Repository navigation
Add SPDX license header checker and missing headers - #372
shreyah963 wants to merge 4 commits into
Conversation
Signed-off-by: shreyah963 <shreyab963@gmail.com>
PR Code Analyzer ❗AI-powered 'Code-Diff-Analyzer' found issues on commit 17a4861. ⛔ Hard block: Issues at High severity or above will block this PR from merging.
The table above displays the top 10 most important findings. Pull Requests Author(s): Please update your Pull Request according to the report above. Repository Maintainer(s): You can Thanks. |
Signed-off-by: shreyah963 <shreyab963@gmail.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #372 +/- ##
============================================
- Coverage 48.96% 48.88% -0.09%
+ Complexity 193 192 -1
============================================
Files 54 54
Lines 1162 1162
Branches 64 64
============================================
- Hits 569 568 -1
- Misses 557 558 +1
Partials 36 36 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
| steps: | ||
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | ||
| - name: Add License Header | ||
| run: npx @kt3k/license-checker@3.2.2 |
There was a problem hiding this comment.
@peterzhuamazon @gaiksaya this looks off, we should be using commit sha, not a version tag, please correct me here, if that is safe to go
There was a problem hiding this comment.
Yes should be commit SHA. @shreyah963 Looks like we are directly running it so needs to SHA to be more secure. I suspect the GHA guardrail did not catch it because it was not an action.
There was a problem hiding this comment.
Unfortunately the source repo kt3k/license_checker is a Deno project and doesn't have a package.json at root so npx can't install it directly from a git commit hash. The CI fails with 'ENOENT: no such file or directory, open package.json'.
There was a problem hiding this comment.
Thanks @shreyah963 , @gaiksaya are we OK with that? Thanks!
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
Description
Add SPDX license header validation to PR/push workflows using
@kt3k/license-checker.Changes:
.github/workflows/license-header-checker.yml.licenserc.jsonSPDX-License-Identifier: Apache-2.0headers to source filesRelated Issues
#6445
Related Issues
Resolves #[Issue number to be closed when this PR is merged]
Check List
--signoff.By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.