opentelemetry-java-contrib icon indicating copy to clipboard operation
opentelemetry-java-contrib copied to clipboard

License Scan/Remediation Questions

Open austinlparker opened this issue 1 year ago • 1 comments

Hello maintainers! We have received a report from the CNCF license audit that the following paths contain licenses that do not match the project license. You can find the full report here: https://lfscanning.org/reports/cncf-2/open-telemetry-2024-02-09-e8fcbc12-0a27-470a-9f2d-c5f680322e13.html

  • static-instrumenter (appears to be test artifacts/resources, so I don't believe this is a problem but if we don't need them we should remove them)

Please review the linked material and document any decisions made in this issue, thanks.

austinlparker avatar Feb 28 '24 14:02 austinlparker

I checked, and these files

static-instrumenter/agent-instrumenter/src/integrationTest/resources/app.jar/mozilla/public-suffix-list.txt static-instrumenter/maven-plugin/src/test/resources/test-http-app.jar/mozilla/public-suffix-list.txt

come from Apache HTTP Client, which includes a direct copy of the MPL licensed file https://publicsuffix.org/list/public_suffix_list.dat

trask avatar Feb 29 '24 04:02 trask