LICENSE-MPL is missing from the published npm package
envgap__cure53__DOMPurify-1434
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
9fd97d6205cd46d74f81af8debedbf324ddd256e- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
cure53/DOMPurify #1434 · read the original issue
### Description
DOMPurify is dual-licensed under `(MPL-2.0 OR Apache-2.0)`. While the main `LICENSE` file is automatically included in the published npm artifact by npm's default behavior, `LICENSE-MPL` is currently left out.
Because `package.json` explicitly defines the `files` array, any files not listed there (and not covered by npm's default auto-include rules) are excluded from the final npm package. Since `LICENSE-MPL` has a custom filename, it doesn't get published to npm, leaving downstream users in `node_modules` without the MPL license text.
### Proposed Solution
Add `"LICENSE-MPL"` to the `"files"` array in `package.json`:
```json
"files": [
"dist",
"src",
"LICENSE-MPL"
],
```
Let me know if you want me to submit a PR.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]