Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/update-3rdparty-licenses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: Update 3rd-party licenses
on:
pull_request:
paths:
- 'yarn.lock'
- "yarn.lock"

jobs:
update-3rdparty-licenses:
Expand All @@ -19,13 +19,13 @@ jobs:
- name: Set up Python
uses: actions/setup-python@83679a892e2d95755f2dac6acb0bfd1e9ac5d548 # v6.1.0
with:
python-version: '3.14'
python-version: "3.14"

- name: Check out dd-license-attribution
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
repository: DataDog/dd-license-attribution
ref: 58e29701db6c72889f9298ff59717987404659c8
ref: 224a89cb69d3143e8aa4640405037cf9c233ddf5
path: dd-license-attribution

- name: Install dd-license-attribution
Expand Down
157 changes: 78 additions & 79 deletions LICENSE-3rdparty.csv
Original file line number Diff line number Diff line change
@@ -1,79 +1,78 @@
"component","origin","license","copyright"
"@datadog/flagging-core","https://github.com/DataDog/openfeature-js-client","['Apache-2.0']","['DataDog']"
"@datadog/libdatadog","https://github.com/DataDog/libdatadog-nodejs","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-appsec","https://github.com/DataDog/dd-native-appsec-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-iast-taint-tracking","https://github.com/DataDog/dd-native-iast-taint-tracking-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-metrics","https://github.com/DataDog/dd-native-metrics-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/openfeature-node-server","https://github.com/DataDog/openfeature-js-client","['Apache-2.0']","['DataDog']"
"@datadog/pprof","https://github.com/DataDog/pprof-nodejs","['Apache-2.0']","['Google Inc.']"
"@datadog/sketches-js","https://github.com/DataDog/sketches-js","['Apache-2.0']","['DataDog']"
"@datadog/source-map","npm:@datadog/source-map","[]","[]"
"@datadog/wasm-js-rewriter","https://github.com/DataDog/dd-wasm-js-rewriter","['Apache-2.0']","['Datadog Inc.']"
"@isaacs/ttlcache","https://github.com/isaacs/ttlcache","['BlueOak-1.0.0']","['Isaac Z. Schlueter']"
"@jsep-plugin/assignment","https://github.com/EricSmekens/jsep","['MIT']","['Shelly']"
"@jsep-plugin/regex","https://github.com/EricSmekens/jsep","['MIT']","['Shelly']"
"@openfeature/server-sdk","https://github.com/open-feature/js-sdk","['Apache-2.0']","['open-feature']"
"@opentelemetry/api","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/api-logs","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/core","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/resources","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/semantic-conventions","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@protobufjs/aspromise","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/base64","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/codegen","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/eventemitter","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/fetch","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/float","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/inquire","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/path","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/pool","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/utf8","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@types/node","https://github.com/DefinitelyTyped/DefinitelyTyped","['MIT']","['DefinitelyTyped']"
"acorn","https://github.com/acornjs/acorn","['MIT']","['acornjs']"
"acorn-import-attributes","https://github.com/xtuc/acorn-import-attributes","['MIT']","['Sven Sauleau']"
"argparse","https://github.com/nodeca/argparse","['Python-2.0']","['nodeca']"
"astring","https://github.com/davidbonnet/astring","['MIT']","['David Bonnet']"
"cjs-module-lexer","https://github.com/nodejs/cjs-module-lexer","['MIT']","['Guy Bedford']"
"crypto-randomuuid","npm:crypto-randomuuid","['MIT']","['Stephen Belanger']"
"dc-polyfill","https://github.com/DataDog/dc-polyfill","['MIT']","['Thomas Hunter II']"
"dd-trace","https://github.com/DataDog/dd-trace-js","['(Apache-2.0 OR BSD-3-Clause)']","['Datadog Inc. <info@datadoghq.com>']"
"delay","https://github.com/sindresorhus/delay","['MIT']","['Sindre Sorhus']"
"detect-newline","https://github.com/sindresorhus/detect-newline","['MIT']","['Sindre Sorhus']"
"escape-string-regexp","https://github.com/sindresorhus/escape-string-regexp","['MIT']","['Sindre Sorhus']"
"esquery","https://github.com/estools/esquery","['BSD-3-Clause']","['Joel Feenstra']"
"estraverse","https://github.com/estools/estraverse","['BSD-2-Clause']","['estools']"
"fast-fifo","https://github.com/mafintosh/fast-fifo","['MIT']","['Mathias Buus']"
"ignore","https://github.com/kaelzhang/node-ignore","['MIT']","['kael']"
"import-in-the-middle","https://github.com/nodejs/import-in-the-middle","['Apache-2.0']","['Bryan English']"
"istanbul-lib-coverage","https://github.com/istanbuljs/istanbuljs","['BSD-3-Clause']","['Krishnan Anantheswaran']"
"jest-docblock","https://github.com/jestjs/jest","['MIT']","['jestjs']"
"js-yaml","https://github.com/nodeca/js-yaml","['MIT']","['Vladimir Zapparov']"
"jsep","https://github.com/EricSmekens/jsep","['MIT']","['Stephen Oney']"
"jsonpath-plus","https://github.com/JSONPath-Plus/JSONPath","['MIT']","['Stefan Goessner']"
"limiter","https://github.com/jhurliman/node-rate-limiter","['MIT']","['John Hurliman']"
"lodash.sortby","https://github.com/lodash/lodash","['MIT']","['John-David Dalton']"
"long","https://github.com/dcodeIO/long.js","['Apache-2.0']","['Daniel Wirtz']"
"lru-cache","https://github.com/isaacs/node-lru-cache","['ISC']","['Isaac Z. Schlueter']"
"meriyah","https://github.com/meriyah/meriyah","['ISC']","['Kenny F.']"
"module-details-from-path","https://github.com/watson/module-details-from-path","['MIT']","['Thomas Watson']"
"mutexify","https://github.com/mafintosh/mutexify","['MIT']","['Mathias Buus']"
"node-addon-api","https://github.com/nodejs/node-addon-api","['MIT']","['nodejs']"
"node-gyp-build","https://github.com/prebuild/node-gyp-build","['MIT']","['Mathias Buus']"
"opentracing","https://github.com/opentracing/opentracing-javascript","['Apache-2.0']","['opentracing']"
"p-limit","https://github.com/sindresorhus/p-limit","['MIT']","['Sindre Sorhus']"
"path-to-regexp","https://github.com/pillarjs/path-to-regexp","['MIT']","['pillarjs']"
"pprof-format","https://github.com/DataDog/pprof-format","['MIT']","['Datadog Inc.']"
"protobufjs","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"queue-tick","https://github.com/mafintosh/queue-tick","['MIT']","['Mathias Buus']"
"retry","https://github.com/tim-kos/node-retry","['MIT']","['Tim Koschützki']"
"rfdc","https://github.com/davidmarkclements/rfdc","['MIT']","['David Mark Clements']"
"semifies","https://github.com/holepunchto/semifies","['Apache-2.0']","['Holepunch Inc']"
"shell-quote","https://github.com/ljharb/shell-quote","['MIT']","['James Halliday']"
"source-map","https://github.com/mozilla/source-map","['BSD-3-Clause']","['Nick Fitzgerald']"
"spark-md5","https://github.com/satazor/js-spark-md5","['(WTFPL OR MIT)']","['André Cruz']"
"tlhunter-sorted-set","https://github.com/tlhunter/node-sorted-set","['MIT']","['Thomas Hunter II']"
"ttl-set","https://github.com/watson/ttl-set","['MIT']","['Thomas Watson']"
"undici-types","https://github.com/nodejs/undici","['MIT']","['nodejs']"
"yocto-queue","https://github.com/sindresorhus/yocto-queue","['MIT']","['Sindre Sorhus']"
"aws-lambda-nodejs-runtime-interface-client","https://github.com/aws/aws-lambda-nodejs-runtime-interface-client/blob/v2.1.0/src/utils/UserFunction.ts","['Apache-2.0']","['Amazon.com Inc. or its affiliates']"
"is-git-url","https://github.com/jonschlinkert/is-git-url/blob/396965ffabf2f46656c8af4c47bef1d69f09292e/index.js#L9C15-L9C87","['MIT']","['Jon Schlinkert']"
"component","origin","license","copyright"
"@datadog/flagging-core","https://github.com/DataDog/openfeature-js-client","['Apache-2.0']","['DataDog']"
"@datadog/libdatadog","https://github.com/DataDog/libdatadog-nodejs","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-appsec","https://github.com/DataDog/dd-native-appsec-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-iast-taint-tracking","https://github.com/DataDog/dd-native-iast-taint-tracking-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/native-metrics","https://github.com/DataDog/dd-native-metrics-js","['Apache-2.0']","['Datadog Inc.']"
"@datadog/openfeature-node-server","https://github.com/DataDog/openfeature-js-client","['Apache-2.0']","['DataDog']"
"@datadog/pprof","https://github.com/DataDog/pprof-nodejs","['Apache-2.0']","['Google Inc.']"
"@datadog/sketches-js","https://github.com/DataDog/sketches-js","['Apache-2.0']","['DataDog']"
"@datadog/wasm-js-rewriter","https://github.com/DataDog/dd-wasm-js-rewriter","['Apache-2.0']","['Datadog Inc.']"
"@isaacs/ttlcache","https://github.com/isaacs/ttlcache","['BlueOak-1.0.0']","['Isaac Z. Schlueter']"
"@jsep-plugin/assignment","https://github.com/EricSmekens/jsep","['MIT']","['Shelly']"
"@jsep-plugin/regex","https://github.com/EricSmekens/jsep","['MIT']","['Shelly']"
"@openfeature/server-sdk","https://github.com/open-feature/js-sdk","['Apache-2.0']","['open-feature']"
"@opentelemetry/api","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/api-logs","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/core","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/resources","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@opentelemetry/semantic-conventions","https://github.com/open-telemetry/opentelemetry-js","['Apache-2.0']","['OpenTelemetry Authors']"
"@protobufjs/aspromise","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/base64","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/codegen","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/eventemitter","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/fetch","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/float","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/inquire","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/path","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/pool","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@protobufjs/utf8","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"@types/node","https://github.com/DefinitelyTyped/DefinitelyTyped","['MIT']","['DefinitelyTyped']"
"acorn","https://github.com/acornjs/acorn","['MIT']","['acornjs']"
"acorn-import-attributes","https://github.com/xtuc/acorn-import-attributes","['MIT']","['Sven Sauleau']"
"argparse","https://github.com/nodeca/argparse","['Python-2.0']","['nodeca']"
"astring","https://github.com/davidbonnet/astring","['MIT']","['David Bonnet']"
"cjs-module-lexer","https://github.com/nodejs/cjs-module-lexer","['MIT']","['Guy Bedford']"
"crypto-randomuuid","npm:crypto-randomuuid","['MIT']","['Stephen Belanger']"
"dc-polyfill","https://github.com/DataDog/dc-polyfill","['MIT']","['Thomas Hunter II']"
"dd-trace","https://github.com/DataDog/dd-trace-js","['(Apache-2.0 OR BSD-3-Clause)']","['Datadog Inc. <info@datadoghq.com>']"
"delay","https://github.com/sindresorhus/delay","['MIT']","['Sindre Sorhus']"
"detect-newline","https://github.com/sindresorhus/detect-newline","['MIT']","['Sindre Sorhus']"
"escape-string-regexp","https://github.com/sindresorhus/escape-string-regexp","['MIT']","['Sindre Sorhus']"
"esquery","https://github.com/estools/esquery","['BSD-3-Clause']","['Joel Feenstra']"
"estraverse","https://github.com/estools/estraverse","['BSD-2-Clause']","['estools']"
"fast-fifo","https://github.com/mafintosh/fast-fifo","['MIT']","['Mathias Buus']"
"ignore","https://github.com/kaelzhang/node-ignore","['MIT']","['kael']"
"import-in-the-middle","https://github.com/nodejs/import-in-the-middle","['Apache-2.0']","['Bryan English']"
"istanbul-lib-coverage","https://github.com/istanbuljs/istanbuljs","['BSD-3-Clause']","['Krishnan Anantheswaran']"
"jest-docblock","https://github.com/jestjs/jest","['MIT']","['jestjs']"
"js-yaml","https://github.com/nodeca/js-yaml","['MIT']","['Vladimir Zapparov']"
"jsep","https://github.com/EricSmekens/jsep","['MIT']","['Stephen Oney']"
"jsonpath-plus","https://github.com/JSONPath-Plus/JSONPath","['MIT']","['Stefan Goessner']"
"limiter","https://github.com/jhurliman/node-rate-limiter","['MIT']","['John Hurliman']"
"lodash.sortby","https://github.com/lodash/lodash","['MIT']","['John-David Dalton']"
"long","https://github.com/dcodeIO/long.js","['Apache-2.0']","['Daniel Wirtz']"
"lru-cache","https://github.com/isaacs/node-lru-cache","['ISC']","['Isaac Z. Schlueter']"
"meriyah","https://github.com/meriyah/meriyah","['ISC']","['Kenny F.']"
"module-details-from-path","https://github.com/watson/module-details-from-path","['MIT']","['Thomas Watson']"
"mutexify","https://github.com/mafintosh/mutexify","['MIT']","['Mathias Buus']"
"node-addon-api","https://github.com/nodejs/node-addon-api","['MIT']","['nodejs']"
"node-gyp-build","https://github.com/prebuild/node-gyp-build","['MIT']","['Mathias Buus']"
"opentracing","https://github.com/opentracing/opentracing-javascript","['Apache-2.0']","['opentracing']"
"p-limit","https://github.com/sindresorhus/p-limit","['MIT']","['Sindre Sorhus']"
"path-to-regexp","https://github.com/pillarjs/path-to-regexp","['MIT']","['pillarjs']"
"pprof-format","https://github.com/DataDog/pprof-format","['MIT']","['Datadog Inc.']"
"protobufjs","https://github.com/protobufjs/protobuf.js","['BSD-3-Clause']","['Daniel Wirtz']"
"queue-tick","https://github.com/mafintosh/queue-tick","['MIT']","['Mathias Buus']"
"retry","https://github.com/tim-kos/node-retry","['MIT']","['Tim Koschützki']"
"rfdc","https://github.com/davidmarkclements/rfdc","['MIT']","['David Mark Clements']"
"semifies","https://github.com/holepunchto/semifies","['Apache-2.0']","['Holepunch Inc']"
"shell-quote","https://github.com/ljharb/shell-quote","['MIT']","['James Halliday']"
"source-map","https://github.com/mozilla/source-map","['BSD-3-Clause']","['Nick Fitzgerald']"
"spark-md5","https://github.com/satazor/js-spark-md5","['(WTFPL OR MIT)']","['André Cruz']"
"tlhunter-sorted-set","https://github.com/tlhunter/node-sorted-set","['MIT']","['Thomas Hunter II']"
"ttl-set","https://github.com/watson/ttl-set","['MIT']","['Thomas Watson']"
"undici-types","https://github.com/nodejs/undici","['MIT']","['nodejs']"
"yocto-queue","https://github.com/sindresorhus/yocto-queue","['MIT']","['Sindre Sorhus']"
"aws-lambda-nodejs-runtime-interface-client","https://github.com/aws/aws-lambda-nodejs-runtime-interface-client/blob/v2.1.0/src/utils/UserFunction.ts","['Apache-2.0']","['Amazon.com Inc. or its affiliates']"
"is-git-url","https://github.com/jonschlinkert/is-git-url/blob/396965ffabf2f46656c8af4c47bef1d69f09292e/index.js#L9C15-L9C87","['MIT']","['Jon Schlinkert']"
47 changes: 44 additions & 3 deletions scripts/check_licenses.js
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ const { execSync } = require('node:child_process')
const { name: rootPackageName } = require('../package.json')

const filePath = join(__dirname, '..', 'LICENSE-3rdparty.csv')
const aliasMap = getAliasMap()
const deps = getProdDeps()
const licenses = new Set()
let isHeader = true
Expand Down Expand Up @@ -39,7 +40,7 @@ lineReader.on('close', () => {

function getProdDeps () {
// Add root package (dd-trace) to the set of dependencies manually as it is not included in the yarn list output.
const deps = new Set([rootPackageName])
const deps = new Set([normalizeDepName(rootPackageName)])

addProdDeps(deps, process.cwd())
addProdDeps(deps, join(process.cwd(), 'vendor'))
Expand Down Expand Up @@ -72,7 +73,7 @@ function collectFromTrees (trees, deps) {
if (typeof node?.name !== 'string') continue

// Remove version from the package name (e.g. `@protobufjs/pool@1.1.0` -> `@protobufjs/pool`)
deps.add(node.name.slice(0, node.name.lastIndexOf('@')))
deps.add(normalizeDepName(node.name.slice(0, node.name.lastIndexOf('@'))))

if (Array.isArray(node.children) && node.children.length) {
collectFromTrees(node.children, deps)
Expand All @@ -99,10 +100,50 @@ function addVendoredDeps (deps) {
const component = columns[0]

// Strip quotes from the component name and add to deps
deps.add(component.replaceAll(/^"|"$/g, ''))
deps.add(normalizeDepName(component.replaceAll(/^"|"$/g, '')))
}
}

function getAliasMap () {
const rootPackagePath = join(__dirname, '..', 'package.json')
const vendorPackagePath = join(__dirname, '..', 'vendor', 'package.json')
const map = new Map()

collectAliasesFromPackageJson(rootPackagePath, map)
collectAliasesFromPackageJson(vendorPackagePath, map)

return map
}

function collectAliasesFromPackageJson (packagePath, map) {
if (!existsSync(packagePath)) return

const packageJson = require(packagePath)
const deps = packageJson?.dependencies ?? {}
const optionalDeps = packageJson?.optionalDependencies ?? {}

collectAliasesFromDeps(deps, map)
collectAliasesFromDeps(optionalDeps, map)
}

function collectAliasesFromDeps (deps, map) {
for (const [alias, spec] of Object.entries(deps)) {
if (typeof spec !== 'string' || !spec.startsWith('npm:')) continue

const rawTarget = spec.slice('npm:'.length)
const atIndex = rawTarget.lastIndexOf('@')
const target = atIndex > 0 ? rawTarget.slice(0, atIndex) : rawTarget

if (target) {
map.set(alias, target)
}
}
}

function normalizeDepName (name) {
return aliasMap.get(name) ?? name
}

function checkLicenses (typeDeps) {
const missing = []
const extraneous = []
Expand Down