Skip to content

ci(deps): scope Go patent-license exception - #93

Merged
AetherAI3 merged 1 commit into
mainfrom
codex/antiflock-dependency-policy-20260922
Sep 22, 2026
Merged

AetherAI3 merged 1 commit into
mainfrom
codex/antiflock-dependency-policy-20260922

Conversation

@AetherAI3

Copy link
Copy Markdown
Owner

Outcome

Allows the Go project's patent-license metadata only for golang.org/x/net and golang.org/x/sys, which unblocks the pending Go dependency update without broadening the repository license allowlist.

Safety

  • Package-URL scoped to exactly two Go modules.
  • High/critical vulnerability review remains enabled.
  • The modules remain BSD-3-Clause licensed; the extra scanner identifier represents Go's royalty-free patent grant.

Train position

Built from current main after #92. Merge this before rebuilding the Go dependency group.

@AetherAI3
AetherAI3 merged commit d861044 into main Sep 22, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant