[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[eclipse.org-planning-council] [Fwd: Re: Swordfish Release, Missing CQs]
- From: Wayne Beaton <wayne@xxxxxxxxxxx>
- Date: Mon, 29 Jun 2009 22:56:14 -0400
- Delivered-to: email@example.com
- User-agent: Thunderbird 18.104.22.168 (X11/20090608)
I am resending as my original note was put into a holding pattern...
-------- Original Message --------
Hello Planning Council.
It has been determined that the Swordfish project has included several
third party libraries in their downloads, their update site, and the
Galileo Update site that have not been taken through the Eclipse IP Due
Diligence process. The full list of problems is copied below.
I have been informed by the IP Team that they cannot reasonably complete
the ten reviews suggested by Oliver by Friday.
This leaves us with an IP exposure in the Galileo Update site that we
need to mitigate. I believe that the Galileo update site will need to be
respun, excluding Swordfish. I understand that this is no simple chore
and that it will require effort from many of us to complete. I assume,
for example, that the testing effort will be non-trivial.
I am seeking your guidance on how we can proceed.
I further request that the Planning Council initiate a conversation with
Swordfish on how best to move forward once the IP issues have been
Barb Cochrane wrote:
It's hard for us to predict whether we're going to be able to clarify IP
any given package. the
The best thing to do would be to start entering the CQs (attaching just
jars you require to each) so we can start to assess the packages on a
by case basis. not
From: Oliver Wolf [mailto:oliver.wolf@xxxxxxxxx]
Sent: Monday, June 29, 2009 12:05 PM
To: Runtime Project PMC mailing list; Wayne Beaton; Eclipse Management
Cc: Zsolt Beothy-Elo; Dietmar Wolz; Jürgen Kindler
Subject: Swordfish Release, Missing CQs
Dear RT PMC members, EMO, and IP team,
The Swordfish project has finalized the in-depth analysis of missing or
matching CQs. These are our findings:
1. Third party libs w/o CQ
Of these, the following ones have been unnecessarily included and can be
removed without any impact on functionality:
Of the remaining ones, one has previously been approved for use within
This leaves us with 10 jars for which new CQs would have to be filed
them Apache2-licensed, hosted at Apache and relatively small):
@IP team: Given your prior experience analyzing ServiceMix source code,
would you rate the risk?
2. Third party libs w/ CQ, but version shipped differs from CQ
org.springframework.core_2.5.6.v200906161300.jar (approved: 2.5.2)2.1.3)
org.springframework.context_2.5.6.v200906161300.jar (approved: 2.5.2)
org.springframework.beans_2.5.6.v200906161300.jar (approved: 2.5.2)
org.springframework.aop_2.5.6.v200906161300.jar (approved: 2.5.2)
org.apache.cxf.cxf-bundle_2.1.4.v200906161300.jar (approved: 2.1.3)
Of these, for one we would have to file a new CQ requesting a version
In all other cases, we'll be able to switch back to the approved
We are confident that we would be able to file the missing CQs and
and regression test a new build containing the correct versionsand with
the unnecessary jars removed until Friday EOB.
@RT PMC, EMO: Please advise us on how to proceed from here.
eclipse.org-architecture-council mailing list
IMPORTANT: Membership in this list is generated by processes internal to
the Eclipse Foundation. To be permanently removed from this list, you
must contact emo@xxxxxxxxxxx to request removal.