Skip to content

chore(licence): remove the MIT label and add an all-rights-reserved notice - #190

Merged
trakhimenok merged 5 commits into
mainfrom
datatug-apps-licence-label
Oct 4, 2026
Merged

trakhimenok merged 5 commits into
mainfrom
datatug-apps-licence-label

Conversation

@trakhimenok

@trakhimenok trakhimenok commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Removes the MIT label from the web app repository and states that no licence is granted yet.

  • package.json: "license": "MIT" becomes "license": "UNLICENSED" (the package is already private).
  • LICENSE: new all-rights-reserved notice; says a licence will be announced and points to the Apache-2.0 CLI, and says bundled third-party demo data (Chinook, World Bank) stays under its own licence.
  • README.md: the licence section and the opening sentence no longer say this repository is open source.
  • landings/index.html: the "Free & Open Source" section no longer names MIT and Apache 2.0 for repositories that are private or gone; it now states only that the CLI is open source under Apache-2.0.

Why: founder ruling. On 2026-09-09: "CLI - Apache 2.0. Web UI private for now, will be AGPL or something like that". On 2026-10-04, asked whether to remove the MIT label and add an all-rights-reserved notice now, with the AGPL decision left until after the paid test, he answered "yes". The repository has been public with an MIT label and no licence file. The copyright holder is written as "the DataTug authors" because no legal owner has been stated for this repository.

No code changes.

🤖 Generated with Claude Code

…otice

The web app repository was public with "license": "MIT" in package.json and
no licence file, against the founder's recorded intent (2026-09-09: "Web UI
private for now, will be AGPL or something like that"; 2026-10-04: "yes" to
removing the MIT label now and deciding AGPL after the paid test).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@trakhimenok

Copy link
Copy Markdown
Contributor Author

[review r1 #190] independent adversarial review (Opus), head 9bd8c8e

Independent review, round 1 — head 9bd8c8e

What I verified

  • Scope. git diff origin/main...HEAD is exactly three files, one commit: LICENSE (+8), README.md (2 lines), package.json (1 line). No code, lockfile or config change.
  • UNLICENSED is the right npm value. It is npm's documented value for "no licence granted" (distinct from Unlicense, which is a public-domain dedication). Root package.json is already "private": true (line 16).
  • Workspace libraries. None of the five libs/datatug/*/package.json files nor landings/incidentius/package.json has a license field. None of the five library names exists on the npm registry (all 404), and there is no publish step in the workflows. Nothing published contradicts this change.
  • CLI claim is true. datatug/datatug-cli is public and GitHub reports Apache-2.0.
  • README. Both edited sentences are accurate; "an open-source CLI and a web UI" no longer claims the web UI is open source. The LICENSE link resolves. README has no contribution invitation that would need licence terms.
  • Other MIT / open-source mentions. git grep outside lockfiles: all remaining MIT hits are third-party Chinook fixture notices and test data (correct, must stay), except the one in finding 1. landings/incidentius/.../BaseLayout.astro:59 ("Open-source projects" linking to the GitHub organisation) is fine.
  • AGENTS.md / CLAUDE.md say nothing about licensing; no rule is broken.
  • Checks (run 37229699708): build pass, test pass, e2e pass, journey e2e (real datatug-cli agent) pending when I looked. All four are required on main. Nothing red; main itself is green on its last three CI runs.
  • Not verified: the founder's 2026-10-04 "yes" (relayed to me, not seen), and the author's hand-off — the cited wave1-results.json and plan.md contain no entry for this task.

Findings

Serious

  1. landings/index.html:39 — the repository still carries a "Free & Open Source" section (lines 38-49) saying "Web app ... Apache 2.0 license" and "Agent ... MIT license". This contradicts the new LICENSE and the description's statement that the repository no longer says it is open source. The links are also dead (one 404, one private). The file appears not to be deployed (no reference in wrangler.jsonc, firebase.json or deploy.yml), which is why this is not a blocker. Fix: delete that <section>, or replace it with one line pointing at the Apache-2.0 CLI.

Minor

  1. LICENSE:1 — "the DataTug authors" is an unnamed holder with no year. The repository names no owner, but the upstream this code was extracted from (sneat-co/sneat-apps) names "Licensor: Sneat.co", and the app footer shows a Sneat.Work copyright line. Fix: ask the founder for the legal owner and write Copyright (c) 2026 <owner>. All rights reserved. A follow-up is acceptable.
  2. LICENSE:4 — the notice is prospective only. package.json said MIT from the initial commit (2026-03-04) in a public repository, and the upstream sneat-apps licence is Apache 2.0 with the Commons Clause. The wording ("at this time") claims nothing untrue; no file change needed, but the founder should be told.
  3. Process — no hand-off entry or declared deviations exist for this task in the cited files; the lead should confirm the founder approval from the transcript.

Land after finding 1 is fixed (or the founder explicitly rules it out of scope), the new head is re-reviewed, and all four required checks are green.

VERDICT: blockers=0 majors=1 minors=3 land=no

OpenVaultDB and others added 3 commits October 4, 2026 21:09
The previous sentence pointed at notice files that one bundled copy does
not have, and covered only third-party material although the demo
project files are first-party CC0. Wording as the reviewer proposed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@trakhimenok

Copy link
Copy Markdown
Contributor Author

Review by claude-opus-5-5@claude-code@r4-datatug-apps-190 (head df70bb98ed13)
Reviewed-Head: df70bb9

[review r4 #190] independent review (Opus), head df70bb9

Independent review, round 4 — head df70bb9

The content is sound and ready to land: the round-3 minor is closed, nothing new was found, and all four required checks are green on this head. The only step left is the branch update from main that the landing verb performs.

What I verified

  • Head. GitHub and the local worktree both report df70bb98ed13b193fbd5efd195a3f2d5e7cae852; the worktree is clean.
  • Delta since round 3 (801462c..df70bb9). One commit, one file: LICENSE +3/-3, lines 7-9 only. The new text is word for word the wording proposed in round 3. Nothing else changed.
  • Whole LICENSE (12 lines) reads consistently.
    • Lines 1-5: all rights reserved; published to be read; no licence to use, copy, modify or distribute; a licence will be announced.
    • Lines 7-9: material that carries its own licence notice stays under that licence. This preserves existing notices and grants nothing new.
    • Lines 11-12: the CLI's Apache-2.0 statement is intact and still true (datatug/datatug-cli is public, Apache-2.0 per the GitHub API).
    • No sentence contradicts another, and there is no AGPL or other licence the founder did not approve.
  • The carve-out is accurate against the tree.
    • chinook-demo/NOTICE.md declares the project files CC0 1.0 and carries the Chinook MIT notice.
    • chinook-demo/data/geo/DATA-LICENSE.md carries the World Bank and GeoNames CC BY 4.0 terms.
    • apps/datatug-app/src/assets/chinook-full.json carries an inline "license":"MIT" field, which "carries its own licence notice" now covers.
  • Full pull request diff. Still four files, licence text only: LICENSE (new, 12 lines), README.md (2 lines), landings/index.html (+5/-11), package.json ("license": "MIT" to "UNLICENSED"). No code, lockfile, workflow or config change.
  • Remaining claims. A fresh grep finds no other open-source or licence claim for this repository or the web app. The one other "open-source" label, landings/incidentius/src/layouts/BaseLayout.astro:59, links to the datatug GitHub organisation and is untouched by this pull request; not a finding.
  • Conflict risk from main. The branch is two commits behind (bddd27a fix(chat): initialize canonical Chinook demo project #189, 95fff83 fix(test): isolate datatug-main suites in forked processes #191). Together they touch 11 files under apps/datatug-app/e2e/ and libs/datatug/main/ (fix(test): isolate datatug-main suites in forked processes #191 only libs/datatug/main/vite.config.mts). None is one of this pull request's four files, so neither can conflict; GitHub reports MERGEABLE, BEHIND.

Round-3 finding

  • Minor 1, LICENSE:7-9 (carve-out pointed at notice files one bundled copy lacks, and covered only third-party material): CLOSED by df70bb9.
  • The separate follow-up from round 3 is still open and outside this pull request: add the Chinook MIT text beside apps/datatug-app/src/assets/chinook-full.json.
  • The two earlier declined-and-accepted minors (unnamed holder and no year; notice is prospective only) are unchanged.

New findings

None.

Remark, not a finding: all four commits on the branch are authored as OpenVaultDB <ovdb@localhost>, from the canonical clone's repo-local git config. The same is true of #189 and #191, whose squash commits on main are authored by the founder's GitHub account with no trailer for that identity, so it does not reach main.

Checks on this head (run 37234363489)

  • build: pass (47s)
  • test: pass (52s)
  • e2e: pass (1m19s)
  • journey e2e (real datatug-cli agent): pass (4m10s)

These are the four required checks on main, which also requires the branch to be up to date. wb ci wait refused, as expected for a branch behind main: "pull request head df70bb9 does not contain current target main at 95fff83; rebase or reintegrate before waiting or merging". I waited on gh pr checks --watch instead.

To land

Update the branch from main and wait for the four required checks on the resulting head. If the update adds only the merge from main, no further content review is needed.

VERDICT: blockers=0 majors=0 minors=0 land=yes

@trakhimenok
trakhimenok enabled auto-merge (squash) October 4, 2026 21:07
@trakhimenok
trakhimenok merged commit 5520dab into main Oct 4, 2026
4 checks passed
@trakhimenok
trakhimenok deleted the datatug-apps-licence-label branch October 4, 2026 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant