chore: auto-generate LICENSE-3rdparty.csv file - #6968
Merged
Conversation
Contributor
Overall package sizeSelf size: 13.42 MB Dependency sizes| name | version | self size | total size | |------|---------|-----------|------------| | @datadog/libdatadog | 0.7.0 | 35.02 MB | 35.02 MB | | @datadog/native-appsec | 10.3.0 | 20.73 MB | 20.74 MB | | @datadog/pprof | 5.12.0 | 11.19 MB | 11.57 MB | | @datadog/native-iast-taint-tracking | 4.1.0 | 9.01 MB | 9.02 MB | | @opentelemetry/resources | 1.30.1 | 557.67 kB | 7.71 MB | | @opentelemetry/core | 1.30.1 | 908.66 kB | 7.16 MB | | protobufjs | 7.5.4 | 2.95 MB | 5.83 MB | | @datadog/wasm-js-rewriter | 5.0.1 | 2.82 MB | 3.53 MB | | @datadog/native-metrics | 3.1.1 | 1.02 MB | 1.43 MB | | @opentelemetry/api-logs | 0.208.0 | 199.48 kB | 1.42 MB | | @opentelemetry/api | 1.9.0 | 1.22 MB | 1.22 MB | | jsonpath-plus | 10.3.0 | 617.18 kB | 1.08 MB | | import-in-the-middle | 1.15.0 | 127.66 kB | 856.24 kB | | lru-cache | 10.4.3 | 804.3 kB | 804.3 kB | | @datadog/openfeature-node-server | 0.2.0 | 118.51 kB | 437.19 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | source-map | 0.7.6 | 185.63 kB | 185.63 kB | | pprof-format | 2.2.1 | 163.06 kB | 163.06 kB | | @datadog/sketches-js | 2.1.1 | 109.9 kB | 109.9 kB | | @isaacs/ttlcache | 2.1.2 | 90.79 kB | 90.79 kB | | lodash.sortby | 4.7.0 | 75.76 kB | 75.76 kB | | ignore | 7.0.5 | 63.38 kB | 63.38 kB | | istanbul-lib-coverage | 3.2.2 | 34.37 kB | 34.37 kB | | rfdc | 1.4.1 | 27.15 kB | 27.15 kB | | dc-polyfill | 0.1.10 | 26.73 kB | 26.73 kB | | tlhunter-sorted-set | 0.1.0 | 24.94 kB | 24.94 kB | | shell-quote | 1.8.3 | 23.74 kB | 23.74 kB | | limiter | 1.1.5 | 23.17 kB | 23.17 kB | | retry | 0.13.1 | 18.85 kB | 18.85 kB | | semifies | 1.0.0 | 15.84 kB | 15.84 kB | | jest-docblock | 29.7.0 | 8.99 kB | 12.76 kB | | crypto-randomuuid | 1.0.0 | 11.18 kB | 11.18 kB | | ttl-set | 1.0.0 | 4.61 kB | 9.69 kB | | mutexify | 1.4.0 | 5.71 kB | 8.74 kB | | path-to-regexp | 0.1.12 | 6.6 kB | 6.6 kB | | module-details-from-path | 1.0.4 | 3.96 kB | 3.96 kB | | escape-string-regexp | 5.0.0 | 3.66 kB | 3.66 kB |🤖 This report was automatically generated by heaviest-objects-in-the-universe |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #6968 +/- ##
=======================================
Coverage 84.94% 84.94%
=======================================
Files 514 514
Lines 21754 21754
=======================================
Hits 18478 18478
Misses 3276 3276 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This comment has been minimized.
This comment has been minimized.
