UNCLASSIFIED - NO CUI

BB Package Licensing information has not been kept up to date

https://docs-bigbang.dso.mil/latest/docs/understanding-bigbang/licensing-model/#Table-to-Help-Elaborate-on-Nuances-of-Application-Licensing

This page/section should list all licenses for packages inside of BB. It is missing some packages and maybe has outdated information as well. I think it should be re-evaluated to ensure it is accurate. I noticed a few discrepancies:

  • Vault: Hashicorp updated to BSL - this is not in a released version yet but something to keep an eye on
  • NeuVector: Missing
  • Tempo: Missing
  • Promtail: Maybe implicit but missing explicitly
  • Prometheus Operator Stack (Prometheus, Grafana, AlertManager, Loki, etc.): Prometheus/Alertmanager are Apache and not AGPL like Grafana
  • Harbor: Missing
  • Fortify: Missing

There may be other issues but those were the clearest ones I saw.

Edited by Micah Nagel