postjevsql.git / tools / third-party-notices

For agents, on top of README.md, which they read first.

  • Never hand-edit THIRD-PARTY or THIRD-PARTY-sidecar. Run buck2 run //tools/third-party-notices:update; :drift fails until you do.
  • Never keep a second list of crates, urls or hashes. The archives are read through $(query_outputs …), which reaches third-party/BUCK's private http_archive targets where a dep cannot (reindeer hard-codes their visibility = []).
  • A crate with no licence expression or no text fails the build, on purpose. Fix it with a texts/<name>-<version>/ entry fetched from upstream at that version, with a SOURCE; an entry for a crate linked into neither binary, or one that ships its own text, fails too, so the folder cannot go stale.
  • Generate both files in one run. One texts/ serves both, and its staleness check is against the union.
  • texts/ gets no README pair: its subfolders are fetched upstream texts, a mechanical shard explained here.