Skip to content

License: enumerate bundled MIT UI components in sdist PKG-INFO License-File #755

Description

@elijahbenizzy

Raised by Jarek Potiuk during the 0.42.0-incubating RC3 PPMC review. Non-blocking for the release.

Issue

The sdist tarball's PKG-INFO License-File metadata only references LICENSE-wheel, NOTICE, and DISCLAIMER. It does not separately enumerate the third-party MIT-licensed UI components in website/src/components/ui/ (Magic UI + shadcn).

The components ARE properly attributed in the LICENSE file (Apache 2.0 + appended MIT notices), and our .rat-excludes covers them. So this is a metadata-completeness gap, not a licensing gap.

What downstream tooling expects

Some downstream consumers (e.g. PyPI license scanners, package indexers, Linux distro packagers) read License-File to enumerate every distinct license file shipped with the artifact. Today they would see only Apache 2.0 + the project NOTICE/DISCLAIMER and might miss that there are MIT components inside.

Suggested fix

Either:

  • Split out the MIT notices for the UI components into a separate file (e.g. LICENSE-third-party-ui) and add it to pyproject.toml's license-files list
  • Or add the existing combined LICENSE file to the sdist license-files list (it already contains the Apache 2.0 text + MIT appendices)

The latter is simpler. The former is more discoverable.

References

Activity

  1. Haricharanpanjwani commented on Jun 4, 2026

    @Haricharanpanjwani
    Contributor

    @elijahbenizzy I can work on this, please assign it to me

  2. github-actions commented on Jul 8, 2026

    @github-actions

    @Haricharanpanjwani, this issue has been inactive for 15 days.
    Are you still working on it? Drop a comment to let us know.

    If there is no update within 7 days, the assignment will be removed
    so someone else can pick it up
    (per the assignment policy).

  3. Haricharanpanjwani commented on Jul 8, 2026

    @Haricharanpanjwani
    Contributor

    @Haricharanpanjwani, this issue has been inactive for 15 days. Are you still working on it? Drop a comment to let us know.

    If there is no update within 7 days, the assignment will be removed so someone else can pick it up (per the assignment policy).

    I am working on it, will have the PR soon

  4. Haricharanpanjwani commented on Jul 9, 2026

    @Haricharanpanjwani
    Contributor

    @andreahlert @elijahbenizzy can you please review the PR #835?

  5. github-actions commented on Jul 29, 2026

    @github-actions

    @Haricharanpanjwani, this issue has been inactive for 20 days.
    Are you still working on it? Drop a comment to let us know.

    If there is no update within 7 days, the assignment will be removed
    so someone else can pick it up
    (per the assignment policy).

  6. Haricharanpanjwani commented on Aug 1, 2026

    @Haricharanpanjwani
    Contributor

    @Haricharanpanjwani, this issue has been inactive for 20 days. Are you still working on it? Drop a comment to let us know.

    If there is no update within 7 days, the assignment will be removed so someone else can pick it up (per the assignment policy).

    I am waiting for review on PR #835 from @andreahlert @elijahbenizzy

  7. jernejfrank commented on Aug 13, 2026

    @jernejfrank
    Contributor

    Sorry, I missed this completely.

    This has been resolved indirectly by #858, which excludes website/** from the sdist. Since the referenced MIT-licensed UI components are no longer packaged there, they no longer need to be enumerated in the sdist’s License-File metadata. Closing as superseded.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions