Skip to content

[Legal/.NET] Document and implement Microsoft .NET redistribution obligations #84

Description

@KeyffMS

Audit finding

The repository is licensed under MIT, but a self-contained Windows release also redistributes Microsoft/.NET runtime components under their applicable distribution terms. The repository does not currently document which terms apply to the exact binary package or how the project satisfies them.

Target state

SightAdapt has a reviewed, written redistribution position for all Microsoft components included in its published artifacts, and the release package and end-user terms implement that position.

Acceptance criteria

  • Identify every Microsoft-origin component included in the self-contained output.
  • Identify the exact applicable license/redistribution terms for the pinned runtime and SDK versions.
  • Record whether each component may be redistributed and under what conditions.
  • Confirm that Microsoft components are distributed only as part of SightAdapt and not presented as a standalone product.
  • Add any required end-user restrictions, notices, warranty exclusions or attribution language to the binary distribution.
  • Keep Microsoft's terms clearly separate from SightAdapt's MIT license.
  • Document the review date, reviewed versions and authoritative sources.
  • Require another review when the SDK, runtime, target framework, runtime identifier or publish mode changes.
  • Have the resulting text reviewed by qualified legal counsel before an official production or paid release.

Deliverable

A repository document describing the redistribution analysis plus the approved files included in every binary package.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions