Conversation
The crate, the Python package and nodejs/package.json moved to MIT OR Apache-2.0, but two places that npm reads were left behind: - nodejs/package-lock.json still recorded GPL-3.0 for the root package. The new value is what `npm install --package-lock-only` writes from the current package.json; no dependency entry changes. - The four platform packages under nodejs/npm/ declared plain MIT. They carry the compiled self_encryption addon, so they now declare the same MIT OR Apache-2.0 as the main package. No code, version or dependency changes.
|
Reviewed as part of the V2-1385 sweep (V2-1389). The change itself is correct — the four platform Requesting one change: this doesn't finish the issue, and the part it's missing is the part that actually reaches users. The issue is titled "finish the relicense in the nodejs lockfile, then release", and its description is explicit about why the second half matters:
That is still true on this branch.
So this one unpublished version bump is the blocker for the last open licence exposure across the whole V2-1385 sweep. Everything else in the parent issue either has landed or is close. What I'd like added before merge: the Happy to approve immediately once either the bump is in or the follow-up is linked. |
master relicensed self_encryption from GPL-3.0 with a linking exception to MIT OR Apache-2.0, but CHANGELOG.md, which ships in the crate, has no entry for it. The release that carries the relicense would therefore not tell anyone upgrading that the terms changed. Add an Unreleased entry recording the change and naming 0.36.0 as the last release under GPL-3.0 with the linking exception. The version number is left to whoever cuts the release; they rename the heading when they bump Cargo.toml.
The npm packages declare MIT OR Apache-2.0 but would have carried no licence text if published: the main package directory has no licence file, and each platform package's `files` list names only its .node addon. The publish workflow now copies the repository's LICENSE-MIT and LICENSE-APACHE into the main package and every platform package after the addons are moved into place, and each platform package lists both files. The repository root stays the only copy of the texts. Checked by running the copy step on a copy of nodejs/ with stub addons: npm pack --dry-run then lists both files in all five packages.
dirvine
left a comment
There was a problem hiding this comment.
Re-review — release follow-up still outstanding
Reviewed d33b568234daa66c67cd0af59964ea341aa4c770.
The Node licence metadata and packaging changes are sound. I reproduced the workflow licence-copy step and checked npm pack --dry-run --ignore-scripts for the root and all four platform packages: each includes both licence texts. Native addons were not rebuilt.
The previous review explicitly requested either a publishable Cargo version bump or a linked release follow-up. Cargo.toml still has 0.36.0, crates.io still reports that version under GPL-3.0 (with the source's linking exception), and I found no follow-up linked in the PR body/comments. The new Unreleased changelog entry does not fulfil either alternative.
Recommendation: keep that request open. Add the version bump, or link a concrete release follow-up and avoid closing the release obligation with this metadata-only patch. There is no need to force publishing into this PR if the follow-up is explicitly tracked.
Applicable CI is green. This is an advisory engineering review; no approval or merge performed.
Panel adjudication: the initial specialist and independent GLM-5.2 reviewer considered the diff approvable (with release concerns); both adversarial reviewers and the coordinator retain the explicitly outstanding bump-or-linked-follow-up request. The disagreement is about satisfying the prior review, not a new code defect.
Summary
master was relicensed from GPL-3.0 to MIT OR Apache-2.0, but two places that npm reads were left behind:
nodejs/package-lock.jsonstill recorded"license": "GPL-3.0"for the root package. The new value is exactly whatnpm install --package-lock-onlywrites from the currentnodejs/package.json; no dependency entry changes.nodejs/npm/declared plainMIT. They carry the compiled self_encryption addon, so they now declare the sameMIT OR Apache-2.0as the main package.A sweep of master found no other GPL leftovers about self_encryption itself. Cargo.toml, nodejs/Cargo.toml, pyproject.toml and the README already say MIT OR Apache-2.0. None of the
@withautonomi/self-encryptionnpm packages has been published yet, so no released npm artifact is affected. If they are published later, the packaging will also need to copy the licence texts into each package, which this PR does not do.crates.io users only get the relicense once a new version is published. Every self_encryption release on crates.io, up to and including 0.36.0, is GPL-3.0 with the linking exception, and the ant-client, ant-node and antd lockfiles resolve that crates.io release today. master's Cargo.toml still carries
version = "0.36.0", the number already used by the GPL release, so the relicensed code needs a new version number when it is published. This PR does not touch the version; that is the release owner's call.Closes V2-1389
Verification
npm install --package-lock-only --ignore-scriptson a copy ofnodejs/produces a lockfile byte-identical to this one.