dannycjones commented on code in PR #3293:
URL: https://github.com/apache/iceberg-rust/pull/3293#discussion_r4135873175


##########
deny.toml:
##########
@@ -15,6 +15,15 @@
 # specific language governing permissions and limitations
 # under the License.
 
+# Dependency license policy. CI checks it on every pull request, and the
+# release scripts check it again before creating a release candidate. See
+# "Dependencies" in CONTRIBUTING.md for what to do when a license is rejected.
+
+[graph]
+# Also check dependencies that only optional features pull in, such as the
+# OpenDAL storage backends. Otherwise cargo-deny only follows default features.
+all-features = true

Review Comment:
   Good catch - I do think we need this.



##########
CONTRIBUTING.md:
##########
@@ -118,6 +118,19 @@ tested in CI and developers have reproducible builds.
 In `Cargo.toml`, we specify the minimum version required to use iceberg-rust. 
This allows users to choose their
 dependency versions without always upgrading to the latest.
 
+Every dependency must have a license that is compatible with the
+[ASF 3rd Party License Policy](https://www.apache.org/legal/resolved.html). 
`deny.toml` lists the allowed licenses
+and the per-crate exceptions. CI checks every pull request against it with 
`cargo deny`, and you can run the same
+check locally with `make check-dependency-licenses`.
+
+If the check rejects a license, look up its category in the ASF policy:
+
+- Category A licenses can be added to `allow` in `deny.toml`.
+- Category B licenses are added to `exceptions` in `deny.toml`, with one entry 
per crate that uses them.
+- Category X licenses are not allowed, so the dependency must be replaced.
+
+Explain any change to `deny.toml` in the pull request description.

Review Comment:
   Thanks for adding this, looks good



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to