Skip to content

fix(core): ship the licence inside the wheel - #18

Merged
Abdeali099 merged 3 commits into
developfrom
core-license
Aug 20, 2026
Merged

Abdeali099 merged 3 commits into
developfrom
core-license

Conversation

@Abdeali099

Copy link
Copy Markdown
Member

Found while opening the actual v0.1.0 wheel to see what's in it: there's no LICENSE inside.

docsigner_core-0.1.0.dist-info/METADATA
docsigner_core-0.1.0.dist-info/WHEEL
docsigner_core-0.1.0.dist-info/top_level.txt
docsigner_core-0.1.0.dist-info/RECORD

Apache-2.0 asks for the licence and the NOTICE to travel with the code. Ours sit at the repo root, outside core/, and packaging tools can't reach above the project directory — so they were silently dropped from every build. host/'s packaging already copies both into its archive for exactly this reason; core/ never did.

The fix

core/ keeps its own copies, declared in pyproject.toml:

license-files = ["LICENSE", "NOTICE"]

That's a copy, and copies drift. So test_docs.py — which already exists to catch things that rot silently — now fails if either stops matching the root:

core/NOTICE has drifted from NOTICE at the repo root. Copy the root one over it.

Verified by building it

Not asserted from the docs — I built the wheel and looked:

docsigner_core-0.1.0.dist-info/licenses/LICENSE
docsigner_core-0.1.0.dist-info/licenses/NOTICE
License-Expression: Apache-2.0
License-File: LICENSE
License-File: NOTICE

The License-Expression line also confirms the setuptools>=77 bump from PR #9 is doing its job — older setuptools would emit the legacy free-text License: field instead.

And the drift test earns its place: appending a line to core/NOTICE fails it, restoring it passes. pytest core/tests is 126 (was 124).

Note on timing

0.1.0 is already published on the release page, and you're about to upload it to PyPI. That upload will not have the licence in it — the fix lands in 0.1.1, whenever core/ next changes. Not worth burning a version over; PyPI shows the licence in the metadata and links to the repo either way.

Not merged, as asked.

Abdeali099 and others added 3 commits August 20, 2026 12:42
The wheel had no LICENSE. Apache-2.0 asks for the licence and the NOTICE
to travel with the code, and the repo's copies sit at the root, outside
core/ -- packaging tools cannot reach above the project directory, so
they were silently left out of every build.

core/ now keeps its own copies, declared with license-files. That is a
copy, and copies drift, so test_docs.py fails if either stops matching
the root -- the same rot it already checks module maps for.

Verified by building the wheel:

    dist-info/licenses/LICENSE
    dist-info/licenses/NOTICE
    License-Expression: Apache-2.0

and by tampering with core/NOTICE, which fails the new test.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
It is the project page on PyPI now, and it was written for someone
standing in the repo. Two things were plainly wrong there:

- 'Not published to PyPI' -- it is, as of today.
- Every link was relative (../docs/core.md, ../CONTRACTS.md), so all of
  them 404 for anyone reading it on PyPI. Now absolute.

Reordered for the visitor it actually gets: what it does, what makes it
different (the interrupted session), pip install, then the two calls that
cover most uses. The exported names are listed, since PyPI is where
someone looks for them.

Dropped 'Pack it', which explained how to build a wheel by hand. CI does
that every release and docs/releasing.md covers it.

Verified: twine check PASSED on a fresh build, Description-Content-Type
is text/markdown, and no relative link remains.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Homepage was the repo root, which is about the whole product -- host,
extension, desktop app -- when the visitor arrived from one package's
page. It points at core/ now.

Documentation is new: docs/core.md is where the flow chart and the module
map are, and PyPI's sidebar was not linking to it at all. Repository
stays the root, which is what a clone needs.

All four checked for a 200, and read back out of the built wheel's
METADATA as Project-URL lines.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Abdeali099
Abdeali099 merged commit aed8c8c into develop Aug 20, 2026
16 checks passed
@Abdeali099
Abdeali099 deleted the core-license branch August 20, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant