For which CNCF project are you requesting exceptions?
Hive (hivecommons/hive), CNCF Sandbox project.
Are you an official maintainer of this project?
Yes. Filed on behalf of Hive maintainers during CNCF Sandbox onboarding.
List of components requiring an exception
Distribution and integration model
Distribution and integration model — explanation
minimatch@10.2.6 appears only in hivecommons/hive under .github/scripts/package-lock.json as a transitive dev dependency of lint tooling (eslint -> minimatch ^10.2.5 and @eslint/config-array -> minimatch ^10.2.4). It is installed from npm for CI/developer lint checks of repository scripts and dashboard inline JavaScript.
It is not product/runtime code, is not vendored in the repository, is not incorporated into any Hive release artifact, and is not needed by end users to install or run Hive. The dependency is retrieved from the npm package repository at build/test tooling install time, so the use satisfies allowlist criteria 2B (not stored in the project repository; retrieved from the upstream package repository) and 3.2 (the upstream project was created in 2011 and has more than 3,000 GitHub stars). The missing allowlist criterion is only the license identifier: BlueOak-1.0.0 is not currently on the CNCF allowlist.
Modification status
Modification status — explanation
Hive does not patch, fork, vendor, or otherwise modify minimatch. It is resolved unmodified from npm through the .github/scripts/package-lock.json dependency graph.
Structural separation
Structural separation — explanation
minimatch source code is never stored in the Hive repository and is retrieved from npm into node_modules only when installing CI/development lint tooling under .github/scripts. It remains a separate npm package and is not copied into Hive source files.
Communication mechanism
Communication mechanism — explanation
For lint tooling only, Node.js loads ESLint and its transitive npm packages, including minimatch, as modules in the Node.js process. There is no static linking into a Hive binary or shipped artifact, and end users do not load this dependency when running Hive.
Data exchange
Data exchange — explanation
Hive project code does not directly exchange internal data structures with minimatch. The dependency is used inside ESLint/config-array during CI lint operations to evaluate glob patterns and file/config matching. Inputs are file paths and glob strings in the lint toolchain; no Hive runtime internals or distributed artifacts are involved.
Additional information — explanation
This request is filed even though Hive is also pursuing a belt-and-braces mitigation that pins the CI scripts' transitive minimatch dependency to the ISC-licensed 9.x line. The exception is requested because the current ESLint dependency chain can resolve minimatch@10.2.6, and ESLint >=9 / @eslint/config-array moved to minimatch ranges that include v10 after the upstream license change.
Precedent: #1434 requested a BlueOak-1.0.0 exception for Prometheus: #1434
Blue Oak Model License 1.0.0 is OSI-approved and permissive. Its published purpose says it gives "everyone as much permission to work with this software as possible" while protecting contributors from liability. Its obligations are attribution/notice-oriented and it does not impose copyleft terms.
Upstream metadata checked for allowlist context: https://github.com/isaacs/minimatch was created in 2011 and currently has more than 3,000 stars.
For which CNCF project are you requesting exceptions?
Hive (hivecommons/hive), CNCF Sandbox project.
Are you an official maintainer of this project?
Yes. Filed on behalf of Hive maintainers during CNCF Sandbox onboarding.
List of components requiring an exception
.github/scripts/package-lock.json; used for CI lint tooling only and not distributed in any Hive artifact.Distribution and integration model
Distribution and integration model — explanation
minimatch@10.2.6appears only inhivecommons/hiveunder.github/scripts/package-lock.jsonas a transitive dev dependency of lint tooling (eslint -> minimatch ^10.2.5and@eslint/config-array -> minimatch ^10.2.4). It is installed from npm for CI/developer lint checks of repository scripts and dashboard inline JavaScript.It is not product/runtime code, is not vendored in the repository, is not incorporated into any Hive release artifact, and is not needed by end users to install or run Hive. The dependency is retrieved from the npm package repository at build/test tooling install time, so the use satisfies allowlist criteria 2B (not stored in the project repository; retrieved from the upstream package repository) and 3.2 (the upstream project was created in 2011 and has more than 3,000 GitHub stars). The missing allowlist criterion is only the license identifier: BlueOak-1.0.0 is not currently on the CNCF allowlist.
Modification status
Modification status — explanation
Hive does not patch, fork, vendor, or otherwise modify
minimatch. It is resolved unmodified from npm through the.github/scripts/package-lock.jsondependency graph.Structural separation
Structural separation — explanation
minimatchsource code is never stored in the Hive repository and is retrieved from npm intonode_modulesonly when installing CI/development lint tooling under.github/scripts. It remains a separate npm package and is not copied into Hive source files.Communication mechanism
Communication mechanism — explanation
For lint tooling only, Node.js loads ESLint and its transitive npm packages, including
minimatch, as modules in the Node.js process. There is no static linking into a Hive binary or shipped artifact, and end users do not load this dependency when running Hive.Data exchange
Data exchange — explanation
Hive project code does not directly exchange internal data structures with
minimatch. The dependency is used inside ESLint/config-array during CI lint operations to evaluate glob patterns and file/config matching. Inputs are file paths and glob strings in the lint toolchain; no Hive runtime internals or distributed artifacts are involved.Additional information — explanation
This request is filed even though Hive is also pursuing a belt-and-braces mitigation that pins the CI scripts' transitive
minimatchdependency to the ISC-licensed 9.x line. The exception is requested because the current ESLint dependency chain can resolveminimatch@10.2.6, and ESLint >=9 /@eslint/config-arraymoved tominimatchranges that include v10 after the upstream license change.Precedent: #1434 requested a BlueOak-1.0.0 exception for Prometheus: #1434
Blue Oak Model License 1.0.0 is OSI-approved and permissive. Its published purpose says it gives "everyone as much permission to work with this software as possible" while protecting contributors from liability. Its obligations are attribution/notice-oriented and it does not impose copyleft terms.
Upstream metadata checked for allowlist context: https://github.com/isaacs/minimatch was created in 2011 and currently has more than 3,000 stars.