Skip to content

Add SPDX license header checker and missing headers - #999

Draft
shreyah963 wants to merge 2 commits into
opensearch-project:mainfrom
shreyah963:add-spdx-license-header-checker
Draft

Add SPDX license header checker and missing headers#999
shreyah963 wants to merge 2 commits into
opensearch-project:mainfrom
shreyah963:add-spdx-license-header-checker

Conversation

@shreyah963

@shreyah963 shreyah963 commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Description

Add SPDX license header validation to PR/push workflows using @kt3k/license-checker.

Changes:

  • Add .github/workflows/license-header-checker.yml
  • Add .licenserc.json
  • Add missing SPDX-License-Identifier: Apache-2.0 headers to source files

Related Issues

#6445

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 8fb7425.

Hard block: Issues at High severity or above will block this PR from merging.

PathLineSeverityDescription
.github/workflows/license-header-checker.yml12highNew npm package introduced via npx: @kt3k/license-checker@3.2.2. Per mandatory supply chain policy, all new package dependencies must be flagged for maintainer verification regardless of apparent legitimacy.
.github/workflows/license-header-checker.yml10highNew GitHub Actions dependency added: actions/checkout@de0fac2. Per mandatory supply chain policy, all new build/CI plugin and action dependencies must be flagged for maintainer verification.

The table above displays the top 10 most important findings.

Total: 2 | Critical: 0 | High: 2 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

Signed-off-by: shreyah963 <shreyab963@gmail.com>
@shreyah963
shreyah963 force-pushed the add-spdx-license-header-checker branch from c1299e9 to 938c36f Compare August 26, 2026 19:58
@codecov

codecov Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 70.55%. Comparing base (3a69aab) to head (8fb7425).
⚠️ Report is 119 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main     #999      +/-   ##
============================================
- Coverage     73.97%   70.55%   -3.42%     
- Complexity      916     1149     +233     
============================================
  Files           135      175      +40     
  Lines          6102     7971    +1869     
  Branches        753      956     +203     
============================================
+ Hits           4514     5624    +1110     
- Misses         1253     1948     +695     
- Partials        335      399      +64     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Signed-off-by: shreyah963 <shreyab963@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant