ci: add transitive-dependency license audit (#137) - #215
Merged
Conversation
Chris-Wolfgang
force-pushed
the
ci/actions-audit
branch
from
July 21, 2026 20:30
314e1ad to
5747da6
Compare
Adds license-audit.yaml + .github/license-audit/ config. Runs nuget-license over both packable projects (TestKit + TestKit.Xunit) on PR + push + schedule, gating on an OSI-permissive allow-list and uploading a JSON inventory. xunit.abstractions 2.0.3 exposes a license URL rather than an SPDX expression; mapped to its actual license (Apache-2.0) in url-license-mappings.json. Both projects audit clean locally. Ported from D20-Dice; matrix'd for two projects. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Chris-Wolfgang
force-pushed
the
ci/license-audit
branch
from
July 21, 2026 20:30
52d3eef to
46e2289
Compare
This was referenced Jul 29, 2026
This was referenced Aug 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #214. Adds
license-audit.yaml+.github/license-audit/config. Runsnuget-licenseover both packable projects (TestKit + TestKit.Xunit) on PR + push + schedule, gating on an OSI-permissive allow-list (MIT / Apache-2.0 / BSD / MS-PL / ISC / BSL-1.0 / MPL-2.0), and uploads a JSON inventory artifact per project.Verified locally
Ran the audit against both projects' full transitive closure:
xunit.abstractions 2.0.3, which exposes a license URL (.../xunit/master/license.txt) rather than an SPDX expression. xunit is Apache-2.0; added that URL →Apache-2.0tourl-license-mappings.json(the documented mapping mechanism). Now clean (exit 0).Config (
.github/license-audit/)allowed-licenses.json— the permissive allow-list (from the canonical fleet config).ignored-packages.json—SonarAnalyzer.CSharponly (build-time analyzer,PrivateAssets=all, non-OSI Sonar license, imposes no consumer obligation).url-license-mappings.json— Microsoft fwlink + dotnet/standard + xunit URL → SPDX.Matrix'd over the two projects; artifact names disambiguated by
strategy.job-index(upload-artifact@v4 rejects duplicate names). Ported from D20-Dice.Closes #137 when the vNext cycle merges to main.
🤖 Generated with Claude Code