Skip to content

legal: audit LICENSE and NOTICE for the first release artifacts #3270

Description

@M4n5ter
English

Part of #2974 — G3: release legal files.

Outcome

Make the legal files match the exact contents of the Apache source release and
the required npm and Desktop convenience artifacts.

Exit criteria

  • Inventory third-party material separately for the source, npm, macOS, and
    Windows artifacts.
  • Confirm that every artifact's LICENSE contains the Apache License 2.0
    text and only the additional licensing information required by its contents.
  • Keep Category B binary-only material out of the source release and label
    it prominently in each convenience artifact where inclusion is permitted.
  • Reject Category X material from every source and convenience artifact.
  • Rewrite NOTICE in ASF form and retain only notices legally required by
    the exact contents of each artifact.
  • Verify generated notices cannot leak licensing information between source,
    npm, and platform-specific Desktop artifacts.
  • Obtain the required human and mentor/legal review of the complete artifact
    matrix.
  • Update DISCLAIMER-WIP when its NOTICE disclosure is no longer true.

Existing work

Out of scope

  • Adding ASF headers or RAT.
  • Implementing npm/Desktop packaging behavior beyond the legal-file boundary.
  • Choosing the technical replacement for bundled Git.

References

Ownership

Leave this issue unassigned until someone explicitly claims the complete
artifact-specific review. Prior work in this area does not imply ownership.

简体中文

#2974 的一部分——G3:发行包法律文件。

目标结果

使法律文件与 Apache 源码 release,以及要求同时发布的 npm 和 Desktop convenience
artifacts 的实际内容完全匹配。

完成条件

  • 分别盘点源码、npm、macOS 和 Windows artifacts 中实际包含的第三方材料。
  • 确认每个 artifact 的 LICENSE 包含 Apache License 2.0 全文,并且只增加其实际
    内容所要求的许可证信息。
  • Category B binary-only 材料不能进入源码 release;在允许进入 convenience
    artifact 时必须显著标注。
  • 从全部源码和 convenience artifacts 中拒绝 Category X 材料。
  • 按 ASF 格式重写 NOTICE,只保留每个 artifact 的精确内容依法必须携带的 notice。
  • 验证自动生成的 notices 不会在源码、npm 和平台特定 Desktop artifacts 之间泄漏
    不属于对方的许可证信息。
  • 对完整 artifact 矩阵取得所需的人工及 mentor/legal 审查。
  • NOTICE 问题解决后,更新 DISCLAIMER-WIP 中不再成立的披露。

已有工作

不在范围内

  • 添加 ASF headers 或 RAT。
  • 实现法律文件边界之外的 npm/Desktop 打包行为。
  • 选择 bundled Git 的具体技术替代方案。

参考资料

负责人边界

在有人明确认领完整的 artifact-specific 审查前保持 unassigned。此前参与过该区域的工作
不代表自动承担本 issue。

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions