build: ship generated dependency licenses with the app and SDK - #445
Merged
Merged
Conversation
Shift, its packages, and its crates are now dual-licensed so the editor SDK, Rust core, and format tooling can be embedded and reused by open and closed products alike. The Cargo workspace declares the license once and every crate inherits it. Releases and the SDK package now carry both license texts and a third-party notices file with the bundled fonts' OFL-1.1 text, the GlyphsInfo BSD-3-Clause notice, and the Slug renderer attribution.
Desktop packaging regenerates THIRD_PARTY_LICENSES.txt before each pack from the desktop's production npm closure and the crates compiled into the native bridge, and bundles it beside the license texts. Packing the SDK writes the same file for the npm packages its source maps show were bundled. Packages that ship no license file are listed with their declared license, followed by the standard MIT and Apache-2.0 texts. The packaged-app smoke test and packed SDK test now fail when any license file is missing.
Contributor
…nses # Conflicts: # apps/desktop/electron-builder.config.ts # packages/sdk/package.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
























Summary
scripts/generate-third-party-licenses.mjs, which writes the license texts of the dependencies an artifact ships, grouping packages that share identical textbeforePackhook regeneratesTHIRD_PARTY_LICENSES.txtfrom the production npm closure of@shift/desktopand the crates compiled into the native bridge, andextraResourcesbundles it; this runs in every existing packaging workflow without new CI stepsprepackwritesTHIRD_PARTY_LICENSES.txtfor the npm packages the built bundle's source maps show were included, plus Tailwind for the stylesheet anduse-sync-external-storefor the vendored selector shimLICENSE-MIT,LICENSE-APACHE,THIRD_PARTY_NOTICES.md, orTHIRD_PARTY_LICENSES.txtis missingIssue
Closes #444
Testing
node scripts/generate-third-party-licenses.mjs desktop …— 274 dependencies, no unknown licensesnode scripts/generate-third-party-licenses.mjs sdk …— 15 bundled dependenciespnpm --filter @shift-editor/sdk test:packed— the packed SDK includes all four license files; Vite and Next consumers still build and runelectron-builder --linux dirafter deleting the generated file —beforePackrecreated it andresources/contains both license texts, both notices files, andTHIRD_PARTY_LICENSES.txtpnpm format:check,pnpm lint:check,pnpm typecheck,pnpm deadcode:strict, and pre-commit hooksThe macOS package target was not verified locally: this environment's Xcode lacks the
actoolthat the existing icon step requires, sopnpm packagefails before packing onmainas well. The license hook ran before that failure and produced the file; CI's macOS packaging exercises the full path.🤖 Generated with Claude Code