Skip to content

build: ship generated dependency licenses with the app and SDK - #445

Merged
kostyafarber merged 4 commits into
mainfrom
build/dependency-licenses
Sep 27, 2026
Merged

kostyafarber merged 4 commits into
mainfrom
build/dependency-licenses

Conversation

@kostyafarber

@kostyafarber kostyafarber commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • add scripts/generate-third-party-licenses.mjs, which writes the license texts of the dependencies an artifact ships, grouping packages that share identical text
  • desktop: an electron-builder beforePack hook regenerates THIRD_PARTY_LICENSES.txt from the production npm closure of @shift/desktop and the crates compiled into the native bridge, and extraResources bundles it; this runs in every existing packaging workflow without new CI steps
  • SDK: prepack writes THIRD_PARTY_LICENSES.txt for the npm packages the built bundle's source maps show were included, plus Tailwind for the stylesheet and use-sync-external-store for the vendored selector shim
  • packages that declare a license but ship no license file are listed with their declared license, followed by the standard MIT and Apache-2.0 texts
  • the packaged-app smoke test and the packed SDK test fail when LICENSE-MIT, LICENSE-APACHE, THIRD_PARTY_NOTICES.md, or THIRD_PARTY_LICENSES.txt is missing

Issue

Closes #444

Testing

  • node scripts/generate-third-party-licenses.mjs desktop … — 274 dependencies, no unknown licenses
  • node scripts/generate-third-party-licenses.mjs sdk … — 15 bundled dependencies
  • pnpm --filter @shift-editor/sdk test:packed — the packed SDK includes all four license files; Vite and Next consumers still build and run
  • electron-builder --linux dir after deleting the generated file — beforePack recreated it and resources/ contains both license texts, both notices files, and THIRD_PARTY_LICENSES.txt
  • pnpm format:check, pnpm lint:check, pnpm typecheck, pnpm deadcode:strict, and pre-commit hooks

The macOS package target was not verified locally: this environment's Xcode lacks the actool that the existing icon step requires, so pnpm package fails before packing on main as well. The license hook ran before that failure and produced the file; CI's macOS packaging exercises the full path.

🤖 Generated with Claude Code

Shift, its packages, and its crates are now dual-licensed so the editor
SDK, Rust core, and format tooling can be embedded and reused by open
and closed products alike. The Cargo workspace declares the license
once and every crate inherits it.

Releases and the SDK package now carry both license texts and a
third-party notices file with the bundled fonts' OFL-1.1 text, the
GlyphsInfo BSD-3-Clause notice, and the Slug renderer attribution.
Desktop packaging regenerates THIRD_PARTY_LICENSES.txt before each pack
from the desktop's production npm closure and the crates compiled into
the native bridge, and bundles it beside the license texts. Packing the
SDK writes the same file for the npm packages its source maps show were
bundled. Packages that ship no license file are listed with their
declared license, followed by the standard MIT and Apache-2.0 texts.

The packaged-app smoke test and packed SDK test now fail when any
license file is missing.
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Installed app screenshots

Platform Result
macOS arm64 ✅ success
Windows x64 ✅ success
Linux x64 ✅ success
Screenshots
Scenario macOS arm64 Windows x64 Linux x64
Launcher window macOS arm64 Launcher window Windows x64 Launcher window Linux x64 Launcher window
Launcher desktop macOS arm64 Launcher desktop Windows x64 Launcher desktop Linux x64 Launcher desktop
Document window macOS arm64 Document window Windows x64 Document window Linux x64 Document window
Document desktop macOS arm64 Document desktop Windows x64 Document desktop Linux x64 Document desktop
File association window macOS arm64 File association window Windows x64 File association window Linux x64 File association window
File association desktop macOS arm64 File association desktop Windows x64 File association desktop Linux x64 File association desktop
Application menu macOS arm64 Application menu Windows x64 Application menu Linux x64 Application menu
Native dialog macOS arm64 Native dialog Windows x64 Native dialog Linux x64 Native dialog

View workflow run

Screenshots are review artifacts, not pixel-gated baselines. Public PNGs expire after 14 days.

@kostyafarber
kostyafarber changed the base branch from chore/relicense to main September 27, 2026 19:09
@kostyafarber
kostyafarber added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit 01238fb Sep 27, 2026
33 of 53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ship generated dependency licenses with desktop releases and the SDK

1 participant