Skip to content

fix(license): restore canonical MPL-2.0 text (line 212 comma) - #234

Merged
erinepshovel-code merged 1 commit into
mainfrom
repair/license-mpl-canonical-comma
Sep 27, 2026
Merged

erinepshovel-code merged 1 commit into
mainfrom
repair/license-mpl-canonical-comma

Conversation

@erinepshovel-code

@erinepshovel-code erinepshovel-code commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

What was wrong

LICENSE was the MPL-2.0 text with one character missing. Line 212 read such warranty, support, indemnity or liability obligation; the canonical text has indemnity, or. Erin's 2026-09-26 rights audit of the org's repos flagged this comma. Its fix was to replace LICENSE with the canonical MPL-2.0 text, which restores the comma. The README also had no license statement.

What changed

  • LICENSE: replaced with the canonical MPL-2.0 text from https://www.mozilla.org/media/MPL/2.0/index.txt. The resulting diff is exactly the one comma on line 212.
  • README.md: added a ## License section naming MPL-2.0 (SPDX MPL-2.0) and linking LICENSE.
  • pyproject.toml is unchanged on purpose. It declares license = {file = "LICENSE"} plus the MPL 2.0 classifier, which already matches. tools/verify_distributions.py also binds the wheel's License/License-File/Dynamic: license-file metadata to that form, so switching to a PEP 639 SPDX expression is a packaging change, not hygiene. See hmmm.
  • No license change.

Verification

  • cmp LICENSE <(curl -sL https://www.mozilla.org/media/MPL/2.0/index.txt): identical (sha1 d7e3ed5a…). git diff main -- LICENSE shows only line 212.
  • uv lock --check passed. uv sync --locked --python 3.12 --extra test --extra build.
  • Full suite via tools/_boundary_pytest.run_suite (the CI invocation): 231 passed, 2 failed locally. Both failures (test_node24_capability_runs_typescript_witness, test_vendored_typescript_parser_retains_numeric_field_names) need Node 24 TypeScript stripping. The local host has Node v20.19.2 and CI pins 24.15.0, so this is an environment gap, not caused by this change.
  • Clean git archive HEAD build: twine check PASSED. tools/verify_distributions.py . dist: "distribution replay inputs: exact". The wheel's License metadata matches the new LICENSE.
  • CI on head ca9995e: verify (3.10/3.11/3.12) and CodeQL all green. That includes the Node 24 tests.

License detection

licensee detect . (licensee 10.1.0) on this branch's checkout:

License:        MPL-2.0
Matched files:  LICENSE, README.md
LICENSE:
  Content hash:  820048a1dbef5dfac65547bd9eb935beb76b2257
  Confidence:    100.00%
  Matcher:       Licensee::Matchers::Exact
  License:       MPL-2.0

On main, gh api repos/The-Interdependency/ucns/license already reports MPL-2.0 (fuzzy match). After merge it should be an exact match.

hmmm

  • pyproject.toml still uses the legacy license = {file = "LICENSE"} table instead of license = "MPL-2.0" + license-files. Changing it would alter the wheel METADATA fields that verify_distributions.py asserts, so it belongs in a separate, coordinated packaging change.
  • Earlier grants are unchanged: PyPI 0.8.2/0.8.3 and tag v0.8.3 were Apache-2.0, and tags v0.9.0/v0.9.1 were MPL-2.0. A planned later step would put the exposition (docs/, CANON.md, README) under a Creative Commons share-alike license. That is not part of this PR; the new README line describes the repo's current single license.
  • This is licensing hygiene, not legal advice.

RIGHTS-AUDIT Phase 1.2: LICENSE differed from the canonical Mozilla text
only at line 212 ('indemnity or' -> 'indemnity, or'). LICENSE is now
byte-identical to https://www.mozilla.org/media/MPL/2.0/index.txt.
README gains a License section naming MPL-2.0. No license change.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T06:03:04.814951Z ca9995e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@erinepshovel-code
erinepshovel-code merged commit fc01e1f into main Sep 27, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant