Skip to content

chore(license): declare MIT OR Apache-2.0 across the nodejs packages - #446

Open
grumbach wants to merge 3 commits into
WithAutonomi:masterfrom
grumbach:chore/nodejs-lockfile-licence
Open

grumbach wants to merge 3 commits into
WithAutonomi:masterfrom
grumbach:chore/nodejs-lockfile-licence

Conversation

@grumbach

@grumbach grumbach commented Oct 1, 2026

Copy link
Copy Markdown
Member

Summary

master was relicensed from GPL-3.0 to MIT OR Apache-2.0, but two places that npm reads were left behind:

  • nodejs/package-lock.json still recorded "license": "GPL-3.0" for the root package. The new value is exactly what npm install --package-lock-only writes from the current nodejs/package.json; no dependency entry changes.
  • The four platform packages under nodejs/npm/ declared plain MIT. They carry the compiled self_encryption addon, so they now declare the same MIT OR Apache-2.0 as the main package.

A sweep of master found no other GPL leftovers about self_encryption itself. Cargo.toml, nodejs/Cargo.toml, pyproject.toml and the README already say MIT OR Apache-2.0. None of the @withautonomi/self-encryption npm packages has been published yet, so no released npm artifact is affected. If they are published later, the packaging will also need to copy the licence texts into each package, which this PR does not do.

crates.io users only get the relicense once a new version is published. Every self_encryption release on crates.io, up to and including 0.36.0, is GPL-3.0 with the linking exception, and the ant-client, ant-node and antd lockfiles resolve that crates.io release today. master's Cargo.toml still carries version = "0.36.0", the number already used by the GPL release, so the relicensed code needs a new version number when it is published. This PR does not touch the version; that is the release owner's call.

Closes V2-1389

Verification

  • npm install --package-lock-only --ignore-scripts on a copy of nodejs/ produces a lockfile byte-identical to this one.
  • All five edited JSON files parse.
  • No code, dependency or version changes.

The crate, the Python package and nodejs/package.json moved to
MIT OR Apache-2.0, but two places that npm reads were left behind:

- nodejs/package-lock.json still recorded GPL-3.0 for the root package.
  The new value is what `npm install --package-lock-only` writes from
  the current package.json; no dependency entry changes.
- The four platform packages under nodejs/npm/ declared plain MIT. They
  carry the compiled self_encryption addon, so they now declare the same
  MIT OR Apache-2.0 as the main package.

No code, version or dependency changes.
@jacderida

Copy link
Copy Markdown
Member

Reviewed as part of the V2-1385 sweep (V2-1389). The change itself is correct — the four platform package.json files and the lockfile root all now say MIT OR Apache-2.0, and the lockfile's stale GPL-3.0 was the specific thing the issue called out.

Requesting one change: this doesn't finish the issue, and the part it's missing is the part that actually reaches users.

The issue is titled "finish the relicense in the nodejs lockfile, then release", and its description is explicit about why the second half matters:

Every published crate up to 0.36.0 is GPL-3.0 with a linking exception, and master's Cargo.toml still carries the same version number as the GPL release, so the relicense reaches consumers only once a new version is published.

That is still true on this branch. master is relicensed, but because the version number is unchanged from the GPL release, no consumer sees the relicense. Concretely, right now:

  • ant-node has had to move self_encryption behind test-utils purely to keep a GPL crate out of release builds
  • the ant-browser-sdk wasm and try.autonomi.com both ship 0.36.0 and each carry a reviewed [exception.self_encryption] entry admitting GPL-3.0-with-linking-exception into their notices
  • those exception entries are version-pinned specifically so they expire when a relicensed release appears

So this one unpublished version bump is the blocker for the last open licence exposure across the whole V2-1385 sweep. Everything else in the parent issue either has landed or is close.

What I'd like added before merge: the Cargo.toml version bump, so that merging this actually produces a publishable relicensed release. If you'd rather keep this PR as the lockfile-only fix and do the bump plus publish in a dedicated follow-up, that's fine too — but in that case please open that follow-up now and link it here, so V2-1389 isn't closed by a change that leaves every consumer still on GPL terms.

Happy to approve immediately once either the bump is in or the follow-up is linked.

master relicensed self_encryption from GPL-3.0 with a linking exception
to MIT OR Apache-2.0, but CHANGELOG.md, which ships in the crate, has no
entry for it. The release that carries the relicense would therefore not
tell anyone upgrading that the terms changed.

Add an Unreleased entry recording the change and naming 0.36.0 as the
last release under GPL-3.0 with the linking exception. The version
number is left to whoever cuts the release; they rename the heading when
they bump Cargo.toml.
The npm packages declare MIT OR Apache-2.0 but would have carried no
licence text if published: the main package directory has no licence
file, and each platform package's `files` list names only its .node
addon.

The publish workflow now copies the repository's LICENSE-MIT and
LICENSE-APACHE into the main package and every platform package after
the addons are moved into place, and each platform package lists both
files. The repository root stays the only copy of the texts. Checked by
running the copy step on a copy of nodejs/ with stub addons: npm pack
--dry-run then lists both files in all five packages.

@dirvine dirvine left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — release follow-up still outstanding

Reviewed d33b568234daa66c67cd0af59964ea341aa4c770.

The Node licence metadata and packaging changes are sound. I reproduced the workflow licence-copy step and checked npm pack --dry-run --ignore-scripts for the root and all four platform packages: each includes both licence texts. Native addons were not rebuilt.

The previous review explicitly requested either a publishable Cargo version bump or a linked release follow-up. Cargo.toml still has 0.36.0, crates.io still reports that version under GPL-3.0 (with the source's linking exception), and I found no follow-up linked in the PR body/comments. The new Unreleased changelog entry does not fulfil either alternative.

Recommendation: keep that request open. Add the version bump, or link a concrete release follow-up and avoid closing the release obligation with this metadata-only patch. There is no need to force publishing into this PR if the follow-up is explicitly tracked.

Applicable CI is green. This is an advisory engineering review; no approval or merge performed.

Panel adjudication: the initial specialist and independent GLM-5.2 reviewer considered the diff approvable (with release concerns); both adversarial reviewers and the coordinator retain the explicitly outstanding bump-or-linked-follow-up request. The disagreement is about satisfying the prior review, not a new code defect.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants