diff --git a/config/dependency_decisions.yml b/config/dependency_decisions.yml index dce1fc1bc45..16f16f77fb9 100644 --- a/config/dependency_decisions.yml +++ b/config/dependency_decisions.yml @@ -570,3 +570,10 @@ :why: https://github.com/codesandbox-app/codesandbox-importers/blob/master/packages/import-utils/LICENSE :versions: [] :when: 2018-08-03 12:23:24.083046000 Z +- - :ignore_group + - devDependencies + - :who: Winnie Hellmann + :why: NPM packages used for development are not distributed with the final product and are therefore + exempt. + :versions: [] + :when: 2018-08-30 12:06:35.668181000 Z diff --git a/doc/development/licensing.md b/doc/development/licensing.md index ddaf636a742..0e71cd47481 100644 --- a/doc/development/licensing.md +++ b/doc/development/licensing.md @@ -100,7 +100,7 @@ If a gem uses a license which is not listed above, open an issue and ask. If a l Keep in mind that each license has its own restrictions (typically defined in their body text). Please make sure to comply with those restrictions at all times whenever an external library is used. -Gems which are included only in the "development" or "test" groups by Bundler are exempt from license requirements, as they're not distributed for use in production. +Dependencies which are only used in development or test environment are exempt from license requirements, as they're not distributed for use in production. **NOTE:** This document is **not** legal advice, nor is it comprehensive. It should not be taken as such.