Skip to content

Correct source links and modified-source notices in third-party README - #481

Open
tonygermano wants to merge 3 commits into
OpenIntegrationEngine:mainfrom
tonygermano:maint/third-party-readme
Open

tonygermano wants to merge 3 commits into
OpenIntegrationEngine:mainfrom
tonygermano:maint/third-party-readme

Conversation

@tonygermano

Copy link
Copy Markdown
Member

Summary

Follow-up to #477, which must merge first. At time of opening, the first two of five commits in this PR are from that one and will drop after a rebase. Further cleanup of server/docs/thirdparty/THIRD-PARTY-README.txt, so it accurately describes what the distribution ships and where to get the source of each copyleft component. It doesn't change the build or the distribution.

1. Drop license entries for libraries we don't ship

Nothing in the distribution bundles these:

  • JaCoCo 0.8.2 and args4j: these entries were added in 2019 alongside the build-time JaCoCo Ant task. args4j is a dependency of JaCoCo's command-line tool, which was never included.
  • Display tag: it was used by the JSP web admin and went away with it in 79a7c23 (Maint: Remove webadmin and manager sub-projects). It was the only Artistic License component, so ARTISTIC-LICENSE.txt
    is removed too.

2. Replace dead source links

Many copyleft source links pointed at java.net, shut down in 2017, or at other hosts that no longer serve them. Each now points at the source of the version we ship:

  • its -sources.jar on Maven Central, or
  • a release tag on GitHub: Javassist, MySQL Connector/J, Rhino, SAAJ Impl and TXW.

Each URL now sits on a single line, so it can be clicked and copied whole.

Corrections made along the way:

  • HK2: labeled 2.4.0-b31, which is what ships. AOP Alliance Repackaged is part of HK2, so it now links its own b31 sources jar instead of the upstream AOP Alliance project.
  • PDF Renderer: now states version 1.0.5. The vendored jar is pdf-renderer 1.0.5 from Maven Central with its signature removed: every class and resource is byte-identical.
  • Eclipse JDT: both mentions point at ecj-3.19.0-sources.jar. Before, one linked the project homepage and the other pointed at a source-tree path that no longer holds the jar.
  • Install paths: dropped the [Install Folder] paths from the Eclipse JDT and PDF Renderer sections. The source links replace them, and the paths go stale whenever a jar is renamed or moved.
  • OSGi Resource Locator links its 1.0.1 sources jar instead of master. iText uses the direct Maven Central path instead of a search.maven.org redirect.
  • Labels:
    • SwingX is 1.6.2-2.
    • javaparser is LGPL 3 or later, per its source headers.
    • The JSON Processing entries no longer name a JSR. The number was wrong (374 instead of 353) and would go stale again on an upgrade to 1.1.
  • Trailing periods: removed from bare URLs, since auto-linkers include them in the link.

3. Point to modified copyleft sources

We ship modified files from dcm4che (MPL 1.1), Rhino (MPL 2.0), jTDS (LGPL 2.1) and Jersey (CDDL). The licenses require making the modified source available. Previously the README only gave a location for the
Jersey changes. The dcm4che, Rhino and jTDS entries now name where the modified source lives in this repository.

Testing

  • Every changed link returns HTTP 200 and points at the shipped version. I spot-checked sources jars and they contain real .java source.
  • Checked versions against gradle/libs.versions.toml and the staged distribution. Scanned every jar in the distribution and found no JaCoCo, args4j or Display tag classes.

Not in this PR

  • Swinglabs Wizard: its source link is still dead. The library isn't on Maven Central and needs a separate decision.

🤖 Generated with Claude Code

@tonygermano tonygermano added this to the Next Release milestone Oct 9, 2026
@tonygermano
tonygermano requested review from a team, gibson9583, kayyagari, kpalang and ssrowe October 9, 2026 15:34
@tonygermano tonygermano added the licensing Eclipse Intellectual Property (IP) due diligence: licensing, provenance, Dash results, IP reviews label Oct 9, 2026
@tonygermano tonygermano changed the title Maint/third party readme Correct source links and modified-source notices in third-party README Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Test Results

128 files  128 suites   3m 53s ⏱️
729 tests 729 ✅ 0 💤 0 ❌
819 runs  813 ✅ 6 💤 0 ❌

Results for commit a90f0ad.

