Docker images.
First-party github.com/cairnobs/cairnobs packages are left out, as
before. New rows follow the conventions the existing ones use, which
the regeneration reproduced exactly for every unchanged Rust and npm
row.

Signed-off-by: John Coffey <johnellis@linux.com>
Base automatically changed from fix/rustls-advisory to main September 15, 2026 22:02
@jcoffey-dev
jcoffey-dev merged commit b7a2f41 into main Sep 15, 2026
27 checks passed
@jcoffey-dev
jcoffey-dev deleted the docs/refresh-license-inventory branch September 15, 2026 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant