angular / angular/angular-cli

Support for list of allowed licenses for 3rdpartylicenses.txt

未關閉
#31,523 4 則留言 22 個 reaction 已指派 0 人 在 GitHub 檢視
angular/build:application feature feature: under consideration
主要語言
TypeScript
星號
27k
分支
11.8k
平均合併
14 小時 23 分鐘
30 天內合併 PR
162

描述

### Command

build

### Description

When running `ng build` angular will generate the file `3rdpartylicenses.txt` which contains information about 3rd party licenses included in the build result.
While this is awesome, it would be good to have an option to allow licenses that can be included in the build. For example `MIT`, `Apache-2.0` and as soon as a license which is not allowed is included, the build should fail.

https://github.com/angular/angular-cli/blob/ec7dd59e38f84db91f5a2e4ed653bbc54cb82d54/packages/angular/build/src/builders/application/execute-build.ts#L247-L253

### Describe the solution you'd like

In go, the package https://github.com/google/go-licenses for example supports `--allowed_licenses=`. As soon as a different license is found, the build fails. also [php](https://github.com/dominikb/composer-license-checker) or other languages have tools for this.

### Describe alternatives you've considered

Currently I'm trying to implement this using the npm package: https://www.npmjs.com/package/@onebeyond/license-checker

The issue is, that it includes a lot of npm packages which are not part of the final angular app - such as `argparse` for example.

貢獻指南

開啟貢獻指南

研究方向

從 packages/angular/build/src/builders/application/execute-build.ts 中 issue 所關聯的 3rdpartylicenses.txt 產生部分開始,然後追蹤最終 build 中的授權條款是如何收集的。定義如何向 ng build 提供以逗號分隔的允許授權條款清單,以及不允許的授權條款如何導致失敗。完成標準是 build 檢查產生的 build 授權條款,而不是不相關的已安裝套件。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
angular, typescript
領域
build-system, cli
Issue 類型
功能
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。