Skip to content

relicense: AGPL-3.0-or-later -> Apache-2.0 - #26

Merged
mizcausevic-dev merged 2 commits into
mainfrom
relicense/apache-2.0
Sep 13, 2026
Merged

mizcausevic-dev merged 2 commits into
mainfrom
relicense/apache-2.0

Conversation

@mizcausevic-dev

Copy link
Copy Markdown
Owner

Summary

Relicense to Apache-2.0. Copyright holder: Kinetic Gain LLC (confirmed with the repo owner before this branch was written, per the standing instruction not to guess it).

19 commits, no external contributors, 0 npm downloads on this package, no CLA needed for this change today.

Rationale: the normalizer is a ~200-line adapter layer with no moat to defend, its value is being easy to depend on. AGPL made that impossible in practice, a copyleft dependency in a server application is a blanket-ban for most engineering orgs regardless of how the network-interaction analysis actually shakes out. The monetizable layer (llm-cost-span-exporter, cost tables) stays AGPL/commercial, matching the permissive-adapter/copyleft-core pattern.

  • LICENSE: full Apache-2.0 text, fetched from apache.org/licenses/LICENSE-2.0.txt rather than retyped, diffed byte-for-byte against the fetched source to confirm.
  • NOTICE: standard Apache convention naming the copyright holder.
  • package.json: license field, and src + tsconfig.json added to the published files array (closes the AGPL-era gap where the tarball shipped compiled output with no corresponding source; moot under Apache-2.0's terms, but worth keeping regardless).
  • README.md, CHANGELOG.md: documented the change, including that published versions 0.1.0-0.2.2 remain AGPL-3.0-or-later permanently, a granted license can't be retracted.

Separate branch from the 0.3.0 token-semantics/detection work by design, this is a licensing decision, not a bugfix. Rebased onto current main (after #21-#25) to avoid a stale base.

Verification

  • LICENSE diffed byte-for-byte against the fetched apache.org source, exact match
  • npm pack --dry-run confirms src/*.ts and tsconfig.json now ship in the tarball
  • npm ci, lint, typecheck, coverage (34/34), build, demo, check:no-network, audit --audit-level=high all pass

🤖 Generated with Claude Code

mizcausevic-dev and others added 2 commits September 13, 2026 18:52
Copyright held by Kinetic Gain LLC. 19 commits, no external
contributors, 0 npm downloads, no CLA needed for this change today.

- LICENSE: full Apache-2.0 text, fetched from apache.org/licenses
  rather than retyped.
- NOTICE: standard Apache convention for the copyright holder name.
- package.json: license field, and "src" + "tsconfig.json" added to
  the published files array.
- README.md, CHANGELOG.md: documented the change plainly, including
  that 0.1.0-0.2.2 remain AGPL permanently (a granted license can't be
  retracted).

Rationale: a ~200-line adapter with no moat to defend, its value is
ubiquity, and AGPL made that impossible in practice, a copyleft
dependency is a blanket-ban for most engineering orgs regardless of
the underlying network-interaction analysis. The monetizable layer
(llm-cost-span-exporter, cost tables) stays AGPL/commercial.

Separate branch from the 0.3.0 token-semantics/detection work by
design, this is a licensing decision, not a bugfix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
package-lock.json's root entry still asserted version 0.2.2 and
license AGPL-3.0-or-later, matching neither package.json's 0.3.0 nor
this branch's Apache-2.0 relicense. Not build-breaking, npm ci doesn't
care and the lockfile never ships in the published tarball, but it's
a wrong signal to repo readers and any SCA tooling that reads lockfile
root metadata, and a relicense landing with a lockfile still asserting
the old license is exactly the kind of loose end this review has been
about closing.

npm install --package-lock-only, diff checked: touches only the three
root name/version/license fields, zero dependency-tree churn.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@mizcausevic-dev
mizcausevic-dev merged commit 609f8a7 into main Sep 13, 2026
4 checks passed
@mizcausevic-dev
mizcausevic-dev deleted the relicense/apache-2.0 branch September 13, 2026 23:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant