Comments (1)
This is a great question. I'd like to think about it a bit longer, but offhand, I'm not sure my studio currently has a need to track licenses in a way that's tightly coupled to the rez package. I recognize you're probably thinking further ahead, and I'd love to discuss it at an upcoming meeting.
We definitely check licenses and are careful about any use restrictions, but our overall tracking is more associated with regular checks of the source code, bringing OSS into the studio, and specific handoffs. Our rez packages are only consumed within our studio and the licensing has already been managed at that point.
We don't use rez-pip due to limitations in the original, and are interested in the new version but haven't had a chance to try it out. The pip install domain certainly makes this more exciting, when dozens of dependencies are brought in automatically. We perform some checks of those dependencies.
It's absolutely valuable when licenses are clearly defined. There's too much ambiguity in the OSS world with how licenses are associated with code.
from rez.
Related Issues (20)
- Missleading warning due to gitbash shell plugin ignoring its config settings HOT 3
- Error searching for plugins if there is an empty package folder in the repo
- Docs still say that it works with Python 2
- Add type hinting
- Remove all traces of Python 2 HOT 2
- Remove `from __future__ import print_function` from the code base
- Replace `rez.utils.data_utils.cached_property` with `functools.cached_property` HOT 3
- TSC Meeting 2024-02-15
- Support virtualenv during installation
- Remove `rez.utils.py23`
- Replace usages of `rez.vendor.enum` with the built-in enum module HOT 1
- Add `SECURITY.md` (security policy, threat model, etc)
- Improve contributing guidelines
- Implement OpenSSF Scorecard HOT 1
- Track code coverage
- Refresh "Getting Started" documentation
- Implement SAST tool HOT 3
- Document how to communicate with maintainers and report issues HOT 1
- Address python warnings
- Sign release artifacts and git tags
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from rez.