Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Package distributions are not licensed #4944

Closed
honzajavorek opened this issue Aug 31, 2018 · 2 comments
Closed

Package distributions are not licensed #4944

honzajavorek opened this issue Aug 31, 2018 · 2 comments
Milestone

Comments

@honzajavorek
Copy link

Hi @gaearon et al 馃憢 The code of the create-react-app monorepo is licensed under MIT, and that's great. But according to MIT, the license text needs to be attached everywhere:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

The npm packages as they're published and distributed, do not comply with this as they do not contain the license files. Effectively, without the full license text they're proprietary code and cannot be used by anyone who cares about licenses. The SPDX identifier in the package.json is not satisfactory (not only) for the reasons mentioned above. There are two solutions to this:

  1. Upgrade to Lerna@3, as it has the licensing built-in now
  2. Copy & paste the root license to all projects in the packages directory, so it gets picked up by npm during publishing, and to re-publish all of them with a new patch version.

For more information, see lerna/lerna#1465 (comment), babel/babel#7308 (comment), babel/babel#8409 (comment).


A similar issue: facebook/regenerator#354

@Timer
Copy link
Contributor

Timer commented Sep 17, 2018

We'll upgrade to Lerna 3 soon. Thanks for the heads up!

@Timer
Copy link
Contributor

Timer commented Oct 1, 2018

We added all the license files by hand for now in #5192 (instead of upgrading Lerna).
Lerna has an outstanding bug preventing us from using it: lerna/lerna#1687.

@Timer Timer closed this as completed Oct 1, 2018
@lock lock bot locked and limited conversation to collaborators Jan 11, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants