Skip to content

chore(release): port the dependency license check from shell to Python - #3379

Merged
CTTY merged 1 commit into
apache:mainfrom
dannycjones:port-dependency-check-to-python
Oct 9, 2026
Merged

CTTY merged 1 commit into
apache:mainfrom
dannycjones:port-dependency-check-to-python

Conversation

@dannycjones

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

Part of the solution for #3239.

What changes are included in this PR?

This PR migrates from the old shell script for cargo-deny to a new Python script.
This new script will contain logic for dealing with dependencies and their licenses. This commit simply translates the existing logic.

In later changes, this script will be extended with:

  • Clarifications for existing dependencies where licenses are misreported, with additional verifications added in the script itself
  • Logic for generating the attribution documentation for the pyiceberg-core package.

Are these changes tested?

No. I have done manual testing but I have not invested in automated testing here.

AI Disclosure

I used an LLM to generate the outline. It also suggested the additional checks after highlighting that errors were not reported by cargo-deny and cargo-about.

I have reviewed and stand by all changes.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 11:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

3 open findings
What changed in this PR

Migrates the Rust dependency license validation step from a Bash script to a Python CLI, updating developer docs, Make targets, and CI to use the new entrypoint.

Changes:

  • Added dev/release/licenses.py implementing dependencies check via cargo deny check license
  • Updated docs/scripts/Makefile/CI to invoke the new Python command
  • Removed the legacy dev/release/dependencies.sh
File Description
website/​src/​release.md Updates release instructions to use the new Python CLI.
dev/​release/​licenses.py New Python CLI replacing the Bash license check logic.
dev/​release/​dependencies.sh Removes the old Bash implementation.
dev/​release/​create_rc.sh Routes RC creation license checks through the new Python CLI and requires python3.
dev/​release/​README.md Updates local release docs to the new Python command and notes CI coverage.
Makefile Swaps make target to run the Python-based license check.
.github/​workflows/​ci.yml Installs Python and switches CI dependency license step to the Python CLI.

🧠 Review effort: Lite


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml Outdated
Comment thread dev/release/licenses.py Outdated
Comment thread .github/workflows/ci.yml
@dannycjones

Copy link
Copy Markdown
Contributor Author

FYI, I opened the following PR to preview the full changes we're working towards: #3380

@dannycjones
dannycjones marked this pull request as draft October 9, 2026 12:53
This change migrates from the old shell script for cargo-deny to a new Python script.
This new script will contain logic for dealing with dependencies and their licenses. This commit simply translates the existing logic.

In later changes, this script will be extended with:
- Clarifications for existing dependencies where licenses are misreported, with additional verifications added in the script itself
- Logic for generating the attribution documentation for the pyiceberg-core package.
@dannycjones
dannycjones force-pushed the port-dependency-check-to-python branch from ee1eed1 to 4a3c5f9 Compare October 9, 2026 18:39
@dannycjones
dannycjones marked this pull request as ready for review October 9, 2026 18:41
@dannycjones

Copy link
Copy Markdown
Contributor Author

@CTTY or @kevinjqliu, would you be able to help push this one through? Thanks in advance!

FYI, I have a draft of all the changes coming here: #3380

@CTTY CTTY left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks Danny for working on this! we have one less loose end now :D

@CTTY
CTTY added this pull request to the merge queue Oct 9, 2026
Merged via the queue into apache:main with commit e8ec7f8 Oct 9, 2026
25 checks passed
@dannycjones
dannycjones deleted the port-dependency-check-to-python branch October 10, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants