Replies: 3 comments
|
@BidLiga Concerning the client-only@0.0.1 package, there are particular legal terms depending on the distribution channel. The main npm release is directly distributed by Meta Platforms, Incorporated as well as its affiliates. The standard MIT terms apply to this original release in the official React code repository. An identical copy is contained within the Next.js code structure after commit ff19e7a. Vercel, Incorporated possesses the overarching copyright of that integrated version. In the case an audit requires the exact upstream copyright text for the standalone package tarball, you can apply the standard statement below. |
|
Applicable Copyright & MIT License Notice The authentic notice to include in your third-party license disclosures for client-only@0.0.1 is: Plaintext Copyright (c) 2022-present Vercel, Inc. Permission is hereby granted, free of charge, to any person obtaining a copy The above copyright notice and this permission notice shall be included in all THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR Vercel Lineage (vercel/styled-jsx & vercel/next.js) Commit references: ea0432b7b910d53bf305ab1fa68c14fa19e84a17 and ff19e7ad304fe10c05b67b0e1eb26cd32de00c18. Role: Vercel published client-only@0.0.1 to npm as part of the React Server Components tooling integration. The root license governing those source commits is the Vercel MIT License. React Specification Lineage (facebook/react) Commit reference: d633174475a77d1538263cb42753b11ef641f5af. Role: The marker pattern (client-only and server-only) originated in the React Server Components RFC/spec and lives inside the official facebook/react monorepo under the Meta / React MIT License. Audit & Software Bill of Materials (SBOM) Guidance Declared License: Accept the "license": "MIT" field declared in package.json. Copyright Attribution: Cite Vercel, Inc. (as the publisher of the 0.0.1 npm tarball) or Vercel, Inc. / Meta Platforms, Inc. to cover both the publishing infrastructure and spec origin. Upstream Canonical Source: Point your compliance inventory to the Vercel Next.js Repository or Meta React Repository. |
|
Short answer: the published release does not contain an authentic copyright line or MIT permission text to quote. I checked the npm archive with The package.json has no For a record of the analyzed tarball, I would use |
Uh oh!
There was an error while loading. Please reload this page.
Summary
We are conducting a dependency/license compliance review for a Next.js-based SaaS application.
For client-only@0.0.1 (npm tarball SHA-1 38bba5d403c41ab150bff64a95c85013cf73bca1), which declares MIT and whose files were later copied unchanged into Next.js, which authentic copyright and MIT permission notice applies specifically to that npm release?
Could you provide the applicable notice or point us to an official source?
Thank you.
Additional information
Example
No response
All reactions