Skip to content

Add fail-closed runtime dependency license evidence #90

Description

@Claudio9701

Parent

Outcome

Every installed UrbanPy runtime dependency has deterministic license evidence and an explicit reviewed disposition, while the required external FOSSA findings remain visible and blocking for EL-BID review.

Scope

  • traverse the active installed runtime dependency closure, excluding dev-only extras
  • prefer PEP 639 expressions and retain legacy classifier evidence
  • fail closed on new packages, changed license metadata, and unknown licenses
  • record narrow primary-source overrides instead of globally allowing UNKNOWN
  • upload requirements and license evidence in CI
  • include license evidence with the release SBOM and attested distributions
  • document the boundary between this engineering gate and FOSSA/legal review

Acceptance criteria

  • the locked runtime closure produces a deterministic JSON report
  • all current runtime packages have a reviewed policy result
  • development-only tools do not pollute runtime evidence
  • defopt missing metadata and text-unidecode license selection cite primary sources
  • FOSSA is not removed, suppressed, or treated as resolved by this PR
  • policy drift fails CI and requires maintainer review

Follow-up EL-BID work is still required to reconcile FOSSA's full source/development/vendored finding set and document legal approval.

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:readyBounded and ready for a remote coding agentarea:releaseRelease engineeringarea:securitySecurity, licensing, and supply chain

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions