Check StudyBuddy's dependencies against its distribution mode and project licence using these simplified rules (not legal advice):
- Licence families:
MIT,BSD,APACHE2→ permissive;LGPL,MPL2→ weak;GPL2,GPL3→ strong;AGPL3→ network;NONE→ no licence. - Project licence:
PROPRIETARY,APACHE2,GPL3. Mode:DISTRIBUTED(app/download) orSERVICE(runs only on our server).
Rules for each dependency, checked in this order:
NONE→BLOCK (no licence: no permission).AGPL3: if the project licence isGPL3→OK (offer source to network users); otherwise →BLOCK (AGPL3 requires offering source)— in both modes.GPL2orGPL3in modeSERVICE→OK (not distributed).GPL2/GPL3in modeDISTRIBUTED: allowed only if the project isGPL3and the dependency isGPL3→OK (same licence); projectGPL3withGPL2→BLOCK (GPL2-only is incompatible with GPL3); otherwise →BLOCK (strong copyleft in distributed non-GPL work).APACHE2when the project isGPL3→OK (compatible with GPL3; keep NOTICE).- Weak copyleft →
OK (keep library changes under its licence). - Other permissive →
OK (keep notices).
Input: first line projectLicence mode, then lines dependency licence. Output dependency (LICENCE): RESULT per line, then Blocked: b and Verdict: SHIP if b = 0, otherwise Verdict: DO NOT SHIP.
Input:
PROPRIETARY DISTRIBUTED
gson APACHE2
charts GPL3
utils NONE
pdfkit MPL2
Output:
gson (APACHE2): OK (keep notices)
charts (GPL3): BLOCK (strong copyleft in distributed non-GPL work)
utils (NONE): BLOCK (no licence: no permission)
pdfkit (MPL2): OK (keep library changes under its licence)
Blocked: 2
Verdict: DO NOT SHIP