Check RubyGems licences

- Ensure we do not accidentally include gems with licences we do not
  agree with.
- Run the Homebrew `licensed` formula in the vendor-gems workflow so
  CI fails when a Bundler gem has an unapproved licence or stale cache
  record.
- Keep `licensed` outside `Library/Homebrew/Gemfile` so all-groups
  Bundler installs do not need its native dependencies.
- Use an isolated Homebrew formula cache key and allow cleanup of any
  existing formulae before installing `licensed` for CI.
- Vendor the current `.licenses` cache so future dependency updates
  have an explicit review baseline.
- Mark generated licence, Sorbet RBI and Bundler files as generated.
This commit is contained in:
Mike McQuaid
2026-05-19 11:47:11 +01:00
parent e0cac3e152
commit 59818f180e
91 changed files with 8510 additions and 2 deletions
+2
View File
@@ -194,6 +194,8 @@
!/.editorconfig
!/.gitignore
!/.irb_config
!/.licenses
!/.licenses/**
!/.ruby-version
!/.shellcheckrc
!/.vale.ini