Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider avoiding changing the AGPL text #5553

Open
pombredanne opened this issue Feb 9, 2023 · 2 comments
Open

Consider avoiding changing the AGPL text #5553

pombredanne opened this issue Feb 9, 2023 · 2 comments

Comments

@pombredanne
Copy link

While running a routine scan, I found that the AGPL text in this repo has been modified. See the diff below of https://raw.githubusercontent.com/Unitech/pm2/5e708459aca32903fd363230e24c37b3e38bb48d/GNU-AGPL-3.0.txt against https://www.gnu.org/licenses/agpl-3.0.txt ... this may look minor but:

  1. Some tools will look for exact checksums of license files.
  2. More importantly the AGPL starts with this statement:

Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.

FWIW, I would myself never modify the license text at all as I may violate the AGPL terms, even with the best of intentions and if it were me, I would restore the original text.

$ diff  agpl-3.0.txt GNU-AGPL-3.0.txt
0a1
> 
4c5
<  Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>
---
>  Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
632,633c633,634
<     <one line to give the program's name and a brief idea of what it does.>
<     Copyright (C) <year>  <name of author>
---
>     PM2 Process manager for Node.JS
>     Copyright (C) 2013-2016 Strzelewicz Alexandre
646c647
<     along with this program.  If not, see <https://www.gnu.org/licenses/>.
---
>     along with this program.  If not, see <http://www.gnu.org/licenses/>.
661c662,665
< <https://www.gnu.org/licenses/>.
---
> <http://www.gnu.org/licenses/>.
> 
> 
> --- ALEXANDRE STRZELEWICZ
@pombredanne
Copy link
Author

@Unitech FYI

@MaerF0x0
Copy link

Similar issue

Deprecated License
License is deprecated which may have legal implications regarding the package's use.
Found 1 instance in 1 package

https://socket.dev/npm/package/pm2
Screenshot 2023-04-11 at 9 17 23 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants