fix(license): restore canonical MPL-2.0 text (line 212 comma) - #234
Merged
Merged
Conversation
RIGHTS-AUDIT Phase 1.2: LICENSE differed from the canonical Mozilla text
only at line 212 ('indemnity or' -> 'indemnity, or'). LICENSE is now
byte-identical to https://www.mozilla.org/media/MPL/2.0/index.txt.
README gains a License section naming MPL-2.0. No license change.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
LICENSEwas the MPL-2.0 text with one character missing. Line 212 readsuch warranty, support, indemnity or liability obligation; the canonical text hasindemnity, or. Erin's 2026-09-26 rights audit of the org's repos flagged this comma. Its fix was to replace LICENSE with the canonical MPL-2.0 text, which restores the comma. The README also had no license statement.What changed
LICENSE: replaced with the canonical MPL-2.0 text from https://www.mozilla.org/media/MPL/2.0/index.txt. The resulting diff is exactly the one comma on line 212.README.md: added a## Licensesection naming MPL-2.0 (SPDXMPL-2.0) and linkingLICENSE.pyproject.tomlis unchanged on purpose. It declareslicense = {file = "LICENSE"}plus the MPL 2.0 classifier, which already matches.tools/verify_distributions.pyalso binds the wheel'sLicense/License-File/Dynamic: license-filemetadata to that form, so switching to a PEP 639 SPDX expression is a packaging change, not hygiene. See hmmm.Verification
cmp LICENSE <(curl -sL https://www.mozilla.org/media/MPL/2.0/index.txt): identical (sha1d7e3ed5a…).git diff main -- LICENSEshows only line 212.uv lock --checkpassed.uv sync --locked --python 3.12 --extra test --extra build.tools/_boundary_pytest.run_suite(the CI invocation): 231 passed, 2 failed locally. Both failures (test_node24_capability_runs_typescript_witness,test_vendored_typescript_parser_retains_numeric_field_names) need Node 24 TypeScript stripping. The local host has Node v20.19.2 and CI pins 24.15.0, so this is an environment gap, not caused by this change.git archive HEADbuild:twine checkPASSED.tools/verify_distributions.py . dist: "distribution replay inputs: exact". The wheel's License metadata matches the new LICENSE.ca9995e: verify (3.10/3.11/3.12) and CodeQL all green. That includes the Node 24 tests.License detection
licensee detect .(licensee 10.1.0) on this branch's checkout:On
main,gh api repos/The-Interdependency/ucns/licensealready reportsMPL-2.0(fuzzy match). After merge it should be an exact match.hmmm
pyproject.tomlstill uses the legacylicense = {file = "LICENSE"}table instead oflicense = "MPL-2.0"+license-files. Changing it would alter the wheel METADATA fields thatverify_distributions.pyasserts, so it belongs in a separate, coordinated packaging change.docs/,CANON.md, README) under a Creative Commons share-alike license. That is not part of this PR; the new README line describes the repo's current single license.