Skip to content

[License Exception Request] Hive / BlueOak-1.0.0 (minimatch) #1552

Description

@clubanderson

For which CNCF project are you requesting exceptions?

Hive (hivecommons/hive), CNCF Sandbox project.

Are you an official maintainer of this project?

Yes. Filed on behalf of Hive maintainers during CNCF Sandbox onboarding.

List of components requiring an exception

Component Upstream URL Project Usage URL License(s) Purpose
minimatch 10.2.6 https://github.com/isaacs/minimatch https://github.com/hivecommons/hive/blob/v5/.github/scripts/package-lock.json BlueOak-1.0.0 Transitive development dependency of ESLint in .github/scripts/package-lock.json; used for CI lint tooling only and not distributed in any Hive artifact.

Distribution and integration model

  • CNCF-Distributed: The CNCF project will distribute the dependency or the resulting combined artifacts to users.
  • User-Fetched Dependency: The CNCF project code will cause the user's system to automatically retrieve the dependency from an upstream source at build, install, or runtime.
  • System Component: The CNCF project expects that the dependency will either already be present on the user's system or will be installed independently by the user.
  • Not Distributed + Not Needed by End User (Internal Project Tooling): ALL of the following are true:

Distribution and integration model — explanation

minimatch@10.2.6 appears only in hivecommons/hive under .github/scripts/package-lock.json as a transitive dev dependency of lint tooling (eslint -> minimatch ^10.2.5 and @eslint/config-array -> minimatch ^10.2.4). It is installed from npm for CI/developer lint checks of repository scripts and dashboard inline JavaScript.

It is not product/runtime code, is not vendored in the repository, is not incorporated into any Hive release artifact, and is not needed by end users to install or run Hive. The dependency is retrieved from the npm package repository at build/test tooling install time, so the use satisfies allowlist criteria 2B (not stored in the project repository; retrieved from the upstream package repository) and 3.2 (the upstream project was created in 2011 and has more than 3,000 GitHub stars). The missing allowlist criterion is only the license identifier: BlueOak-1.0.0 is not currently on the CNCF allowlist.

Modification status

  • Modified Upstream: The CNCF project will patch, alter, or otherwise modify the source code of the dependency and contribute upstream.
  • Modified Downstream: The CNCF project will patch, alter, or otherwise modify the source code of the dependency and maintain a downstream fork or local copy.
  • Unmodified: The CNCF project will use the dependency exactly as provided by the upstream maintainers without any changes to its source code.

Modification status — explanation

Hive does not patch, fork, vendor, or otherwise modify minimatch. It is resolved unmodified from npm through the .github/scripts/package-lock.json dependency graph.

Structural separation

  • Separated Component: The dependency's code will either be (a) kept in a distinct directory or module clearly separated from CNCF project code, or (b) retrieved at build/installation time from a third-party repository and never stored in the CNCF project repository.
  • Intermingled Code: The dependency's code will be "mixed in" with CNCF source files, copied into existing project files, or will otherwise lose its distinct directory/module boundary.

Structural separation — explanation

minimatch source code is never stored in the Hive repository and is retrieved from npm into node_modules only when installing CI/development lint tooling under .github/scripts. It remains a separate npm package and is not copied into Hive source files.

Communication mechanism

  • Static Linking: The dependency and the CNCF project code will be combined into a single binary or similar type of artifact during the build process.
  • Dynamic Linking: The CNCF project code will interact with the dependency by loading it into the shared address space (memory) at run-time. This includes traditional shared objects compiled into a separate binary, as well as runtime module loading in interpreted or JIT-compiled languages.
  • Separate Process: The dependency and the CNCF project code will run as distinct executables and communicate via Inter-Process Communication (e.g., pipes, sockets, or shared files)
  • Network Interaction: The dependency and the CNCF project code will be logically and physically separated by a network boundary, with the CNCF project's code acting as a client or consumer of the remote service and interacting with the dependency exclusively via standardized network protocols.

Communication mechanism — explanation

For lint tooling only, Node.js loads ESLint and its transitive npm packages, including minimatch, as modules in the Node.js process. There is no static linking into a Hive binary or shipped artifact, and end users do not load this dependency when running Hive.

Data exchange

  • Tightly Coupled: The upstream dependency and CNCF project code will exchange complex internal data structures such as shared pointers, class instances, or private memory offsets that require extensive knowledge of the other component's internal memory layout.
  • Arms-Length Only: The communication between the dependency and the CNCF project code will be limited to standard serialized data (e.g., JSON, XML, or Protobuf) where data is "flattened" for transport and neither component accesses the other's internal memory structures.

Data exchange — explanation

Hive project code does not directly exchange internal data structures with minimatch. The dependency is used inside ESLint/config-array during CI lint operations to evaluate glob patterns and file/config matching. Inputs are file paths and glob strings in the lint toolchain; no Hive runtime internals or distributed artifacts are involved.

Additional information — explanation

This request is filed even though Hive is also pursuing a belt-and-braces mitigation that pins the CI scripts' transitive minimatch dependency to the ISC-licensed 9.x line. The exception is requested because the current ESLint dependency chain can resolve minimatch@10.2.6, and ESLint >=9 / @eslint/config-array moved to minimatch ranges that include v10 after the upstream license change.

Precedent: #1434 requested a BlueOak-1.0.0 exception for Prometheus: #1434

Blue Oak Model License 1.0.0 is OSI-approved and permissive. Its published purpose says it gives "everyone as much permission to work with this software as possible" while protecting contributors from liability. Its obligations are attribution/notice-oriented and it does not impose copyleft terms.

Upstream metadata checked for allowlist context: https://github.com/isaacs/minimatch was created in 2011 and currently has more than 3,000 stars.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions