review licenses for pekko-grpc-codegen and bat files (published to maven central)
- Dominant language
- Scala
- Stars
- 55
- Forks
- 30
- Avg merge
- 23h 12m
- Merged PRs (30d)
- 34
Description
https://repository.apache.org/content/groups/staging/org/apache/pekko/pekko-grpc-codegen_2.13/1.1.1/
See pekko-grpc-codegen_2.13-1.1.1-assembly.jar and pekko-grpc-codegen_2.13-1.1.1-bat.bat
* They are big files.
* I am not sure if they are needed
* The assembly jar bundles lots of scala-library, io.grpc, guava, protobuf, checkerframework classes but the only LICENSE and NOTICE in the jar are copied from the scala-library.
* If we choose to keep publishing this file, we need to fix its build so that we add a proper LICENSE setup that properly attributes the license details for all classes bundled in the jar
* I don't know what the bat file is but presume it also includes compiled code from many sources
Contributor guide
Research direction
Start by inspecting the repository staging URL and the two named artifacts: pekko-grpc-codegen_2.13-1.1.1-assembly.jar and pekko-grpc-codegen_2.13-1.1.1-bat.bat. Review what they contain and whether they are needed; done means the publishing decision is documented and, if retained, the bundled Scala, gRPC, Guava, protobuf, and Checker Framework classes have appropriate license and notice attribution.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- grpc, scala
- Domain
- build-system, release
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100