Skip to content

Add SPDX license header checker and missing headers - #372

Open
shreyah963 wants to merge 4 commits into
opensearch-project:mainfrom
shreyah963:add-spdx-license-header-checker
Open

shreyah963 wants to merge 4 commits into
opensearch-project:mainfrom
shreyah963:add-spdx-license-header-checker

Conversation

@shreyah963

@shreyah963 shreyah963 commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Description

Add SPDX license header validation to PR/push workflows using @kt3k/license-checker.

Changes:

  • Add .github/workflows/license-header-checker.yml
  • Add .licenserc.json
  • Add missing SPDX-License-Identifier: Apache-2.0 headers to source files

Related Issues

#6445

Related Issues

Resolves #[Issue number to be closed when this PR is merged]

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: shreyah963 <shreyab963@gmail.com>
@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 17a4861.

⛔ Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
.github/workflows/license-header-checker.yml12highNew npm package introduced via `npx @kt3k/license-checker@3.2.2` in a CI workflow. Per mandatory supply chain policy, any dependency addition must be flagged regardless of apparent legitimacy. Maintainers should verify the authenticity and integrity of this package on the npm registry before merging.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@shreyah963
shreyah963 marked this pull request as ready for review September 15, 2026 19:24
@codecov

codecov Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 48.88%. Comparing base (b140da4) to head (fa4dd11).

Additional details and impacted files
@@             Coverage Diff              @@
##               main     #372      +/-   ##
============================================
- Coverage     48.96%   48.88%   -0.09%     
+ Complexity      193      192       -1     
============================================
  Files            54       54              
  Lines          1162     1162              
  Branches         64       64              
============================================
- Hits            569      568       -1     
- Misses          557      558       +1     
  Partials         36       36              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@reta reta added the skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. label Sep 15, 2026
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- name: Add License Header
run: npx @kt3k/license-checker@3.2.2

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@peterzhuamazon @gaiksaya this looks off, we should be using commit sha, not a version tag, please correct me here, if that is safe to go

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes should be commit SHA. @shreyah963 Looks like we are directly running it so needs to SHA to be more secure. I suspect the GHA guardrail did not catch it because it was not an action.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately the source repo kt3k/license_checker is a Deno project and doesn't have a package.json at root so npx can't install it directly from a git commit hash. The CI fails with 'ENOENT: no such file or directory, open package.json'.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @shreyah963 , @gaiksaya are we OK with that? Thanks!

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ No major issues detected

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants