Puts the licence files on master ahead of making this repository public.
LICENSE -- GPLv3, which Cargo.toml has been declaring as GPL-3.0 all along without the file being present.
LICENSE-DATA -- CC0 1.0 for contributed manifests, which are data submitted by other people rather than this project code.
Plus the two docs commits already on the branch (tagging untagged verifications, recording the UR-007 conflict).
Verified before publishing: no .env, key, certificate or credential file appears anywhere in history, and the only high-entropy literals in the tree are a base64 alphabet constant in validate.rs and dummy ULIDs in tests. The token/secret matches throughout src/auth.rs are the bearer-capability mechanism the server implements, not stored credentials.
Puts the licence files on master ahead of making this repository public.
- `LICENSE` -- GPLv3, which `Cargo.toml` has been declaring as `GPL-3.0` all along without the file being present.
- `LICENSE-DATA` -- CC0 1.0 for contributed manifests, which are data submitted by other people rather than this project code.
Plus the two docs commits already on the branch (tagging untagged verifications, recording the UR-007 conflict).
Verified before publishing: no `.env`, key, certificate or credential file appears anywhere in history, and the only high-entropy literals in the tree are a base64 alphabet constant in `validate.rs` and dummy ULIDs in tests. The `token`/`secret` matches throughout `src/auth.rs` are the bearer-capability mechanism the server implements, not stored credentials.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
`license = "GPL-3.0-or-later"` has been in the manifest since the start, and
cargo-deny's allow-list carries it annotated "This crate's own licence" — but
no LICENSE file existed, so the declaration pointed at nothing.
Text copied from the jRay plugin's LICENSE after verifying it is byte-identical
to the FSF's canonical gpl-3.0.txt, rather than transcribed. 674 lines where a
single altered word changes the terms is not a file to write by hand.
No requirement trailer: this serves none, it completes an existing declaration.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributed manifests were in no declared condition at all, which left §9a
replication with no grant flowing through it: peers mirror each other's
catalogues wholesale, and every hop of that was unlicensed.
CC0 rather than a share-alike licence, because a share-alike works by asserting
a right in the data and then conditioning its use. The position in
docs/legal-posture.md §3 is that presence timings are facts rather than
protectable expression — asserting copyright in them in order to license them
would contradict that argument in the same repository, and that contradiction is
worth more to an opponent than the licence is worth to us. CC0 also waives the
sui generis database right by name, closing the EU-specific residual exposure
from the contributor's side.
The grant is taken at token issuance, and that is not incidental. There are no
accounts, so there is no sign-up to attach terms to, and a manifest arrives over
POST /manifests with no channel to negotiate over. Acquiring the contribute
capability is the only moment a grant can be made, so POST /tokens now returns
the licence and its terms alongside the token — a licence the server publishes
but never delivers is one no contributor agreed to.
The test pins the scope limit as well as the identifier. Bounding the grant to
the manifest is the half that can fail silently: a reworded term reading onto
the underlying work would purport to grant what no contributor can.
Also records the settled code-licence position across all four repositories in
the legal posture, correcting an earlier claim there that the plugin and
extraction repos declared nothing. Both already carried LICENSE files.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
TRACES: UR-019 | PR-006
Five tests and the schema constant implemented requirements without
carrying a tag, so those requirements read as uncovered when they were
not. No behaviour changes here — every edit is a comment.
Also documents `static` as a real tier rather than an exemption: it is
already in `ci_executable_tiers` and its checks run in CI, and it exists
because DR-007's single binary and DR-012's licence policy are properties
of the build that a unit test could only assert as theatre.
The UR-007 note records a cross-repo status conflict rather than
resolving it. `jRay` JR-025 is `Done` and claims UR-007, but the fetch
path that would exercise it (`jRay` JR-031) is still `Planned`. Either
JR-025 is scoped to selection alone or it over-claims; until that is
settled neither register should be trusted for UR-007 coverage.
The gate reports 0 orphan tags and 19/19 UR coverage.
TRACES: DR-001, DR-014, UR-015, UR-016, UR-018 | SR-003, SR-004
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Puts the licence files on master ahead of making this repository public.
LICENSE-- GPLv3, whichCargo.tomlhas been declaring asGPL-3.0all along without the file being present.LICENSE-DATA-- CC0 1.0 for contributed manifests, which are data submitted by other people rather than this project code.Plus the two docs commits already on the branch (tagging untagged verifications, recording the UR-007 conflict).
Verified before publishing: no
.env, key, certificate or credential file appears anywhere in history, and the only high-entropy literals in the tree are a base64 alphabet constant invalidate.rsand dummy ULIDs in tests. Thetoken/secretmatches throughoutsrc/auth.rsare the bearer-capability mechanism the server implements, not stored credentials.🤖 Generated with Claude Code