Packaging documentation: source and notice mapping for six bundled libraries in 4.11.0.86 Linux contrib wheel
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 45/100
- Loại issue
- Tài liệu
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python
- Lĩnh vực
- build-system, documentation, release
Hướng nghiên cứu
Bắt đầu bằng việc kiểm tra wheel 4.11.0.86 được chỉ định, thư mục opencv_contrib_python.libs/ của nó và LICENSE-3RD-PARTY.txt, sau đó xem xét bản phát hành PyPI được liên kết và metadata đóng gói của repository. Được xem là hoàn tất khi đã ghi lại chính xác các gói nguồn và phiên bản, các liên kết đến build-recipe, cùng các notices tương ứng cho cả sáu thư viện được liệt kê, kèm theo mọi thông tin SBOM hoặc liên kết tĩnh hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Expected behaviour
The third-party notices or linked build metadata should make it possible to associate bundled native libraries with their source versions and copyright/licence notices.
Actual behaviour
While reviewing the official artifact opencv_contrib_python-4.11.0.86-cp37-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl, I could not locate a specific source/version and notice mapping for the six files below in its LICENSE-3RD-PARTY.txt.
Wheel SHA-256: c47c0ef1098461cdc6fa1cdce4c942b8ec974c87423f4b5951443d26bb9ae407
These members are under opencv_contrib_python.libs/:
| Bundled filename | SHA-256 |
|---|---|
libquadmath-96973f99.so.0.0.0 |
934c22ded0e7d169c4d4678876c96051adf3d94545da962f60b41659b075da3b |
libgfortran-91cc3cb1.so.3.0.0 |
55e3eb67306c2ff17e6f8a0810eaa0dcb26e94cd83924c5065d5040e87814608 |
libxkbcommon-x11-c65ed502.so.0.0.0 |
34b0726b008fe059b70204265080e5db34afacc0af2a12698ad6c38ae1166d54 |
libxkbcommon-71ae2972.so.0.0.0 |
1fcb38a646bd1ce1daaf682ad29b72e65bfdf67a06335b278f8e99d0b7530212 |
libX11-xcb-0e257303.so.1.0.0 |
a8cf52f67fb6844bfa19d47fdfb6781a02af3ca6afe78ba9fb58a314b9365d72 |
libopenblas-r0-f650aae0.3.3.so |
79ec02b53f573cd7116a89f04c397473018e7fda05720b354d43505c19d47958 |
I found the aggregate notices for FFmpeg, Qt, OpenSSL, PNG and xcb-related components, but could not associate the six files above precisely. This is not a claim that they cannot be used commercially; I am trying to complete the artifact-to-notice mapping.
Steps to reproduce / artifact scope
Inspect the above wheel's opencv_contrib_python.libs/ directory and LICENSE-3RD-PARTY.txt without importing or rebuilding the package.
- Platform: Linux x86_64, manylinux2014 / manylinux_2_17 wheel.
- Version: opencv-contrib-python 4.11.0.86, cp37-abi3 wheel used with CPython 3.11.
- The request deliberately concerns this published version; I have not asserted that it is the latest release.
Could you provide links to the exact source packages/versions, build recipe and corresponding notices for these files? A build SBOM and indication of additional statically linked components would also help, if available. Another wheel's similarly named library would not establish this artifact's provenance.
I checked #855 and searched for SBOM and the bundled library/licence names; I did not find an existing artifact-specific mapping. I am not requesting legal advice or a rebuild.
Issue submission checklist
- This is a binary packaging/documentation issue, not a generic OpenCV coding question.
- I read the README and understand that this repository provides the Python package build toolchain.
- The request relates to the pre-built binaries and their build/notice metadata.
- Latest version: intentionally reviewing the fixed 4.11.0.86 release described above.
- Ngôn ngữ chính
- Python
- Star
- 5.4k
- Fork
- 1k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của opencv/opencv-python
-
[DOC] README fileĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
opencv/opencv-python#1217 · 3 bình luận ·
-
Dependency specification missing for python3.14Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
opencv/opencv-python#1165 · 2 bình luận · 1 reaction ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
opencv/opencv-python#1276 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
opencv/opencv-python#1273 · 1 bình luận ·
-
FFMPEG v8.1.1 vulnerabilitiesĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
opencv/opencv-python#1272 · 1 bình luận ·
Tất cả issue của opencv/opencv-python
Issue tương tự
-
Device Details tables: FS/SF columns contradict each other (nfet_01v8 Vt row, pfet_01v8 Idsat row)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
google/skywater-pdk#450 ·
-
Drained trajectory arrays are overwritten when the sequence buffer is reusedCó thể đã có người làm @sylvesterkaczmarek đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
google-deepmind/bsuite#56 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
LearningCircuit/local-deep-research#7206 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[TASK] Document technology stackĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
chingu-voyages/V62-tier3-team-33#285 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Proxy drops log notifications from backends that don't send FastMCP's msg/extra dictCó thể đã có người làm @asasemahmed đã nhận hôm nay. Đang mởbug server
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày