Skip to content

chore: relicense the Seamless Auth ecosystem to Apache-2.0 #335

Description

@Bccorb

Part of #334.

Decision

Relicense the whole ecosystem from AGPL-3.0-only to Apache-2.0: the API, the SDKs, types, CLI, templates, messaging, admin dashboard and docs.

The SDKs are the main reason. @seamless-auth/react, client, core, express, fastify and types are all AGPL-3.0-only today and get bundled or linked into the adopter's own application, which most company and government legal reviews will block. Apache-2.0 over MIT for the explicit patent grant, which those same reviewers look for.

Before changing any file

External contributors hold copyright in their contributions and have to agree to the change (or those contributions are rewritten). From git log:

Repo Contributors other than the maintainer
seamless-auth-react Peter (12 commits), nightcityblade (1), kcorbettsr (1)
seamless-cli Bharat Bhojwani (1)
seamless-auth-docs Peter (11 commits)
  • Written consent from each, recorded on this issue or linked from it
  • Re-check every repo's history for new contributors right before switching

Per repo

For each of seamless-auth-api, seamless-auth-server, seamless-auth-react, seamless-auth-types, seamless-cli, seamless-templates, seamless-auth-messaging, seamless-auth-admin-dashboard, seamless-auth-docs:

  • Replace LICENSE / LICENSE.md with the Apache-2.0 text (and remove duplicates; several repos have both)
  • license field in every package.json, including workspace packages (some are missing it entirely)
  • Update the license header rule in eslint config and rewrite the header in every source file
  • README license section
  • Changeset (minor, describing the change) for each published package

Known leftovers to clean up on the way: seamless-auth-react/LICENSE.md still has template boilerplate, and seamless-auth-server/packages/fastify/LICENSE.md calls itself the Express package.

Outside the repos

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Security work outside the FIDO2 track

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions