← All tasks
javascriptcure53/DOMPurify #1434Not a task: already works

LICENSE-MPL is missing from the published npm package

envgap__cure53__DOMPurify-1434

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
9fd97d6205cd46d74f81af8debedbf324ddd256e
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

cure53/DOMPurify #1434 · read the original issue
### Description

DOMPurify is dual-licensed under `(MPL-2.0 OR Apache-2.0)`. While the main `LICENSE` file is automatically included in the published npm artifact by npm's default behavior, `LICENSE-MPL` is currently left out.

Because `package.json` explicitly defines the `files` array, any files not listed there (and not covered by npm's default auto-include rules) are excluded from the final npm package. Since `LICENSE-MPL` has a custom filename, it doesn't get published to npm, leaving downstream users in `node_modules` without the MPL license text.

### Proposed Solution

Add `"LICENSE-MPL"` to the `"files"` array in `package.json`:

```json
  "files": [
    "dist",
    "src",
    "LICENSE-MPL"
  ],
```

Let me know if you want me to submit a PR.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]