angular / angular/angular-cli

Support for list of allowed licenses for 3rdpartylicenses.txt

未关闭
#31,523 4 条评论 22 个 reaction 已指派 0 人 在 GitHub 查看
angular/build:application feature feature: under consideration
主要语言
TypeScript
星标
27k
派生
11.8k
平均合并
14 小时 23 分钟
30 天内合并 PR
162

描述

### Command

build

### Description

When running `ng build` angular will generate the file `3rdpartylicenses.txt` which contains information about 3rd party licenses included in the build result.
While this is awesome, it would be good to have an option to allow licenses that can be included in the build. For example `MIT`, `Apache-2.0` and as soon as a license which is not allowed is included, the build should fail.

https://github.com/angular/angular-cli/blob/ec7dd59e38f84db91f5a2e4ed653bbc54cb82d54/packages/angular/build/src/builders/application/execute-build.ts#L247-L253

### Describe the solution you'd like

In go, the package https://github.com/google/go-licenses for example supports `--allowed_licenses=`. As soon as a different license is found, the build fails. also [php](https://github.com/dominikb/composer-license-checker) or other languages have tools for this.

### Describe alternatives you've considered

Currently I'm trying to implement this using the npm package: https://www.npmjs.com/package/@onebeyond/license-checker

The issue is, that it includes a lot of npm packages which are not part of the final angular app - such as `argparse` for example.

贡献指南

打开贡献指南

调研方向

从 packages/angular/build/src/builders/application/execute-build.ts 中 issue 所关联的 3rdpartylicenses.txt 生成部分开始,然后跟踪最终 build 中的许可证是如何收集的。定义如何向 ng build 提供以逗号分隔的允许许可证列表,以及不允许的许可证如何导致失败。完成标准是 build 检查生成的 build 许可证,而不是不相关的已安装软件包。

由索引模型根据 Issue 内容生成。

评估

技术栈
angular, typescript
领域
build-system, cli
Issue 类型
功能
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。