Skip to content

docs(assembly): add v3.2.3 third-party notice draft - #2830

Open
dillon-zheng wants to merge 1 commit into
pingcap:release-3.2from
dillon-zheng:draft/add-v3-2-3-third-party-notices
Open

docs(assembly): add v3.2.3 third-party notice draft#2830
dillon-zheng wants to merge 1 commit into
pingcap:release-3.2from
dillon-zheng:draft/add-v3-2-3-third-party-notices

Conversation

@dillon-zheng

@dillon-zheng dillon-zheng commented Aug 28, 2026

Copy link
Copy Markdown

What problem does this PR solve?

Issue Number: ref #2831

The TiSpark v3.2.3 Spark 3.0 assembly has no release-scoped third-party notice in its packaged JAR. This PR adds an evidence-based draft notice for repository-owner and compliance review.

What is changed and how it works?

  • Add assembly/src/main/assembly/ThirdPartyNotices.txt.
    • Scope: the published v3.2.3 Spark 3.0 assembly baseline, SHA-256 116a2ac7909cbe6cbab038f7219d299a6fcefe60ae8120de748ed07aae9eba64.
    • The draft inventories 92 evidenced payload components and retains collected upstream/assembly legal material.
    • It deliberately remains marked DRAFT and NOT APPROVED FOR RELEASE.
  • Add it to the assembly descriptor so the built JAR contains ThirdPartyNotices.txt at its root.

Review required before removing the draft marker or using this notice in a release:

  • Confirm the proposed SPDX expressions, including dual-license choices for JNA, JAXB API, and checker-compat-qual.
  • Confirm ownership/retention decisions for 16 final legal assets and 29 native assets, including Netty tcnative/BoringSSL material.
  • Confirm whether org.tikv:tikv-client-java is handled as a third-party component or under a first-party policy.

Check List

Tests

  • Manual test: mvn -pl assembly -DskipTests -DskipCloneProtoFiles=true package
    • Build succeeds.
    • ThirdPartyNotices.txt is present at the root of assembly/target/tispark-assembly-3.0_2.12-3.2.3.jar.
    • Its SHA-256 in the built JAR matches the source file: d9445b79854c451fc96ecd32361bfc1d324dfab0fd9d62066399733198cc0509.
  • git diff --check

Code changes

  • Has exported function/method change
  • Has exported variable/fields change
  • Has interface methods change
  • Has persistent data change

Side effects

  • Possible performance regression
  • Increased code complexity
  • Breaking backward compatibility

Related changes

  • Need to cherry-pick to the release branch
  • Need to update the documentation
  • Need to update the tidb-ansible repository
  • Need to be included in the release note

@ti-chi-bot

ti-chi-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign birdstorm for approval. For more information see the Code Review Process.
Please ensure that each of them provides their approval before proceeding.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ti-chi-bot
ti-chi-bot Bot requested a review from zhangyangyu August 28, 2026 00:58
@pingcap-cla-assistant

pingcap-cla-assistant Bot commented Aug 28, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@dillon-zheng

Copy link
Copy Markdown
Author

/type development

@dillon-zheng

Copy link
Copy Markdown
Author

/type enhancement

@dillon-zheng

Copy link
Copy Markdown
Author

/type type/enhancement

@dillon-zheng
dillon-zheng marked this pull request as ready for review September 4, 2026 08:28
@dillon-zheng

Copy link
Copy Markdown
Author

/retest

1 similar comment
@dillon-zheng

Copy link
Copy Markdown
Author

/retest

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant