diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3308335..0b10d81 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -88,6 +88,10 @@ jobs: uses: docker/metadata-action@v6 with: images: ${{ env.IMAGE }} + # The default comes from the repository's license (MIT) and would replace the + # Dockerfile's label, but the image also bundles Apache-2.0 licensed ocr. + labels: | + org.opencontainers.image.licenses=MIT AND Apache-2.0 # latest follows main only; the default (auto) would also move it on every v* tag. flavor: latest=false # Lowest priority, so the version passed to the build is sha- on main, not "latest". diff --git a/Dockerfile b/Dockerfile index 534b2b6..2e86a97 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,12 +26,17 @@ RUN apk add --no-cache curl \ && curl -fsSLO "https://github.com/alibaba/open-code-review/releases/download/${OCR_VERSION}/opencodereview-linux-${arch}" \ && curl -fsSLO "https://github.com/alibaba/open-code-review/releases/download/${OCR_VERSION}/sha256sum.txt" \ && grep " opencodereview-linux-${arch}\$" sha256sum.txt | sha256sum -c - \ - && install -m 0755 "opencodereview-linux-${arch}" /out-ocr + && install -m 0755 "opencodereview-linux-${arch}" /out-ocr \ + && curl -fsSL -o /out-ocr-LICENSE "https://raw.githubusercontent.com/alibaba/open-code-review/${OCR_VERSION}/LICENSE" FROM alpine:3 # OCR needs git >= 2.41; alpine:3 ships a current git. RUN apk add --no-cache git ca-certificates COPY --from=ocr /out-ocr /usr/local/bin/ocr COPY --from=build /out/pruefbyte /usr/local/bin/pruefbyte +# pruefbyte is MIT licensed; the bundled ocr binary is Apache-2.0. +COPY LICENSE /usr/share/licenses/pruefbyte/LICENSE +COPY --from=ocr /out-ocr-LICENSE /usr/share/licenses/open-code-review/LICENSE +LABEL org.opencontainers.image.licenses="MIT AND Apache-2.0" ENTRYPOINT [] CMD ["pruefbyte", "review"] diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..fc48bd0 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 feinarbyte GmbH + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index f6993c3..f235f48 100644 --- a/README.md +++ b/README.md @@ -153,3 +153,11 @@ Layout: | `internal/gitutil` | reads the repo config at the base commit; fetches missing commits | OCR is used as a subprocess. Its Go packages all live under `internal/`, so they can't be imported from another module; its JSON output is the stable interface. + +## License + +pruefbyte is released under the [MIT License](LICENSE). + +The Docker image also bundles the OpenCodeReview (`ocr`) binary, which is +licensed under the [Apache License 2.0](https://github.com/alibaba/open-code-review/blob/main/LICENSE). +Both license texts are in the image under `/usr/share/licenses/`.