Skip to content

chore: license compliance for published artifacts - #80

Open
dskarzh wants to merge 7 commits into
thingsboard:release/4.3from
dskarzh:chore/license-compliance-4.3
Open

dskarzh wants to merge 7 commits into
thingsboard:release/4.3from
dskarzh:chore/license-compliance-4.3

Conversation

@dskarzh

@dskarzh dskarzh commented Oct 1, 2026 •

Copy link
Copy Markdown

Part of the license compliance work across ThingsBoard-owned dependencies, along the same lines as thingsboard/tbel#52, thingsboard/protobuf-dynamic#4 and thingsboard/springdoc-openapi#3.

This PR targets release/4.3, so the changes ship with the next 4.3.x client (4.3.1.6). #81 applies the same commits to master.

Changes

SPDX license headers. Every file the license plugin covers now starts with a two-line SPDX header in place of the year-stamped Apache block (Copyright © 2026-2026 ThingsBoard, Inc. plus the full notice):

// SPDX-FileCopyrightText: Copyright ThingsBoard, Inc.
// SPDX-License-Identifier: Apache-2.0
  • license-maven-plugin is upgraded from 3.0 to 5.1.2, configured with licenseSets and the single-line // style for Java, the same as license-server.
  • license-header-template.txt is renamed to license-header.txt, since it is no longer a template, and holds just the two SPDX lines. The unused owner property is gone.
  • generate-client.sh already runs mvn license:format after generation, so regenerated sources get the new header without any script change.
  • .github/workflows/ci.yml no longer carries a header. It stays excluded from the plugin.
  • The diff of this commit consists only of header lines.

Templates derived from OpenAPI Generator. openapi/api.mustache and openapi/pojo.mustache are edited copies of the OpenAPI Generator 7.20.0 templates (Java/libraries/native/api.mustache and Java/pojo.mustache). Most of their text is still upstream's. OpenAPI Generator licenses its templates under Apache-2.0, so these two now carry SPDX-FileCopyrightText: Modifications Copyright ThingsBoard, Inc. instead of claiming plain ThingsBoard copyright. They are excluded from the license plugin so that license:format does not overwrite that header. The other four templates (api_doc, model_doc, pojo_doc, enum_outer_doc) were written from scratch and keep the standard header.

The generated Java sources keep the plain ThingsBoard header. OpenAPI Generator states that generated code is not subject to its license and is owned by the user (README, section 3.4 "License information on Generated Code").

LICENSE. The file is restored to the canonical Apache License 2.0 text, with https URLs. The appendix had its placeholders filled in (Copyright 2016 The Thingsboard Authors, with {} in place of []); it is boilerplate showing how to apply the license, so it should keep the placeholders.

License text in the published jars. LICENSE is now packaged as META-INF/LICENSE in the main and sources jars of every module. Before this, the published jars contained no license text.

SPDX license name. The pom declares Apache License 2.0, the SPDX full name, instead of Apache License, Version 2.0.

thingsboard-client-common is no longer deployed. The module stays: it is where ThingsboardClient and RetryingHttpClient are edited and tested, and generate-client.sh copies those sources into every edition. Its own jar is of no use to consumers, though:

  • it contains only the hand-written classes;
  • it fails with NoClassDefFoundError without an edition jar, since ThingsboardClient extends the generated ThingsboardApi;
  • next to an edition jar it duplicates classes that jar already contains;
  • nothing depends on it.

The README already described it as "not published separately". It now really is not. The versions already published to the repository are unaffected.

README. The ## License section becomes ## Licensing, using the same wording as the other ThingsBoard repositories.

Published artifacts after this change

thingsboard-client-parent (pom), plus thingsboard-ce-client, thingsboard-pe-client and thingsboard-paas-client (jar, sources jar, pom). Each jar contains META-INF/LICENSE.

Merging release/4.3 into master

When release/4.3 is next merged forward, pe/src/main/java/org/thingsboard/client/model/ComplexOperation.java will produce a modify/delete conflict. master deleted that generated file in 9108cbf, and this PR rewrites its header. Resolve it by keeping the deletion. Everything else merges cleanly, because both PRs change the shared files' headers identically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant