[
https://issues.apache.org/jira/browse/HDFS-11161?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18066716#comment-18066716
]
ASF GitHub Bot commented on HDFS-11161:
---------------------------------------
LuciferYang commented on PR #8347:
URL: https://github.com/apache/hadoop/pull/8347#issuecomment-4088514823
@yangdong2398 I have conducted some analysis on the dependencies of this
module with cc and summarized them as follows:
## Compile-Scope Dependency Tree
```
org.apache.hadoop:hadoop-bos:3.6.0-SNAPSHOT
└── com.baidubce:bce-java-sdk:0.10.330
├── org.apache.commons:commons-lang3:3.18.0
├── org.slf4j:slf4j-api:1.7.36
├── commons-codec:commons-codec:1.15
├── commons-io:commons-io:2.16.1
├── org.apache.httpcomponents:httpasyncclient:4.0.2
│ ├── org.apache.httpcomponents:httpcore:4.4.13
│ ├── org.apache.httpcomponents:httpcore-nio:4.3.2
│ ├── org.apache.httpcomponents:httpclient:4.5.13
│ └── commons-logging:commons-logging:1.3.0
├── joda-time:joda-time:2.3
├── org.eclipse.paho:org.eclipse.paho.client.mqttv3:1.2.1
├── javax.validation:validation-api:1.1.0.Final
└── org.bouncycastle:bcprov-jdk15on:1.59
```
## License Summary
| Artifact | Version | License | ASF Category | APL 2.0? |
|---|---|---|---|---|
| com.baidubce:bce-java-sdk | 0.10.330 | Apache License 2.0 | A | Yes |
| org.apache.commons:commons-lang3 | 3.18.0 | Apache License 2.0 | A | Yes |
| org.slf4j:slf4j-api | 1.7.36 | MIT License | A | Compatible |
| commons-codec:commons-codec | 1.15 | Apache License 2.0 | A | Yes |
| commons-io:commons-io | 2.16.1 | Apache License 2.0 | A | Yes |
| org.apache.httpcomponents:httpasyncclient | 4.0.2 | Apache License 2.0 | A
| Yes |
| org.apache.httpcomponents:httpcore | 4.4.13 | Apache License 2.0 | A | Yes
|
| org.apache.httpcomponents:httpcore-nio | 4.3.2 | Apache License 2.0 | A |
Yes |
| org.apache.httpcomponents:httpclient | 4.5.13 | Apache License 2.0 | A |
Yes |
| commons-logging:commons-logging | 1.3.0 | Apache License 2.0 | A | Yes |
| joda-time:joda-time | 2.3 | Apache License 2.0 | A | Yes |
| **org.eclipse.paho:org.eclipse.paho.client.mqttv3** | **1.2.1** | **EPL
1.0 / EDL 1.0** | **B** | **No** |
| javax.validation:validation-api | 1.1.0.Final | Apache License 2.0 | A |
Yes |
| org.bouncycastle:bcprov-jdk15on | 1.59 | MIT License (Bouncy Castle
Licence) | A | Compatible |
**Result:** 12 of 14 dependencies are Apache License 2.0. Two (slf4j-api,
bcprov-jdk15on) are MIT — ASF Category A, fully compatible. **One dependency
(`org.eclipse.paho:org.eclipse.paho.client.mqttv3`) is EPL 1.0 — ASF Category
B, requiring special handling.**
---
## Open-Source License Risks
### Risk 1: `org.eclipse.paho:org.eclipse.paho.client.mqttv3:1.2.1` — EPL
1.0 (ASF Category B)
**JAR:** `org.eclipse.paho.client.mqttv3-1.2.1.jar`
**Risk:** This library is dual-licensed under **EPL 1.0** (Eclipse Public
License) and **EDL 1.0** (Eclipse Distribution License / BSD-3-Clause). EPL 1.0
is classified as **ASF Category B** — weak copyleft. Per [ASF third-party
licensing policy](https://www.apache.org/legal/resolved.html):
- Category B dependencies **must not** appear in source releases
- Category B dependencies **may** appear in binary distributions, but
**must** be prominently labeled in `LICENSE-binary` and/or `NOTICE-binary`
- The PR description claims *"No changes required to LICENSE,
LICENSE-binary, or NOTICE-binary files as dependencies are shaded and not
exposed in distribution"* — **this is incorrect**. Shading does not eliminate
licensing obligations; the EPL-licensed bytecode is still present in the shaded
JAR
**How to address (Option A — Preferred):** Exclude the dependency in
`pom.xml`. This is an MQTT client library with no obvious relevance to a Baidu
Object Storage connector — it is almost certainly an unused transitive
dependency of `bce-java-sdk`:
```xml
<dependency>
<groupId>com.baidubce</groupId>
<artifactId>bce-java-sdk</artifactId>
<version>${bce-java-sdk.version}</version>
<exclusions>
<!
> Incorporate Baidu Yun BOS file system implementation
> ----------------------------------------------------
>
> Key: HDFS-11161
> URL: https://issues.apache.org/jira/browse/HDFS-11161
> Project: Hadoop HDFS
> Issue Type: New Feature
> Components: fs
> Reporter: Faen Zhang
> Priority: Major
> Labels: pull-request-available
> Original Estimate: 840h
> Remaining Estimate: 840h
>
> Baidu Yun ( https://cloud.baidu.com/ ) is one of top tier cloud computing
> provider. Baidu Yun BOS is widely used among China's cloud users, but
> currently it is not easy to access data laid on BOS storage from user's
> Hadoop/Spark application, because of no original support for BOS in Hadoop.
> This work aims to integrate Baidu Yun BOS with Hadoop. By simple
> configuration, Spark/Hadoop applications can read/write data from BOS without
> any code change. Narrowing the gap between user's APP and data storage, like
> what have been done for S3 and Aliyun OSS in Hadoop.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]