Repository navigation
relicense: AGPL-3.0-or-later -> Apache-2.0 - #26
Merged
Merged
Conversation
Copyright held by Kinetic Gain LLC. 19 commits, no external contributors, 0 npm downloads, no CLA needed for this change today. - LICENSE: full Apache-2.0 text, fetched from apache.org/licenses rather than retyped. - NOTICE: standard Apache convention for the copyright holder name. - package.json: license field, and "src" + "tsconfig.json" added to the published files array. - README.md, CHANGELOG.md: documented the change plainly, including that 0.1.0-0.2.2 remain AGPL permanently (a granted license can't be retracted). Rationale: a ~200-line adapter with no moat to defend, its value is ubiquity, and AGPL made that impossible in practice, a copyleft dependency is a blanket-ban for most engineering orgs regardless of the underlying network-interaction analysis. The monetizable layer (llm-cost-span-exporter, cost tables) stays AGPL/commercial. Separate branch from the 0.3.0 token-semantics/detection work by design, this is a licensing decision, not a bugfix. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
package-lock.json's root entry still asserted version 0.2.2 and license AGPL-3.0-or-later, matching neither package.json's 0.3.0 nor this branch's Apache-2.0 relicense. Not build-breaking, npm ci doesn't care and the lockfile never ships in the published tarball, but it's a wrong signal to repo readers and any SCA tooling that reads lockfile root metadata, and a relicense landing with a lockfile still asserting the old license is exactly the kind of loose end this review has been about closing. npm install --package-lock-only, diff checked: touches only the three root name/version/license fields, zero dependency-tree churn. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This was referenced Sep 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Relicense to Apache-2.0. Copyright holder: Kinetic Gain LLC (confirmed with the repo owner before this branch was written, per the standing instruction not to guess it).
19 commits, no external contributors, 0 npm downloads on this package, no CLA needed for this change today.
Rationale: the normalizer is a ~200-line adapter layer with no moat to defend, its value is being easy to depend on. AGPL made that impossible in practice, a copyleft dependency in a server application is a blanket-ban for most engineering orgs regardless of how the network-interaction analysis actually shakes out. The monetizable layer (
llm-cost-span-exporter, cost tables) stays AGPL/commercial, matching the permissive-adapter/copyleft-core pattern.LICENSE: full Apache-2.0 text, fetched fromapache.org/licenses/LICENSE-2.0.txtrather than retyped, diffed byte-for-byte against the fetched source to confirm.NOTICE: standard Apache convention naming the copyright holder.package.json:licensefield, andsrc+tsconfig.jsonadded to the publishedfilesarray (closes the AGPL-era gap where the tarball shipped compiled output with no corresponding source; moot under Apache-2.0's terms, but worth keeping regardless).README.md,CHANGELOG.md: documented the change, including that published versions 0.1.0-0.2.2 remain AGPL-3.0-or-later permanently, a granted license can't be retracted.Separate branch from the 0.3.0 token-semantics/detection work by design, this is a licensing decision, not a bugfix. Rebased onto current
main(after #21-#25) to avoid a stale base.Verification
LICENSEdiffed byte-for-byte against the fetchedapache.orgsource, exact matchnpm pack --dry-runconfirmssrc/*.tsandtsconfig.jsonnow ship in the tarballnpm ci, lint, typecheck, coverage (34/34), build, demo,check:no-network,audit --audit-level=highall pass🤖 Generated with Claude Code