Skip to content

MAINT update NOTICE generation - #2599

Merged
Roman Lutz (romanlutz) merged 3 commits into
microsoft:mainfrom
romanlutz:romanlutz-notice-generation
Sep 8, 2026
Merged

MAINT update NOTICE generation#2599
Roman Lutz (romanlutz) merged 3 commits into
microsoft:mainfrom
romanlutz:romanlutz-notice-generation

Conversation

@romanlutz

@romanlutz Roman Lutz (romanlutz) commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Description

  • refresh NOTICE.txt from Component Governance
  • detect Python dependencies directly from uv.lock and frontend dependencies from package-lock.json
  • publish the generated NOTICE artifact on every Component Governance run
  • report whether NOTICE.txt differs from the artifact without failing or blocking pull requests

Automation

A recurring session automation checks for an updated Component Governance artifact every 30 days. It creates or updates a draft NOTICE pull request only when the generated content changes.

Validation

Component Governance generated the lockfile-based artifact twice with identical output, and the final non-blocking pipeline completed successfully.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@romanlutz
Roman Lutz (romanlutz) marked this pull request as ready for review September 8, 2026 19:05
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Sep 8, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 8, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Sep 8, 2026
Merged via the queue into microsoft:main with commit 48384c0 Sep 8, 2026
47 checks passed
@romanlutz
Roman Lutz (romanlutz) deleted the romanlutz-notice-generation branch September 8, 2026 20:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants