From 53c939608b78e47c8a33e5d450b135b43cecd9b1 Mon Sep 17 00:00:00 2001 From: Jonathon Anderson Date: Mon, 20 Jan 2025 10:21:32 -0700 Subject: [PATCH] Enforce updating license dependencies - Closes: #1148 Signed-off-by: Jonathon Anderson --- .github/workflows/check.yml | 9 ++ LICENSE_DEPENDENCIES.md | 188 +++++++++++-------------- Makefile | 5 + Tools.mk | 5 + scripts/update-license-dependencies.sh | 4 +- 5 files changed, 99 insertions(+), 112 deletions(-) diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index 2fa3d868..dbbf01a0 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -72,6 +72,15 @@ jobs: - name: Check for dead Warewulf code (golang ${{ matrix.go-version }}) run: make deadcode + licenses: + runs-on: ubuntu-latest + steps: + - name: Checkout Warewulf + uses: actions/checkout@v4 + - uses: ./.github/actions/prepare + - name: Check for out-of-date license information + run: make LICENSE_DEPENDENCIES.md && git diff --quiet LICENSE_DEPENDENCIES.md + testsuite: runs-on: ubuntu-latest strategy: diff --git a/LICENSE_DEPENDENCIES.md b/LICENSE_DEPENDENCIES.md index 0eae13e4..24ef8fe9 100644 --- a/LICENSE_DEPENDENCIES.md +++ b/LICENSE_DEPENDENCIES.md @@ -21,7 +21,7 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/containers/libtrust @@ -33,13 +33,13 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/containers/storage **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/coreos/go-semver/semver @@ -87,7 +87,7 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/docker/distribution/registry @@ -99,7 +99,7 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/docker/go-connections @@ -113,11 +113,11 @@ The dependencies and their licenses are as follows: **License URL:** -## github.com/go-jose/go-jose/v3 +## github.com/go-jose/go-jose/v4 **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-logr/logr @@ -135,91 +135,97 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/errors **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/jsonpointer **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/jsonreference **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/loads **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/runtime **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/spec **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/strfmt **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/swag **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/go-openapi/validate **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/golang/glog **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/google/go-containerregistry/pkg/name **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/klauspost/compress **License:** Apache-2.0 -**License URL:** +**License URL:** + +## github.com/moby/docker-image-spec/specs-go/v1 + +**License:** Apache-2.0 + +**License URL:** ## github.com/moby/sys/mountinfo **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/moby/sys/user **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/modern-go/concurrent @@ -255,7 +261,7 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/opencontainers/runtime-spec/specs-go @@ -281,41 +287,35 @@ The dependencies and their licenses are as follows: **License URL:** -## github.com/sassoftware/go-rpmutils - -**License:** Apache-2.0 - -**License URL:** - ## github.com/sigstore/fulcio/pkg/certificate **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/sigstore/rekor/pkg/generated/models **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/sigstore/sigstore/pkg **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/spf13/cobra **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/stefanberger/go-pkcs11uri **License:** Apache-2.0 -**License URL:** +**License URL:** ## github.com/vbatts/go-mtree/pkg/govis @@ -357,31 +357,19 @@ The dependencies and their licenses are as follows: **License:** Apache-2.0 -**License URL:** +**License URL:** ## google.golang.org/genproto/googleapis/rpc/status **License:** Apache-2.0 -**License URL:** +**License URL:** ## google.golang.org/grpc **License:** Apache-2.0 -**License URL:** - -## gopkg.in/go-jose/go-jose.v2 - -**License:** Apache-2.0 - -**License URL:** - -## gopkg.in/yaml.v2 - -**License:** Apache-2.0 - -**License URL:** +**License URL:** ## github.com/pkg/errors @@ -405,19 +393,19 @@ The dependencies and their licenses are as follows: **License:** BSD-3-Clause -**License URL:** +**License URL:** ## github.com/cyphar/filepath-securejoin **License:** BSD-3-Clause -**License URL:** +**License URL:** -## github.com/go-jose/go-jose/v3/json +## github.com/go-jose/go-jose/v4/json **License:** BSD-3-Clause -**License URL:** +**License URL:** ## github.com/gogo/protobuf/proto @@ -447,19 +435,13 @@ The dependencies and their licenses are as follows: **License:** BSD-3-Clause -**License URL:** - -## github.com/imdario/mergo - -**License:** BSD-3-Clause - -**License URL:** +**License URL:** ## github.com/klauspost/compress/internal/snapref **License:** BSD-3-Clause -**License URL:** +**License URL:** ## github.com/manifoldco/promptui @@ -477,7 +459,7 @@ The dependencies and their licenses are as follows: **License:** BSD-3-Clause -**License URL:** +**License