Goal
The repository is public under the Apache License 2.0 (LICENSE) and carries no NOTICE file. Anyone redistributing a build should be able to see, in one place at the repository root, which third-party components it includes and under which licences.
Proposed change
Add a NOTICE file at the repository root that names the project and its copyright holder, refers to LICENSE for the project's own terms, and lists every direct Go module dependency from go.mod with the licence stated in that module's own LICENSE file. Keep it current when go.mod gains or drops a direct dependency.
Acceptance criteria
NOTICE exists at the repository root, names Debuglet and ETH Zurich as the copyright holder, and refers to LICENSE for the project's own terms.
- Every direct dependency in
go.mod appears with its module path, the licence named in its LICENSE file, and whether it is used by the product or only by its tests.
- The listed licences were checked against the
LICENSE files of the pinned module versions rather than taken from memory.
Goal
The repository is public under the Apache License 2.0 (
LICENSE) and carries noNOTICEfile. Anyone redistributing a build should be able to see, in one place at the repository root, which third-party components it includes and under which licences.Proposed change
Add a
NOTICEfile at the repository root that names the project and its copyright holder, refers toLICENSEfor the project's own terms, and lists every direct Go module dependency fromgo.modwith the licence stated in that module's ownLICENSEfile. Keep it current whengo.modgains or drops a direct dependency.Acceptance criteria
NOTICEexists at the repository root, names Debuglet and ETH Zurich as the copyright holder, and refers toLICENSEfor the project's own terms.go.modappears with its module path, the licence named in itsLICENSEfile, and whether it is used by the product or only by its tests.LICENSEfiles of the pinned module versions rather than taken from memory.