Skip to content

build: ship third-party license for bundled code - #11

Merged
rishvic merged 1 commit into
mainfrom
build/ship-third-party-notices
May 30, 2026
Merged

build: ship third-party license for bundled code#11
rishvic merged 1 commit into
mainfrom
build/ship-third-party-notices

Conversation

@rishvic

@rishvic rishvic commented May 30, 2026

Copy link
Copy Markdown
Contributor

tsdown inlines the Vite-derived code in src/html.ts and src/utils.ts into dist/ and strips their SPDX headers, so the published tarball shipped MIT-licensed code with no permission notice.

  • Add THIRD-PARTY-NOTICES.txt with Vite copyright + verbatim MIT text and include it, NOTICE, and CHANGELOG.md in package.json "files".
  • Trim NOTICE to the minimal Apache attribution; per Apache guidance the MIT notice belongs in the notices file, not NOTICE. Repoint the README acknowledgement there.
  • Note in tsdown.config.ts that bundling a dependency obligates updating THIRD-PARTY-NOTICES.txt.

tsdown inlines the Vite-derived code in src/html.ts and src/utils.ts
into dist/ and strips their SPDX headers, so the published tarball
shipped MIT-licensed code with no permission notice.

- Add THIRD-PARTY-NOTICES.txt with Vite copyright + verbatim MIT text
  and include it, NOTICE, and CHANGELOG.md in package.json "files".
- Trim NOTICE to the minimal Apache attribution; per Apache guidance the
  MIT notice belongs in the notices file, not NOTICE. Repoint the README
  acknowledgement there.
- Note in tsdown.config.ts that bundling a dependency obligates updating
  THIRD-PARTY-NOTICES.txt.
@changeset-bot

changeset-bot Bot commented May 30, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: fe5d930

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@smoothtml/vite-plugin-sri Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@rishvic
rishvic merged commit fe5d930 into main May 30, 2026
2 checks passed
@rishvic
rishvic deleted the build/ship-third-party-notices branch May 30, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant