Repository navigation
License inconsistency: package.json AGPL-3.0-or-later vs LICENSE MPL-2.0 #186
Description
Activity
Status update post-hardening landed today (2026-06-02):
This auto-filed inconsistency is now flag-only — see umbrella
hypatia#416(now CLOSED). The 3-layer guard prevents any auto-PR:- hypatia#414+#415 —
SC-010flipped toauto_fixable: false;license_finding_strategy/0caps severity to:warn/:review; Manual-Only policy header at the top oflib/rules/cicd_rules.ex - gitbot-fleet#247 —
dispatch-runner.shrefuses anyrecipe_idorcategorymatchinglicense|spdx|pmpl|mpl-2|agpl|palimpsest; the 3 fix-scripts (fix-license-hygiene.sh/fix-license-file.sh/fix-missing-spdx.sh) exit 1 with refusal banners - standards#339 —
.claude/CLAUDE.mdtop-of-file 'License Policy — Manual Only' section + 5-way classification
Resolution requires manual owner classification per the 5-way directive (
estate-license-policy-umbrella):Category License Applies to Sole owner repos (default) MPL-2.0 most of hyperpolymath/* 007 only All Rights Reserved hyperpolymath/007 Shared with son AGPL-3.0-or-later idaptik, burble, etc. Third-party / forks DO NOT TOUCH upstream forks Palimpsest carve-out PMPL-1.0-or-later palimpsest-license, palimpsest-plasma, consent-aware-http Until classified manually by owner, this issue stays open as a tracked-but-not-auto-actionable record.
Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com
- hypatia#414+#415 —
FYI from the 2026-06-02 licence campaign: this issue says LICENSE is MPL-2.0 but the current LICENSE file is AGPL-3.0-or-later. The manifest declaration of AGPL-3.0-or-later is now CONSISTENT with LICENSE, not inconsistent. The issue is stale — either close as resolved, or re-triage if boj-server should actually be MPL-2.0 (sole-owner default) vs AGPL (son-shared category 3). cc owner for direction.
- added 3 commits that reference this issue
on Jun 11, 2026 Resolved — verified 2026-08-07 against
main.$ grep -h '"license"' package.json jsr.json "license": "MPL-2.0", "license": "MPL-2.0", $ head -1 LICENSE Mozilla Public License Version 2.0package.jsonandjsr.jsonboth declare MPL-2.0 and agree with rootLICENSE. The AGPL string this issue reported is gone.Two related notes from a full licence audit done today, so they don't get lost:
- The dual-licence posture here is correct and the estate's best example —
NOTICEexplains MPL-2.0 (code) / CC-BY-SA-4.0 (prose),LICENSES/holds both texts,.reuse/dep5covers headerless config. 335 MPL / 184 CC-BY-SA headers, zero third licence. - The sibling registry does not have this.
boj-server-cartridgescarries 480 CC-BY-SA-4.0 headers under an MPL-2.0LICENSEwith noNOTICEand no.reuse/dep5— a scanner reading onlyLICENSEmis-attributes all 480. Logged as L-1 in its newDEBT.md(docs: add a technical-debt register with reproducible evidence boj-server-cartridges#111); the fix is to copy this repo's pattern.
Remaining minor licence debt here is tracked as L-1/L-2/L-3 in
DEBT.md(#306):glama.jsonhas nolicensefield at all,ai-plugin.jsondeclares licence only by URL, and four tracked files lack SPDX headers.- The dual-licence posture here is correct and the estate's best example —
Gap
Root
LICENSEis Mozilla Public License 2.0 butpackage.json:5declares"license": "AGPL-3.0-or-later". Same shape as verisimdb#82, fixed manually in verisimdb#101.Specifics
package.json:5:"license": "AGPL-3.0-or-later"LICENSE: Mozilla Public License Version 2.0Owner action
Per estate license-policy umbrella: sole-owner repos default to
MPL-2.0. Single-line fix. Filed as issue (not PR) perfeedback_no_automated_licence_edits.Related
feedback_estate_license_policy_umbrella🤖 Generated with Claude Code