Skip to content

License inconsistency: package.json AGPL-3.0-or-later vs LICENSE MPL-2.0 #186

Description

@hyperpolymath

Gap

Root LICENSE is Mozilla Public License 2.0 but package.json:5 declares "license": "AGPL-3.0-or-later". Same shape as verisimdb#82, fixed manually in verisimdb#101.

Specifics

  • package.json:5: "license": "AGPL-3.0-or-later"
  • Root LICENSE: Mozilla Public License Version 2.0

Owner action

Per estate license-policy umbrella: sole-owner repos default to MPL-2.0. Single-line fix. Filed as issue (not PR) per feedback_no_automated_licence_edits.

Related

  • verisimdb#82, verisimdb#101 (precedent)
  • Estate memory: feedback_estate_license_policy_umbrella

🤖 Generated with Claude Code

Activity

  1. hyperpolymath commented on Jun 2, 2026

    @hyperpolymath
    OwnerAuthor

    Status update post-hardening landed today (2026-06-02):

    This auto-filed inconsistency is now flag-only — see umbrella hypatia#416 (now CLOSED). The 3-layer guard prevents any auto-PR:

    • hypatia#414+#415 — SC-010 flipped to auto_fixable: false; license_finding_strategy/0 caps severity to :warn/:review; Manual-Only policy header at the top of lib/rules/cicd_rules.ex
    • gitbot-fleet#247 — dispatch-runner.sh refuses any recipe_id or category matching license|spdx|pmpl|mpl-2|agpl|palimpsest; the 3 fix-scripts (fix-license-hygiene.sh/fix-license-file.sh/fix-missing-spdx.sh) exit 1 with refusal banners
    • standards#339 — .claude/CLAUDE.md top-of-file 'License Policy — Manual Only' section + 5-way classification

    Resolution requires manual owner classification per the 5-way directive (estate-license-policy-umbrella):

    Category License Applies to
    Sole owner repos (default) MPL-2.0 most of hyperpolymath/*
    007 only All Rights Reserved hyperpolymath/007
    Shared with son AGPL-3.0-or-later idaptik, burble, etc.
    Third-party / forks DO NOT TOUCH upstream forks
    Palimpsest carve-out PMPL-1.0-or-later palimpsest-license, palimpsest-plasma, consent-aware-http

    Until classified manually by owner, this issue stays open as a tracked-but-not-auto-actionable record.

    Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com

  2. hyperpolymath commented on Jun 2, 2026

    @hyperpolymath
    OwnerAuthor

    FYI from the 2026-06-02 licence campaign: this issue says LICENSE is MPL-2.0 but the current LICENSE file is AGPL-3.0-or-later. The manifest declaration of AGPL-3.0-or-later is now CONSISTENT with LICENSE, not inconsistent. The issue is stale — either close as resolved, or re-triage if boj-server should actually be MPL-2.0 (sole-owner default) vs AGPL (son-shared category 3). cc owner for direction.

  3. hyperpolymath commented on Aug 7, 2026

    @hyperpolymath
    OwnerAuthor

    Resolved — verified 2026-08-07 against main.

    $ grep -h '"license"' package.json jsr.json
      "license": "MPL-2.0",
      "license": "MPL-2.0",
    $ head -1 LICENSE
    Mozilla Public License Version 2.0
    

    package.json and jsr.json both declare MPL-2.0 and agree with root LICENSE. The AGPL string this issue reported is gone.

    Two related notes from a full licence audit done today, so they don't get lost:

    • The dual-licence posture here is correct and the estate's best example — NOTICE explains MPL-2.0 (code) / CC-BY-SA-4.0 (prose), LICENSES/ holds both texts, .reuse/dep5 covers headerless config. 335 MPL / 184 CC-BY-SA headers, zero third licence.
    • The sibling registry does not have this. boj-server-cartridges carries 480 CC-BY-SA-4.0 headers under an MPL-2.0 LICENSE with no NOTICE and no .reuse/dep5 — a scanner reading only LICENSE mis-attributes all 480. Logged as L-1 in its new DEBT.md (docs: add a technical-debt register with reproducible evidence boj-server-cartridges#111); the fix is to copy this repo's pattern.

    Remaining minor licence debt here is tracked as L-1/L-2/L-3 in DEBT.md (#306): glama.json has no license field at all, ai-plugin.json declares licence only by URL, and four tracked files lack SPDX headers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions