# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
#
# Supplement only dependencies actually included in the artifact.
# Sources and audited versions are documented in README.md.
com.aliyun.oss:aliyun-sdk-oss:3.10.2=LICENSE.aliyun-inieditor | Aliyun OSS (Apache-2.0), including IniEditor (BSD-2-Clause)
com.aliyun.oss:aliyun-sdk-oss:3.13.0=LICENSE.aliyun-inieditor | Aliyun OSS (Apache-2.0), including IniEditor (BSD-2-Clause)
com.google.api-client:google-api-client:1.24.1=LICENSE.google-cloudshell | Google API Client (Apache-2.0), including CloudShellCredential (BSD-3-Clause)
com.google.auth:google-auth-library-credentials:1.28.0=LICENSE.google-auth | Google Auth Library (BSD-3-Clause)
com.google.auth:google-auth-library-oauth2-http:1.28.0=LICENSE.google-auth | Google Auth Library (BSD-3-Clause)
com.azure:*=LICENSE.azure | Microsoft Azure SDK (MIT)
com.microsoft.azure:msal4j=LICENSE.msal | Microsoft Authentication Library (MIT)
com.microsoft.azure:msal4j-persistence-extension=LICENSE.msal | Microsoft Authentication persistence extension (MIT)
com.microsoft.azure:azure-keyvault-core=LICENSE.azure | Azure Key Vault core (MIT and Apache-2.0)
com.sun.xml.bind:jaxb-core=LICENSE.jaxb | JAXB Reference Implementation (CDDL-1.1); https://github.com/javaee/jaxb-v2
com.sun.xml.bind:jaxb-impl=LICENSE.jaxb | JAXB Reference Implementation (CDDL-1.1); https://github.com/javaee/jaxb-v2
com.h2database:h2=LICENSE.h2 | H2 Database Engine (MPL-2.0); https://h2database.com
com.google.code.findbugs:jsr305=LICENSE.jsr305,LICENSE.jsr305-concurrent | JSR305 concurrency annotations by Brian Goetz (CC-BY-2.5); http://www.jcip.net
io.grpc:grpc-api=NOTICE.grpc
io.netty:*=NOTICE.netty
io.netty:netty-tcnative-classes=NOTICE.netty-tcnative
io.netty:netty-common=NOTICE.netty,NOTICE.netty-harmony,LICENSE.netty-slf4j | Netty Common (Apache-2.0), including SLF4J code (MIT)
io.netty:netty-codec=NOTICE.netty,LICENSE.netty-jbzip2,LICENSE.netty-libdivsufsort,LICENSE.netty-jfastlz,LICENSE.netty-protobuf | Netty Codec (Apache-2.0), including BSD and MIT components identified in the accompanying license texts
io.netty:netty-codec-http=NOTICE.netty,LICENSE.netty-webbit,LICENSE.netty-utf8 | Netty HTTP codec (Apache-2.0), including Webbit (BSD) and UTF-8 validation (MIT)
io.netty:netty-codec-http2=NOTICE.netty,LICENSE.netty-hyper-hpack,LICENSE.netty-nghttp2-hpack | Netty HTTP/2 codec (Apache-2.0), including hyper-hpack and nghttp2 (MIT)
io.netty:netty-resolver-dns-native-macos=NOTICE.netty,LICENSE.netty-dnsinfo | Netty macOS DNS resolver, including Apple dnsinfo (APSL-2.0, for Apple hardware); https://github.com/apple-oss-distributions/configd; covered source is available under APSL-2.0 at https://github.com/netty/netty/blob/netty-4.1.109.Final/resolver-dns-native-macos/src/main/c/dnsinfo.h
jakarta.transaction:jakarta.transaction-api=LICENSE.transaction,NOTICE.transaction | Jakarta Transactions API (EPL-2.0); https://github.com/jakartaee/transactions
org.jetbrains.kotlin:*=NOTICE.kotlin
org.ow2.asm:asm=LICENSE.asm | ASM (BSD-3-Clause)
org.reactivestreams:reactive-streams=LICENSE.reactive-streams | Reactive Streams (MIT-0)
org.xerial.snappy:snappy-java=NOTICE.snappy,LICENSE.snappy,LICENSE.bitshuffle | Snappy Java (Apache-2.0), with Snappy (BSD-3-Clause) and Bitshuffle (MIT)
org.jacoco:org.jacoco.agent=LICENSE.EPL-2.0 | JaCoCo runtime (EPL-2.0); https://www.jacoco.org
com.sun.activation:javax.activation= | JavaBeans Activation Framework (CDDL-1.1); https://github.com/javaee/activation
javax.xml.bind:jaxb-api= | JAXB API (CDDL-1.1); https://github.com/javaee/jaxb-spec
org.checkerframework:checker-qual= | Checker Framework qualifiers (MIT)
org.codehaus.woodstox:stax2-api= | StAX2 API (BSD-2-Clause)
org.slf4j:*= | SLF4J (MIT)
net.java.dev.jna:*= | Java Native Access (Apache-2.0 selected from dual license)
# Version-specific rules require an explicit entry for every audited version.
# These older versions do not contain FastDoubleParser or Schubfach.
com.fasterxml.jackson.core:jackson-core:2.9.2=
com.fasterxml.jackson.core:jackson-core:2.13.5=
com.fasterxml.jackson.core:jackson-core:2.15.2=LICENSE.fastdoubleparser-0.9.0,LICENSE.schubfach | Jackson Core (Apache-2.0), including FastDoubleParser 0.9.0 and Schubfach (MIT), bigint (BSD-2-Clause)
com.fasterxml.jackson.core:jackson-core:2.18.3=LICENSE.fastdoubleparser-1.0.90,LICENSE.schubfach,LICENSE.fastdoubleparser-boost | Jackson Core (Apache-2.0), including FastDoubleParser 1.0.90 and Schubfach (MIT), fast_double_parser (BSL-1.0), fast_float (MIT), bigint (BSD-2-Clause)
# This version already includes the complete parser license texts.
com.fasterxml.jackson.core:jackson-core:2.21.3=
