Phase 6: license-compliance audit and enterprise/ relicensing to AGPLv3
Full dependency inventory across Rust/Go/npm plus Docker base images and vendored assets (776 rows, 502 unique deps), classified against AGPLv3 compatibility with real citations rather than assumptions. enterprise/ relicensed from its commercial-license stub to AGPLv3, matching core -- the one real flag (Redpanda's BSL 1.1) was evaluated against primary sources and accepted as-is rather than triggering a broker swap. CI enforcement wired up (.github/workflows/license- compliance.yml, this repo's first CI workflow), a root LICENSE file added, and every doc/comment referencing the old commercial-license boundary updated to describe it as architectural only. See /docs/compliance/ for the full report, inventory, and policy.
This commit is contained in:
+4
-2
@@ -192,8 +192,10 @@ attribute" above.
|
||||
surface) -- meaningfully different auth model (offline operator flags
|
||||
today, not a stable REST API a provider could safely drive
|
||||
idempotently -- see `/enterprise/README.md`'s "Bootstrapping a tenant"
|
||||
section) and Phase 4 commercial licensing, so this would need its own
|
||||
design pass, not just "add another resource file."
|
||||
section), so this would need its own design pass, not just "add
|
||||
another resource file." (Not a licensing question as of Phase 6 --
|
||||
`enterprise/` is AGPLv3 same as this provider module; the blocker is
|
||||
purely that the underlying API isn't idempotent-safe yet.)
|
||||
- Publishing to the real Terraform Registry -- `main.go`'s `Address`
|
||||
(`registry.terraform.io/sentry/sentry`) is the address a real
|
||||
publication would use, but nothing has actually been published; local
|
||||
|
||||
Reference in New Issue
Block a user