Add third-party license notices to native packages - #8594
Draft
cknitt wants to merge 2 commits into
Draft
Conversation
Signed-off-by: Christoph Knittel <ck@cca.io>
cknitt
force-pushed
the
codex/third-party-licenses
branch
from
August 29, 2026 05:04
00a08aa to
3e4cda7
Compare
Signed-off-by: Christoph Knittel <ck@cca.io>
cknitt
force-pushed
the
codex/third-party-licenses
branch
from
August 29, 2026 05:09
3e4cda7 to
21709c8
Compare
rescript
@rescript/belt
@rescript/darwin-arm64
@rescript/darwin-x64
@rescript/linux-arm64
@rescript/linux-x64
@rescript/runtime
@rescript/win32-x64
commit: |
|
Developer playground preview: https://rescript-lang.github.io/rescript/dev-playground/?version=pr-8594 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds generated, target-specific THIRD_PARTY_LICENSES files to the native platform packages.
The notices cover:
Repeated Rust standard-library notices are deduplicated while preserving the complete license and attribution information.
The root rescript package does not ship the notice bundle because it contains no native binaries. @rescript/runtime and @rescript/belt are also unaffected and remain MIT-licensed.
Generation and package-content checks run in CI, and notices are regenerated when publishing.
During the source audit, we found that the Rewatch queue implementation had been copied from rawnly/queue-rs, which has no declared license or license file. It has therefore been replaced with a small, independently written implementation providing only the operations Rewatch uses.