Skip to content

docs(issues): add dependency license review specification - #2109

Merged
josecelano merged 2 commits into
torrust:developfrom
josecelano:269-review-dependency-licenses
Aug 28, 2026
Merged

docs(issues): add dependency license review specification#2109
josecelano merged 2 commits into
torrust:developfrom
josecelano:269-review-dependency-licenses

Conversation

@josecelano

Copy link
Copy Markdown
Member

Adds the source-of-truth specification and preliminary technical assessment for the dependency-license review.

The preliminary assessment inventories the current resolved Cargo graph, records the evidence limits, and identifies the direct bloom GPL-2.0 dependency as requiring qualified legal review. It does not make a legal compatibility conclusion.

The approved specification establishes a manual-first, twice-yearly review process and defers any automated license-enforcement policy to a separate future issue.

Related to #269.

Copilot AI lite review requested due to automatic review settings August 28, 2026 11:19
@josecelano josecelano self-assigned this Aug 28, 2026
@josecelano
josecelano force-pushed the 269-review-dependency-licenses branch from a06e5a1 to 1489b56 Compare August 28, 2026 11:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds the source-of-truth issue specification and a preliminary technical assessment for a recurring dependency-license review process (Issue #269), documenting scope, evidence expectations, and initial high-risk findings without making legal compatibility conclusions.

Changes:

  • Adds an issue-spec folder for #269 defining scope, decisions, acceptance criteria, and verification plan for a manual-first, twice-yearly license review.
  • Adds a preliminary assessment artifact capturing current evidence sources, inventory commands, and notable license/metadata findings (including the direct bloom GPL-2.0 dependency requiring qualified review).
  • Updates the project spellchecker dictionary to include webpki for the new documentation content.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
project-words.txt Adds webpki to the project word list to keep spellcheck clean for the new license-review docs.
docs/issues/open/269-review-dependency-licenses/ISSUE.md Introduces the issue specification describing the intended manual dependency-license review process and tracking plan.
docs/issues/open/269-review-dependency-licenses/preliminary-assessment.md Adds the preliminary, evidence-scoped technical triage and initial inventory notes for the dependency-license review.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/issues/open/269-review-dependency-licenses/preliminary-assessment.md Outdated
@josecelano

Copy link
Copy Markdown
Member Author

ACK 8f55c72

@josecelano
josecelano merged commit c30fbff into torrust:develop Aug 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants