Skip to content

Add a NOTICE file listing third-party licences #183

Description

@ctfbruce

Goal

The repository is public under the Apache License 2.0 (LICENSE) and carries no NOTICE file. Anyone redistributing a build should be able to see, in one place at the repository root, which third-party components it includes and under which licences.

Proposed change

Add a NOTICE file at the repository root that names the project and its copyright holder, refers to LICENSE for the project's own terms, and lists every direct Go module dependency from go.mod with the licence stated in that module's own LICENSE file. Keep it current when go.mod gains or drops a direct dependency.

Acceptance criteria

  • NOTICE exists at the repository root, names Debuglet and ETH Zurich as the copyright holder, and refers to LICENSE for the project's own terms.
  • Every direct dependency in go.mod appears with its module path, the licence named in its LICENSE file, and whether it is used by the product or only by its tests.
  • The listed licences were checked against the LICENSE files of the pinned module versions rather than taken from memory.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions