Skip to content

ci: check dependency licenses with cargo-deny on every PR - #3293

Open
comphead wants to merge 1 commit into
apache:mainfrom
comphead:cargo-deny-license-check
Open

comphead wants to merge 1 commit into
apache:mainfrom
comphead:cargo-deny-license-check

Conversation

@comphead

Copy link
Copy Markdown
Collaborator

Which issue does this PR close?

What changes are included in this PR?

The lint job in ci.yml now runs dev/release/dependencies.sh check, the same cargo deny license check the release process runs. A PR that adds a dependency whose license deny.toml does not allow now fails CI instead of being caught at release time. cargo-deny 0.19.9 is installed by the existing taiki-e/install-action step, matching the version pinned in dependencies.sh. lint already feeds ci-required, so .asf.yaml does not change.

deny.toml now sets [graph] all-features = true. Without it, cargo-deny only follows default features. #3143 removed opendal-all from the Python bindings, so the default graph no longer includes the optional OpenDAL backends (gcs, oss, azdls, hf). Today the default graph has 503 crates and the all-features graph has 619. The missing crates include the two MPL-2.0 crates that deny.toml has exceptions for (colored and option-ext, pulled in by opendal-service-hf). This setting also applies to the release-time check.

Other changes:

  • make check-dependency-licenses runs the check locally, and make check now includes it.
  • CONTRIBUTING.md describes the license policy and what to do when the check rejects a license.
  • The release docs point to make install-cargo-deny for the pinned version and note that CI already runs the check.
  • Two comments in dependencies.sh no longer refer to the CI TSV check removed in chore: Move dependency list generation back to release manager task #2706.

As suggested in #3233, the release-time check in create_rc.sh stays. TSV generation is unchanged.

Unlike the TSV check reverted in #2706, this check does not ask PRs to regenerate any files. Dependabot PRs pass unless an update brings in a license that deny.toml does not allow.

Are these changes tested?

Tested locally with cargo-deny 0.19.9:

  • dev/release/dependencies.sh check and make check-dependency-licenses pass on this branch.
  • Removing the colored exception from deny.toml makes the check fail and name colored v3.1.1. On main, the same edit still passes, because the default-feature graph does not include colored.
  • dev/release/dependencies.sh generate produces identical TSV files with and without the [graph] setting.
  • taplo fmt --check passes.

The new CI step has not run in GitHub Actions yet. This PR is its first run.

AI Disclosure

I used Claude Code, an AI coding assistant, to investigate the issue, write the changes and this description, and run the local tests above.

Areas for reviewers to check:

  • The CONTRIBUTING.md guidance on Category A, B, and X licenses describes how deny.toml handles them today. It is not a legal interpretation of the ASF policy.
  • The new CI step has only been tested locally so far.

Run `dev/release/dependencies.sh check` in the `lint` job, so a dependency
whose license is not allowed by `deny.toml` fails the pull request instead
of being found at release time.

Set `[graph] all-features = true` in `deny.toml`. Without it, cargo-deny
only follows default features. Since apache#3143 that graph no longer includes
the optional OpenDAL backends, so the check skipped the MPL-2.0 crates that
`deny.toml` has exceptions for.

Closes apache#3234.
Copilot AI lite review requested due to automatic review settings September 28, 2026 21:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Release-time cargo-deny version validation is not aligned with the CI and local tooling pin.

Review effort: Lite
Findings: None

What changed in this PR

Adds PR-time and local cargo-deny license checks, including all dependency features, with updated contributor and release documentation.

Changes:

  • Pins cargo-deny 0.19.9 for CI and local checks.
  • Enables all-feature license validation.
  • Updates license policy and release guidance.
File Summary
website/​src/​release.md Updates release tooling and license-check guidance.
Makefile Adds local license-check targets.
dev/​release/​README.md Documents pinned cargo-deny installation and CI checks.
dev/​release/​dependencies.sh Updates cargo-deny version references and validation.
deny.toml Enables all-feature dependency analysis.
CONTRIBUTING.md Documents dependency license policy.
.github/​workflows/​ci.yml Adds the CI license-check step.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dannycjones

Copy link
Copy Markdown
Contributor

Thanks for looking at this, both you and I ended up implementing similar changes. (I should have posted on #3234, my bad!)

I only opened #3299 today however my approach has been to move the invocation of cargo-deny into a Python script, as I found there were other gaps with it. It's a precursor to addressing #3239. Let me know what you think.

I do particularly like that there is guidance added to CONTRIBUTING.md here, I will take a closer look.

@dannycjones dannycjones left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Specifically took a look at the changes different from #3299.

Comment thread deny.toml
Comment on lines +22 to +25
[graph]
# Also check dependencies that only optional features pull in, such as the
# OpenDAL storage backends. Otherwise cargo-deny only follows default features.
all-features = true

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch - I do think we need this.

Comment thread CONTRIBUTING.md
Comment on lines +121 to +132
Every dependency must have a license that is compatible with the
[ASF 3rd Party License Policy](https://www.apache.org/legal/resolved.html). `deny.toml` lists the allowed licenses
and the per-crate exceptions. CI checks every pull request against it with `cargo deny`, and you can run the same
check locally with `make check-dependency-licenses`.

If the check rejects a license, look up its category in the ASF policy:

- Category A licenses can be added to `allow` in `deny.toml`.
- Category B licenses are added to `exceptions` in `deny.toml`, with one entry per crate that uses them.
- Category X licenses are not allowed, so the dependency must be replaced.

Explain any change to `deny.toml` in the pull request description.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for adding this, looks good

@dannycjones dannycjones left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! We can see the check working here: https://github.com/apache/iceberg-rust/actions/runs/36485758300/job/109142138283?pr=3293#step:11:16

Let's merge this, I'll work on dropping TSVs and then rebasing #3299 on top here. (More info: #3299 (comment))

@dannycjones

Copy link
Copy Markdown
Contributor

@kevinjqliu @laskoviymishka if either of you can help here with review and merge, it'd be much appreciated!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add cargo deny license checks to PRs

3 participants