Skip to content

Bring the legal files in line with the Eclipse progress review checklist - #1995

Merged
rfecher merged 2 commits into
masterfrom
progress-review-docs
Oct 5, 2026
Merged

rfecher merged 2 commits into
masterfrom
progress-review-docs

Conversation

@rfecher

@rfecher rfecher commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Docs only, for the 2026.10 progress review (EMO issue #1386), whose checklist covers these files.

  • NOTICE and README.md: use the formal name, LocationTech GeoWave, in the first mention and in the trademark line. This matches LocationTech Proj4J's NOTICE; the old text said "Eclipse GeoWave".
  • SECURITY.md: follows the Eclipse Foundation template. It now has:
    • the vulnerability reporting policy;
    • the confidential report tracker as the first channel;
    • GitHub private vulnerability reporting as the second channel, which the checklist asks for.
  • CONTRIBUTING.md: links the build instructions and SECURITY.md. The checklist recommends both.

Before the GitHub link works: private vulnerability reporting is currently disabled on this repository (GET /repos/locationtech/geowave/private-vulnerability-reporting returns enabled: false). It is enabled through Otterdog in locationtech/.eclipsefdn (private_vulnerability_reporting_enabled).

Please check: the "Supported Versions" section says security fixes happen on master, the 3.x line. Adjust it if 2.x-jdk8 is meant to receive them too.

  • DEPENDENCIES: regenerated with Dash. The dependency set is unchanged; ten entries the IP team has approved since then now say so. 787 of 805 are approved, and the other 18 all have open IPLab requests.

Rich Fecher added 2 commits October 5, 2026 10:25
- NOTICE and README use the project's formal name, LocationTech GeoWave, in
  the first mention and the trademark line, as other LocationTech projects do.
- SECURITY.md follows the Eclipse Foundation template: the vulnerability
  reporting policy, the confidential report tracker as the first channel, and
  GitHub private vulnerability reporting as the second.
- CONTRIBUTING.md points to the build instructions and to SECURITY.md.

Co-authored-by: Rich Fecher <richard.fecher@vantor.com>
The dependency set is unchanged. Ten entries the IP team approved since the
file was last generated now say so: six Accumulo 2.1.6 artifacts,
hbase-annotations and hbase-testing-util 2.6.6, grpc-services 1.83.1 and
protobuf-java-util 3.25.9. 787 of 805 entries are approved, and the other 18
all have open IPLab requests.

Co-authored-by: Rich Fecher <richard.fecher@vantor.com>
@rfecher
rfecher force-pushed the progress-review-docs branch from 63fd80e to 8579d10 Compare October 5, 2026 14:36
@rfecher
rfecher merged commit fe963f5 into master Oct 5, 2026
6 checks passed
@rfecher
rfecher deleted the progress-review-docs branch October 5, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant