fix: pack the NOTICE file - #2282
Open
justFU7 wants to merge 2 commits into
Open
Conversation
The published tarball has never contained it, so downstream redistributors cannot carry the attribution notices Apache-2.0 section 4(d) asks them to preserve.
justFU7
requested review from
AayushSaini101,
Amzani,
Shurtu-gal,
Souvikns and
asyncapi-bot-eve
as code owners
August 17, 2026 20:10
Contributor
There was a problem hiding this comment.
Welcome to AsyncAPI. Thanks a lot for creating your first pull request. Please check out our contributors guide useful for opening a pull request.
Keep in mind there are also other channels you can use to interact with AsyncAPI community. For more details check out this issue.
🦋 Changeset detectedLatest commit: 0b1d9b7 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
The repository has a
NOTICEfile at its root, but it has never reached the published package.npmalways packsREADMEandLICENSEfrom the package root whateverfilessays, which is whythose two ship even though
filesnames neither.NOTICEis not on that automatic list, so it needs anexplicit entry - and it does not have one.
Evidence from the published artifact
@asyncapi/cli@6.0.2packs 267 entries. Its root level is:No
NOTICE.Why it matters
Apache-2.0 section 4(d) puts the obligation on whoever redistributes the work: if the distribution
includes a
NOTICE, the attribution notices in it have to be carried along. Anyone repackaging@asyncapi/cli- a Docker image, a vendored bundle, a downstream CLI - only ever receives the npmtarball, so today they have no way to comply. Shipping the file is what makes that possible.
Changes
One line:
"/NOTICE"added to thefilesarray. No behaviour change, no new dependency, nothing elsetouched.
Verifying
NOTICEnow appears in the pack listing.