Hi,

-1 (binding) until MPL licensed source issue resolved.

I checked:
- name contains incubating
- signatures and hashes good
- DISCLAIMER exists
- LICENSE is OK, but look to be missing one permissive license? and assuming 
its ok it would be best if the MPL was in another file.
- NOTICE is OK (but perhaps requires a notice from MPL?)
- All ASF source file have apache header
- No unexpected binary files
- Can compile from source

For the license I think this file [1] may incorrectly have an apache header. 
I’m also unsure of it’s license, but it’s likely to be permissive [2] and needs 
to be mentioned in LICENSE. Can you fix this in the next release please.

There is a more serious issue in that the source includes MPL licensed 
files.[4][5][6] This is a category B license [3] and as such files under these 
terms can only included in binary form, but they plain text. They are not small 
(10,000 lines) and given they contain list of domain name it seems likely they 
they would change so I don’t think the last paragraph in [3] applies either. It 
would also be a good idea to list where they come from.

Thanks,
Justin

1. 
./metron-platform/metron-data-management/src/test/java/org/apache/metron/dataloads/extractor/stix/StixExtractorTest.java
2. http://stixproject.github.io/legal/
3. http://www.apache.org/legal/resolved.html#category-b
4. ./metron-platform/metron-common/src/test/resources/effective_tld_names.dat
5. 
./metron-platform/metron-enrichment/src/main/resources/effective_tld_names.dat
6. ./metron-platform/metron-parsers/src/test/resources/effective_tld_names.dat


---------------------------------------------------------------------
To unsubscribe, e-mail: general-unsubscr...@incubator.apache.org
For additional commands, e-mail: general-h...@incubator.apache.org

Reply via email to