Third-party licenses
CAPTF is Apache-2.0. The modules below are linked into tfcapi-lint, and
this file lists those whose license is not Apache-2.0. The full dependency
set is in go.mod; a license check over the full set is not yet
automated.
| Module | Version | License | Used for |
|---|---|---|---|
github.com/hashicorp/terraform-config-inspect | v0.0.0-20260904064934-75d64de68c31 | MPL-2.0 | tfcapi-lint reads a module’s variables and outputs without running Terraform |
github.com/hashicorp/hcl/v2 | v2.20.1 | MPL-2.0 | the second lint pass: backend/cloud blocks, provider attributes, .tofu files, expressions |
github.com/hashicorp/hcl | v0.0.0-20170504190234-a4b07c25de5f | MPL-2.0 | legacy HCL parser required by terraform-config-inspect |
github.com/zclconf/go-cty | v1.14.4 | MIT | HCL’s type and value system (the lint pass reads literal values with it) |
github.com/mitchellh/go-wordwrap | v1.0.0 | MIT | diagnostic formatting in HCL |
MPL-2.0
MPL-2.0 is file-level copyleft. An Apache-2.0 binary may link unmodified MPL-2.0 code (MPL-2.0 section 3.3, “Distribution of a Larger Work”), provided the MPL-covered source stays available: these modules are published, and CAPTF does not modify them.
The combination would not be permitted for a file carrying Exhibit B, the
“Incompatible With Secondary Licenses” notice. hack/check-licenses.sh
(part of make verify) checks the three MPL modules at their pinned
versions: the phrase must appear only in their LICENSE files, as the
license’s own definitions (sections 1.5, 3.3 and 10.4), and in no source
file. It last passed on 2026-09-26. This remains subject to license review
before a release.