Skip to content

[audit S3] Licensing hygiene: missing per-file ELv2/SPDX headers and THIRD-PARTY-NOTICES #109

Description

@mikemcdougall

Disposition: backlog | Severity: S3

Compliance-hygiene gaps for a source-available (Elastic License 2.0) product whose model depends on the license being visible. No source file carries an SPDX/ELv2 header and there is no header enforcement, and there is no aggregated THIRD-PARTY-NOTICES file for bundled Apache-2.0/MIT dependencies that the shipped MAUI binary will redistribute (Apache-2.0 4(d) requires preserving NOTICE content).

  • [S3] No Elastic License 2.0 / SPDX header on any source file and no header enforcement — Directory.Build.props:1 — add a short SPDX/ELv2 header via a build/editorconfig check or one-time sweep.
  • [S3] No THIRD-PARTY-NOTICES file for bundled Apache-2.0/MIT dependencies — Directory.Packages.props:50 — generate and commit a THIRD-PARTY-NOTICES file (license-scan task) and include it in the app package.

Register: AUD-301, AUD-302 (release audit)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/licensingLicense compliance and SPDX headerschoreMaintenance / cleanup / toolingeffort/SRough sizepriority/P3Medium

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions