You are viewing a plain text version of this content. The canonical link for it is here.
Posted to legal-discuss@apache.org by "Bertrand Delacretaz (JIRA)" <ji...@apache.org> on 2018/03/13 15:39:00 UTC

[jira] [Commented] (LEGAL-374) 3rd party dependencies in Apache Software Grants

    [ https://issues.apache.org/jira/browse/LEGAL-374?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16397123#comment-16397123 ] 

Bertrand Delacretaz commented on LEGAL-374:
-------------------------------------------

Here's my view as an Incubation Mentor: I don't think a list of 3rd party dependencies is useful in a Software Grant. 

As per https://www.apache.org/licenses/software-grant.txt the Exhibit A of such a grant consists of a "list of software and other intellectual property covered by this agreement", I don't see how this would require listing 3rd party dependencies.

If our VP Legal can confirm agreement with the above view I think we're all good.

Additional comments about Software Grants in general, again from my Incubation Mentor's point of view:

What's needed for the grant's Exhibit A is a *very clear* description of what's being donated - ideally, the donated code is in a single zip or tar archive, containing nothing else than the donated code. A sha-256 digest of the archive is included in the Software Grant, pointing very precisely to the exact code that's being donated so there are no ambiguities.

3rd party dependencies come into play when the time comes to make an Apache Release, so we ask for a reasonably precise list of them in Incubator proposals, but that's a different topic.



> 3rd party dependencies in Apache Software Grants
> ------------------------------------------------
>
>                 Key: LEGAL-374
>                 URL: https://issues.apache.org/jira/browse/LEGAL-374
>             Project: Legal Discuss
>          Issue Type: Question
>            Reporter: Geertjan Wielenga
>            Priority: Major
>
> What are the requirements for the content of Apache Software Grants? Is it mandatory for a list of 3rd party dependencies (i.e., external dependencies, e.g., binaries such as JARs or ZIPs that are downloaded during build or at runtime) of the code to be donated to be included in the grant document? If not mandatory, is it at least optional or could it be considered a courtesy to include that information?



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: legal-discuss-unsubscribe@apache.org
For additional commands, e-mail: legal-discuss-help@apache.org