BenchmarksBenchmark execution time: 2025-11-28 11:01:42 Comparing candidate commit 630cc07 in PR branch Found 0 performance improvements and 0 performance regressions! Performance is the same for 288 metrics, 32 unstable metrics. |
watson
force-pushed
the
watson/auto-gen-license-csv
branch
15 times, most recently
from
November 27, 2025 13:13
a2a03b5 to
d7162dc
Compare
The file was previously maintained manually, which could easily lead to errors as the only thing validated was that the expected packages were referenced, not that the url, license or copyright information was correct. With the recent addition of support for the `dd-trace-js` repo in https://github.com/DataDog/dd-license-attribution, we can now generate this file automatically.
watson
force-pushed
the
watson/auto-gen-license-csv
branch
from
November 28, 2025 10:47
d7162dc to
46a60dc
Compare
This reverts commit 46a60dc.
watson
marked this pull request as ready for review
November 28, 2025 10:57
bengl
approved these changes
Dec 2, 2025
sdavtaker
self-requested a review
December 4, 2025 16:12
dd-octo-sts Bot
pushed a commit
that referenced
this pull request
Dec 6, 2025
The file was previously maintained manually, which could easily lead to errors as the only thing validated was that the expected packages were referenced, not that the url, license or copyright information was correct. With the recent addition of support for the `dd-trace-js` repo in https://github.com/DataDog/dd-license-attribution, we can now generate this file automatically.
Merged
BridgeAR
pushed a commit
that referenced
this pull request
Dec 17, 2025
The file was previously maintained manually, which could easily lead to errors as the only thing validated was that the expected packages were referenced, not that the url, license or copyright information was correct. With the recent addition of support for the `dd-trace-js` repo in https://github.com/DataDog/dd-license-attribution, we can now generate this file automatically.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What does this PR do?
LICENSE-3rdparty.csvwith auto-generated version that doesn't include dev-dependencies, but does include sub-dependencies (which the manually maintained version didn't)LICENSE-3rdparty.csv(similar to the manually maintainedfilerows in the old version ofLICENSE-3rdparty.csv). Note that the row for the previously vendoredprofile.protodependency has been removed in this PR, as the vendored dependency was apparently deleted long agoscripts/check_licenses.jsto support new file formatTo-do:
scripts/check_licenses.jsto work with this new formatdd-license-attributionwith root package incorrectly being named the repo url instead of the name frompackage.json(this should have been addressed by Extract Node.js root package metadata frompackage.jsondd-license-attribution#120, but something isn't working as expected)LICENSE-3rdparty.csvdirectly in a PR whosyarn.lockfile is modified (otherwise this will block Dependabot PRs)scripts/check_licenses.jsshould also validate sub-dependenciesdd-license-attributionsometimes fails to fetch the copyright and adds agit+prefix to the urlfilein the old format is okGITHUB_TOKENwith the permissionscontent-readandmetadata-readand access to the internal repoopenfeature-js-client(issue: it will expire after max 30 days) or alternatively look into open sourcingopenfeature-js-client(preferable, if it doesn't contain any secrets)dd-trace-js-license-attribution-readpolicy to be made available (https://github.com/DataDog/.github/pull/77)Motivation
With the recent addition of support for the
dd-trace-jsrepo in https://github.com/DataDog/dd-license-attribution, we can now generate this file automatically. This comes with the following benefits:LICENSE-3rdparty.csvfileurl,licenseandcopyrightcolumns up to date, even if they change after the dependency is first addedAdditional Notes
The following command was used to generate the
LICENSE-3rdparty.csvfile:The following PRs to
dd-license-attributionwere prerequisites for this PR:package.jsondd-license-attribution#120Note on testing
This workflow cannot be tested until it lands in
masterdue to security constraints. The workflow usespull_request_targetinstead ofpull_request, which means it runs using the workflow definition from the base branch (master) rather than from the PR branch. This is necessary to satisfy the trust policy for thedd-octo-sts-action, which requires that the workflow run in the context of the protectedmasterbranch (ref: refs/heads/master,ref_protected: "true"). This security design prevents attackers from modifying the workflow in a malicious PR to exfiltrate the STS token. Once merged tomaster, the workflow will automatically run on all subsequent PRs that modifyyarn.lock, and will check out and analyze the PR's code while maintaining the security guarantees of running the trusted workflow definition frommaster.