♻️ This comment has been updated with latest results.

mgaffigan
mgaffigan previously approved these changes Oct 9, 2026
THIRD-PARTY-README.txt has license sections for JaCoCo 0.8.2, args4j
and the Display tag library, but nothing in the distribution bundles
them.

- The JaCoCo and args4j entries were added in 2019 alongside the
  build-time JaCoCo Ant task. args4j is a dependency of JaCoCo's
  command-line tool, which was never included.
- Display tag was used by the JSP web admin and left with it in
  79a7c23 ("Maint: Remove webadmin and manager sub-projects").

Remove them. Display tag was the only Artistic License component, so
remove ARTISTIC-LICENSE.txt as well.

Signed-off-by: Tony Germano <tony@germano.name>
Assisted-by: Claude:claude-opus-5-5
The README tells recipients where to get the source of the copyleft
components we ship, and many of those links point at java.net (shut
down in 2017) or other hosts that no longer serve them. Point each one
at the source of the version we ship: its -sources.jar on Maven
Central, or its release tag on GitHub for Javassist, MySQL
Connector/J, Rhino and SAAJ Impl. Pin the TXW link to its release tag
and the OSGi Resource Locator link to its -sources.jar instead of
master, and move iText's link from the search.maven.org redirect to
the same Maven Central path as the others. Keep each URL on a single
line, even past 80 columns, so it can be clicked and copied whole.

Along the way:

- HK2 ships 2.4.0-b31, not the 2.4.0-b34 the old link named. AOP
  Alliance Repackaged is part of HK2 and ships the same version, so
  link its -sources.jar instead of the upstream AOP Alliance project.
- Note where the modified Jersey WebResourceFactory source lives in
  this repository.
- Name PDF Renderer's version, 1.0.5: the vendored jar is
  pdf-renderer 1.0.5 from Maven Central with its signature removed
  (every class and resource is byte-identical; only the manifest
  digests and the signature files differ).
- Point both Eclipse JDT mentions at ecj's -sources.jar: the EPL entry
  linked the project homepage, and the license section pointed at
  lib/jetty/jsp in the source tree, which no longer holds the jar.
- Drop the [Install Folder] paths from the Eclipse JDT and PDF
  Renderer sections. The source links make them unnecessary, and
  they go stale whenever a jar is renamed or moved.
- Label SwingX 1.6.2-2 to match the version that ships and its link.
- javaparser is LGPL 3 or later according to its source headers, not
  LGPL 2.1.
- Drop the JSR number from the JSON Processing entries. They said
  JSR 374, but 1.0 is JSR 353, and the number would go stale again on
  an upgrade to 1.1; the version alone identifies the library.
- Drop the sentence-ending periods after bare URLs, which auto-linkers
  include in the link.

The Swinglabs Wizard link is still dead: that library is not on Maven
Central and needs a separate decision.

Signed-off-by: Tony Germano <tony@germano.name>
Assisted-by: Claude:claude-opus-5-5
We ship modified copies of files from dcm4che (MPL 1.1), Rhino
(MPL 2.0) and jTDS (LGPL 2.1), and both licenses require making the
source of those modifications available. The README said the files
were changed but not where to find the changed versions. Point each
entry at the modified source in this repository, as the Jersey entry
already does.

Signed-off-by: Tony Germano <tony@germano.name>
Assisted-by: Claude:claude-opus-5-5
@tonygermano

Copy link
Copy Markdown
Member Author

Rebased after merging parent PR to drop first two commits.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

licensing Eclipse Intellectual Property (IP) due diligence: licensing, provenance, Dash results, IP reviews

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants