bottlerocket-os / bottlerocket-os/twoliter

Do not use bottlerocket-sdk as source for cargo-make license

Open
#458 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
34
Forks
43
Avg merge
11h 13m
Merged PRs (30d)
16

Description

Twoliter uses the `bottlerocket-sdk` as a convenient location to grab the license for `cargo-make` to include in our license bundle.

Twoliter does not currently ship with `cargo-make`, and I believe this attribution may have been added in error when I created the script. We should:

* Check my assertion that the license is not required to be included in our attribution bundle (because we aren't re-distributing `cargo-make`)
* Stop pulling the license from the SDK
* Consider vending `cargo-make` ourselves, and using cargo to include the license in our attribution document.

Contributor guide

Open the contributing guide

Research direction

Start by tracing Twoliter's license or attribution bundle logic and the current bottlerocket-sdk source reference; verify whether cargo-make is redistributed and whether its license is required. Done means the SDK is no longer used for this license, with the decision about vending cargo-make and using cargo for attribution resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
build-system, tooling
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.