amplify-backend icon indicating copy to clipboard operation
amplify-backend copied to clipboard

add dependency review

Open rtpascual opened this issue 1 year ago • 1 comments

Problem

We have no mechanism to validate licensing of dependencies.

Issue number, if available:

Changes

  • Add dependency-review-action to health_checks. This will start validating any change to dependencies (even version bumps) moving forward.

  • Add config file for the new dependency review action:

    • Took allowed license list from amplify-ci-support repo config file
    • Skip packages in amplify-backend because dependency-review-action does not recognize the top level license file for these nested packages

Corresponding docs PR, if applicable:

Validation

Checklist

  • [ ] If this PR includes a functional change to the runtime behavior of the code, I have added or updated automated test coverage for this change.
  • [ ] If this PR requires a change to the Project Architecture README, I have included that update in this PR.
  • [ ] If this PR requires a docs update, I have linked to that docs PR above.
  • [ ] If this PR modifies E2E tests, makes changes to resource provisioning, or makes SDK calls, I have run the PR checks with the run-e2e label set.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

rtpascual avatar May 02 '24 21:05 rtpascual

🦋 Changeset detected

Latest commit: c6f965e03c6786189c356c45c0c57c62d3248fe5

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 21 packages
Name Type
@aws-amplify/deployed-backend-client Patch
@aws-amplify/integration-tests Patch
@aws-amplify/backend-function Patch
@aws-amplify/model-generator Patch
@aws-amplify/auth-construct Patch
@aws-amplify/backend-secret Patch
@aws-amplify/form-generator Patch
@aws-amplify/client-config Patch
@aws-amplify/platform-core Patch
@aws-amplify/plugin-types Patch
@aws-amplify/backend Patch
@aws-amplify/sandbox Patch
@aws-amplify/backend-cli Patch
@aws-amplify/backend-auth Patch
@aws-amplify/backend-data Patch
@aws-amplify/backend-deployer Patch
@aws-amplify/backend-output-storage Patch
@aws-amplify/backend-storage Patch
@aws-amplify/cli-core Patch
create-amplify Patch
@aws-amplify/schema-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

changeset-bot[bot] avatar May 02 '24 21:05 changeset-bot[bot]