URL:** ## github.com/proglottis/gpgme @@ -495,7 +477,7 @@ The dependencies and their licenses are as follows: **License:** BSD-3-Clause -**License URL:** +**License URL:** ## github.com/vbatts/go-mtree @@ -513,79 +495,73 @@ The dependencies and their licenses are as follows: **License:** BSD-3-Clause -**License URL:** +**License URL:** -## golang.org/x/exp +## golang.org/x/exp/maps **License:** BSD-3-Clause -**License URL:** +**License URL:** ## golang.org/x/net **License:** BSD-3-Clause -**License URL:** +**License URL:** -## golang.org/x/sync/semaphore +## golang.org/x/sync **License:** BSD-3-Clause -**License URL:** +**License URL:** -## golang.org/x/sys/unix +## golang.org/x/sys **License:** BSD-3-Clause -**License URL:** +**License URL:** ## golang.org/x/term **License:** BSD-3-Clause -**License URL:** +**License URL:** ## golang.org/x/text **License:** BSD-3-Clause -**License URL:** +**License URL:** ## google.golang.org/protobuf **License:** BSD-3-Clause -**License URL:** - -## gopkg.in/go-jose/go-jose.v2/json - -**License:** BSD-3-Clause - -**License URL:** +**License URL:** ## github.com/davecgh/go-spew/spew **License:** ISC -**License URL:** +**License URL:** ## github.com/BurntSushi/toml **License:** MIT -**License URL:** +**License URL:** ## github.com/Masterminds/semver/v3 **License:** MIT -**License URL:** +**License URL:** ## github.com/Masterminds/sprig/v3 **License:** MIT -**License URL:** +**License URL:** ## github.com/VividCortex/ewma @@ -611,6 +587,12 @@ The dependencies and their licenses are as follows: **License URL:** +## github.com/cheynewallace/tabby + +**License:** MIT + +**License URL:** + ## github.com/chzyer/readline **License:** MIT @@ -621,7 +603,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/creasty/defaults @@ -633,13 +615,13 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/fatih/color **License:** MIT -**License URL:** +**License URL:** ## github.com/felixge/httpsnoop @@ -651,7 +633,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/josharian/intern @@ -669,7 +651,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/klauspost/pgzip @@ -699,7 +681,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/mattn/go-sqlite3 @@ -725,17 +707,17 @@ The dependencies and their licenses are as follows: **License URL:** -## github.com/olekukonko/tablewriter +## github.com/mohae/deepcopy **License:** MIT -**License URL:** +**License URL:** ## github.com/rivo/uniseg **License:** MIT -**License URL:** +**License URL:** ## github.com/secure-systems-lab/go-securesystemslib/encrypted @@ -747,7 +729,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/sirupsen/logrus @@ -759,7 +741,7 @@ The dependencies and their licenses are as follows: **License:** MIT -**License URL:** +**License URL:** ## github.com/stretchr/testify/assert @@ -797,18 +779,6 @@ The dependencies and their licenses are as follows: **License URL:** -## github.com/hashicorp/errwrap - -**License:** MPL-2.0 - -**License URL:** - -## github.com/hashicorp/go-multierror - -**License:** MPL-2.0 - -**License URL:** - ## github.com/hashicorp/go-version **License:** MPL-2.0 @@ -819,7 +789,7 @@ The dependencies and their licenses are as follows: **License:** MPL-2.0 -**License URL:** +**License URL:** ## github.com/talos-systems/go-smbios/smbios @@ -831,5 +801,5 @@ The dependencies and their licenses are as follows: **License:** Unlicense -**License URL:** +**License URL:** diff --git a/Makefile b/Makefile index 0a94d9c9..600605a7 100644 --- a/Makefile +++ b/Makefile @@ -247,3 +247,8 @@ cleanproto: clean: cleanvendor endif + +.PHONY: LICENSE_DEPENDENCIES.md +LICENSE_DEPENDENCIES.md: $(GOLANG_LICENSES) scripts/update-license-dependencies.sh + rm -rf vendor + GOLANG_LICENSES=$(GOLANG_LICENSES) scripts/update-license-dependencies.sh diff --git a/Tools.mk b/Tools.mk index 1d899be1..159f53f0 100644 --- a/Tools.mk +++ b/Tools.mk @@ -9,6 +9,8 @@ GOLANGCI_LINT_VERSION := v1.60.1 GOLANG_DEADCODE := $(TOOLS_BIN)/deadcode +GOLANG_LICENSES := $(TOOLS_BIN)/go-licenses + PROTOC := $(TOOLS_BIN)/protoc PROTOC_GEN_GO := $(TOOLS_BIN)/protoc-gen-go PROTOC_GEN_GO_GRPC := $(TOOLS_BIN)/protoc-gen-go-grpc @@ -51,6 +53,9 @@ $(PROTOC_GEN_GO): $(PROTOC_GEN_GO_GRPC): GOBIN="$(PWD)/$(TOOLS_BIN)" go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.2 +$(GOLANG_LICENSES): + GOBIN="$(PWD)/$(TOOLS_BIN)" go install github.com/google/go-licenses@v1.6.0 + .PHONY: cleantools cleantools: rm -rf $(TOOLS_DIR) diff --git a/scripts/update-license-dependencies.sh b/scripts/update-license-dependencies.sh index 3c59e95f..613c5104 100755 --- a/scripts/update-license-dependencies.sh +++ b/scripts/update-license-dependencies.sh @@ -3,8 +3,6 @@ set -e set -u -go install github.com/google/go-licenses@v1.6.0 - if [ -d "vendor" ]; then echo "Please remove vendor directory before running this script" exit 255 @@ -22,7 +20,7 @@ exclude="github.com/warewulf/warewulf" # Ensure a constant sort order export LC_ALL=C -go-licenses csv ./... | grep -v -E "${exclude}" | sort -k3,3 -k1,1 -t, > LICENSE_DEPENDENCIES.csv +${GOLANG_LICENSES:-go-licenses} csv ./... | grep -v -E "${exclude}" | sort -k3,3 -k1,1 -t, > LICENSE_DEPENDENCIES.csv # Header for the markdown file cat <<-'EOF' >LICENSE_DEPENDENCIES.md