Repository navigation
Correct source links and modified-source notices in third-party README - #481
Open
tonygermano wants to merge 3 commits into
Open
tonygermano wants to merge 3 commits into
tonygermano wants to merge 3 commits into
Conversation
tonygermano
requested review from
a team,
gibson9583,
kayyagari,
kpalang and
ssrowe
October 9, 2026 15:34
Test Results128 files 128 suites 3m 53s ⏱️ Results for commit a90f0ad. ♻️ This comment has been updated with latest results. |
mgaffigan
previously approved these changes
Oct 9, 2026
THIRD-PARTY-README.txt has license sections for JaCoCo 0.8.2, args4j and the Display tag library, but nothing in the distribution bundles them. - The JaCoCo and args4j entries were added in 2019 alongside the build-time JaCoCo Ant task. args4j is a dependency of JaCoCo's command-line tool, which was never included. - Display tag was used by the JSP web admin and left with it in 79a7c23 ("Maint: Remove webadmin and manager sub-projects"). Remove them. Display tag was the only Artistic License component, so remove ARTISTIC-LICENSE.txt as well. Signed-off-by: Tony Germano <tony@germano.name> Assisted-by: Claude:claude-opus-5-5
The README tells recipients where to get the source of the copyleft components we ship, and many of those links point at java.net (shut down in 2017) or other hosts that no longer serve them. Point each one at the source of the version we ship: its -sources.jar on Maven Central, or its release tag on GitHub for Javassist, MySQL Connector/J, Rhino and SAAJ Impl. Pin the TXW link to its release tag and the OSGi Resource Locator link to its -sources.jar instead of master, and move iText's link from the search.maven.org redirect to the same Maven Central path as the others. Keep each URL on a single line, even past 80 columns, so it can be clicked and copied whole. Along the way: - HK2 ships 2.4.0-b31, not the 2.4.0-b34 the old link named. AOP Alliance Repackaged is part of HK2 and ships the same version, so link its -sources.jar instead of the upstream AOP Alliance project. - Note where the modified Jersey WebResourceFactory source lives in this repository. - Name PDF Renderer's version, 1.0.5: the vendored jar is pdf-renderer 1.0.5 from Maven Central with its signature removed (every class and resource is byte-identical; only the manifest digests and the signature files differ). - Point both Eclipse JDT mentions at ecj's -sources.jar: the EPL entry linked the project homepage, and the license section pointed at lib/jetty/jsp in the source tree, which no longer holds the jar. - Drop the [Install Folder] paths from the Eclipse JDT and PDF Renderer sections. The source links make them unnecessary, and they go stale whenever a jar is renamed or moved. - Label SwingX 1.6.2-2 to match the version that ships and its link. - javaparser is LGPL 3 or later according to its source headers, not LGPL 2.1. - Drop the JSR number from the JSON Processing entries. They said JSR 374, but 1.0 is JSR 353, and the number would go stale again on an upgrade to 1.1; the version alone identifies the library. - Drop the sentence-ending periods after bare URLs, which auto-linkers include in the link. The Swinglabs Wizard link is still dead: that library is not on Maven Central and needs a separate decision. Signed-off-by: Tony Germano <tony@germano.name> Assisted-by: Claude:claude-opus-5-5
We ship modified copies of files from dcm4che (MPL 1.1), Rhino (MPL 2.0) and jTDS (LGPL 2.1), and both licenses require making the source of those modifications available. The README said the files were changed but not where to find the changed versions. Point each entry at the modified source in this repository, as the Jersey entry already does. Signed-off-by: Tony Germano <tony@germano.name> Assisted-by: Claude:claude-opus-5-5
tonygermano
force-pushed
the
maint/third-party-readme
branch
from
October 9, 2026 20:05
e9898a9 to
a90f0ad
Compare
Member
Author
|
Rebased after merging parent PR to drop first two commits. |
mgaffigan
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #477, which must merge first. At time of opening, the first two of five commits in this PR are from that one and will drop after a rebase. Further cleanup of
server/docs/thirdparty/THIRD-PARTY-README.txt, so it accurately describes what the distribution ships and where to get the source of each copyleft component. It doesn't change the build or the distribution.1. Drop license entries for libraries we don't ship
Nothing in the distribution bundles these:
ARTISTIC-LICENSE.txtis removed too.
2. Replace dead source links
Many copyleft source links pointed at java.net, shut down in 2017, or at other hosts that no longer serve them. Each now points at the source of the version we ship:
-sources.jaron Maven Central, orEach URL now sits on a single line, so it can be clicked and copied whole.
Corrections made along the way:
pdf-renderer1.0.5 from Maven Central with its signature removed: every class and resource is byte-identical.ecj-3.19.0-sources.jar. Before, one linked the project homepage and the other pointed at a source-tree path that no longer holds the jar.[Install Folder]paths from the Eclipse JDT and PDF Renderer sections. The source links replace them, and the paths go stale whenever a jar is renamed or moved.master. iText uses the direct Maven Central path instead of asearch.maven.orgredirect.3. Point to modified copyleft sources
We ship modified files from dcm4che (MPL 1.1), Rhino (MPL 2.0), jTDS (LGPL 2.1) and Jersey (CDDL). The licenses require making the modified source available. Previously the README only gave a location for the
Jersey changes. The dcm4che, Rhino and jTDS entries now name where the modified source lives in this repository.
Testing
.javasource.gradle/libs.versions.tomland the staged distribution. Scanned every jar in the distribution and found no JaCoCo, args4j or Display tag classes.Not in this PR
🤖 Generated with Claude Code