Skip to content

Engage in the IP Due Diligence process for third party assets #320

@waynebeaton

Description

@waynebeaton

AFAICT, the Eclipse VOLTTRON project team has not engaged in the IP Due Diligence Process for third-party dependencies.

Per the Eclipse Committer Due Diligence Guidelines, we depend on committers to help us identify content that requires licence review. There is some help in the handbook.

The EMO provides the Eclipse Dash License Tool to help vet third-party content, but the tool needs to be provided with a list of dependencies. I did a quick spot check on dependencies specified in your pyproject.toml file, but I lack the necessary knowledge and skills to extract a complete list of the resolved dependencies.

The Eclipse Dash License Tool document has some examples of how to generate list of dependencies and vet them; you should be able to find a good starting point there (I failed to get deptree to work, I'm hopeful that you will have better luck).

The Dash License Tool has an option to automatically create review request records to engage IP Team and resolve the outstanding licence information.

Please engage in the IP Due Diligence process.

fyi @mtdelgadoa

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions