Skip to content

OIC-GC-008 — Licensing and dependency compatibility review #12

Description

@veraxis-protocol

Owner

Arkadiy Miteiko / Veraxis coordinates the review; final compatibility conclusions require an appropriately qualified independent licensing reviewer or counsel.

Required inputs

  • Current dependency lockfiles, SBOM, LICENSES.json, dependency inventory, and upstream license texts/notices.
  • ZTL and VEIP dossier licensing data.
  • Corpus rights/provenance findings from OIC-GC-005.

Required outputs

  • Dependency-by-dependency compatibility matrix.
  • Missing notice, attribution, source-offer, redistribution, patent, and copyleft obligations.
  • Risk/uncertainty register and owner-ready recommendations.

Acceptance criteria

  • Every direct and transitive dependency is mapped to a pinned version and reviewed license evidence.
  • Unknown, ambiguous, or conflicting terms remain blocked and are escalated.
  • Repository license publication is excluded unless separately authorized by the owner after qualified review.
  • Findings do not claim legal compliance.

Explicit non-goals

  • No license publication.
  • No legal-compliance claim or substitution for legal advice.
  • No semantic implementation or gate opening.

Dependencies

  • Requires evidence from OIC-GC-004 and OIC-GC-005 where applicable.
  • Feeds OIC-GC-007.
  • Blocked pending qualified independent review.

Current gate impact

Provides licensing-risk evidence only. It cannot open the semantic implementation gate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedBlocked pending required evidence or authorityexternal-reviewRequires independent external reviewlicensingLicensing and dependency compatibility

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions