Audit: dependency licences are AGPL-3.0-only compatible #868

Open
opened 2026-10-02 16:47:41 +00:00 by kayg · 2 comments
Owner

CLAUDE.md: dependencies must be AGPL-compatible (no GPL-2.0-only, no proprietary, no non-commercial model weights); every crate sets license = AGPL-3.0-only and every package.json "license": "AGPL-3.0-only". Read Cargo.lock and the bun lockfile; get licences from the local cargo registry sources (~/.cargo/registry/src) and node_modules package.json files (read only; do not install). Also check model files and runtimes referenced in the repo (voice, OCR, embeddings, decision models) and NOTICE/licenses/. Report every incompatible, unknown or missing licence and every crate/package without the project licence. File one issue with the table.

Read-only job (LIGHT class)

This job runs at the lowest CPU priority on a shared, overloaded build host. Do not build or test: no cargo build/test/clippy/check, no bun install/build/test/run check, no servers, no browsers. Use rg, sed, git, scripts/fj, and reading. Write findings to audit-findings.md at the worktree root as you go (append per finding) and commit it on your branch. For each real defect: search existing issues first (scripts/fj --host https://git.kayg.org issue search --repo kayg/calternal "<terms>"), then either add evidence to the existing issue or create one self-contained issue (title, evidence with file:line, owner rule or DESIGN section, expected behaviour, test idea) that a later build job can own. Group findings that share one fix into one issue (one owner per shared fix). No product code changes. Post a summary with the list of issues on your own issue. Docs use ASD-STE100 Simplified Technical English.

CLAUDE.md: dependencies must be AGPL-compatible (no GPL-2.0-only, no proprietary, no non-commercial model weights); every crate sets license = AGPL-3.0-only and every package.json "license": "AGPL-3.0-only". Read Cargo.lock and the bun lockfile; get licences from the local cargo registry sources (~/.cargo/registry/src) and node_modules package.json files (read only; do not install). Also check model files and runtimes referenced in the repo (voice, OCR, embeddings, decision models) and NOTICE/licenses/. Report every incompatible, unknown or missing licence and every crate/package without the project licence. File one issue with the table. ## Read-only job (LIGHT class) This job runs at the lowest CPU priority on a shared, overloaded build host. **Do not build or test**: no `cargo build/test/clippy/check`, no `bun install/build/test/run check`, no servers, no browsers. Use `rg`, `sed`, `git`, `scripts/fj`, and reading. Write findings to `audit-findings.md` at the worktree root as you go (append per finding) and commit it on your branch. For each real defect: search existing issues first (`scripts/fj --host https://git.kayg.org issue search --repo kayg/calternal "<terms>"`), then either add evidence to the existing issue or create one self-contained issue (title, evidence with file:line, owner rule or DESIGN section, expected behaviour, test idea) that a later build job can own. Group findings that share one fix into one issue (one owner per shared fix). No product code changes. Post a summary with the list of issues on your own issue. Docs use ASD-STE100 Simplified Technical English.
Author
Owner

Audit started on branch job/licence-audit, based at 440e19dce23040ac8ebaae88f0469b6535b1afcb (same as origin/dev at inspection). I am reading lockfiles and local package metadata only; no install, build, test, or product-code changes.

Audit started on branch `job/licence-audit`, based at `440e19dce23040ac8ebaae88f0469b6535b1afcb` (same as `origin/dev` at inspection). I am reading lockfiles and local package metadata only; no install, build, test, or product-code changes.
Author
Owner

Audit complete. Findings are committed on job/licence-audit at f35a06885b558226115c5fff75d1ef48dc2c59bb.

Area Result
First-party licences All 30 Rust packages resolve to AGPL-3.0-only; all seven npm packages set AGPL-3.0-only.
Locked dependencies 884 Cargo and 747 npm release records reviewed. No incompatible licence found.
Unknown licences None after exact-version registry checks. Five Cargo source directories and 123 npm package manifests were absent from local caches; exact registry metadata resolved them.
Missing SPDX fields nom-exif 3.8.0 has an MIT LICENSE; svelte-toolbelt 0.10.6 has an MIT LICENSE.
Models MiniLM is Apache-2.0; CLIP is MIT. No non-commercial model weights or voice, OCR, decision, or face model runtime assets were found.

One distribution finding was added to existing issue #812: the final image recipe copies only the server binary and omits the project licence and third-party notices. This matters because the binary embeds GeoNames CC BY 4.0 data and uses the ODbL timezone-boundary dataset. I found no duplicate issue and opened no new issue.

The full licence table and evidence are in audit-findings.md.

Checks: git diff --check produced no output and exited 0. Cargo and Bun build/test gates were not run because the LIGHT job rules prohibit them. cargo clean removed 1 file (356 B); apps/web/build was absent.

No product files changed. The only decision was to add the image notice evidence to #812 because that issue already tracks MPL, LGPL, and data licence notices.

Audit complete. Findings are committed on `job/licence-audit` at `f35a06885b558226115c5fff75d1ef48dc2c59bb`. | Area | Result | |---|---| | First-party licences | All 30 Rust packages resolve to `AGPL-3.0-only`; all seven npm packages set `AGPL-3.0-only`. | | Locked dependencies | 884 Cargo and 747 npm release records reviewed. No incompatible licence found. | | Unknown licences | None after exact-version registry checks. Five Cargo source directories and 123 npm package manifests were absent from local caches; exact registry metadata resolved them. | | Missing SPDX fields | `nom-exif 3.8.0` has an MIT `LICENSE`; `svelte-toolbelt 0.10.6` has an MIT `LICENSE`. | | Models | MiniLM is Apache-2.0; CLIP is MIT. No non-commercial model weights or voice, OCR, decision, or face model runtime assets were found. | One distribution finding was added to existing issue #812: the final image recipe copies only the server binary and omits the project licence and third-party notices. This matters because the binary embeds GeoNames CC BY 4.0 data and uses the ODbL timezone-boundary dataset. I found no duplicate issue and opened no new issue. The full licence table and evidence are in `audit-findings.md`. Checks: `git diff --check` produced no output and exited 0. Cargo and Bun build/test gates were not run because the LIGHT job rules prohibit them. `cargo clean` removed 1 file (356 B); `apps/web/build` was absent. No product files changed. The only decision was to add the image notice evidence to #812 because that issue already tracks MPL, LGPL, and data licence notices.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#868
No description provided.