Adopt pinned public core snapshot and prepare Sized 2.0.0
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
# Sized 2.0 source and dependency notices
|
||||
|
||||
Sized and the exact public core snapshot retain GPL-3.0-only. The owner confirmed
|
||||
that the first-party code was developed by Cole Speelman with Codex assistance.
|
||||
The core forge remains private; `crates/sized-core` includes the required source
|
||||
at `fb63e96266dcb8ffbca53b73c6c0f738ac3e827d`. `CORE-SNAPSHOT.json` records the
|
||||
upstream revision and exact file hashes; `scripts/check-core.py` checks them.
|
||||
The snapshot preserves upstream README/provenance as historical source records.
|
||||
|
||||
Each binary download is accompanied by its exact source archive, including
|
||||
Cargo.lock, all registry dependencies, core source, build scripts and original
|
||||
notices. Recipients need no forge credentials. The archive is checked with an
|
||||
empty Cargo cache and offline mode. Preserve it as long as the binaries remain
|
||||
available. Source-only development dependencies retain their original bundled
|
||||
notices and package licence metadata in the vendor directory.
|
||||
|
||||
`scripts/package-notices.py` uses Cargo's normal/build tree for the target and
|
||||
locked metadata to produce `DEPENDENCIES.json` and complete `LICENCES.txt`.
|
||||
Development-only and inactive optional dependencies are excluded from the binary
|
||||
inventory. Missing notices and new licence expressions stop packaging. Where a
|
||||
choice is offered, this distribution uses MIT, or Apache-2.0 when MIT is absent;
|
||||
all bundled alternative licence texts and copyright notices are preserved.
|
||||
Unicode-3.0 notices are retained along with MIT/Apache notices where required.
|
||||
No third-party licence is replaced by the first-party licence.
|
||||
|
||||
The existing `colored` 2.2.0 dependency is MPL-2.0. Its sources and notices are
|
||||
unmodified; inspection found no Exhibit B declaration in its source files or
|
||||
README. The generic Exhibit B in the MPL licence text itself is not an applied
|
||||
declaration. Under MPL section 3.3, colored is additionally distributed under
|
||||
GPL-3.0-only as part of this Larger Work. Its original MPL rights and notices
|
||||
remain available to recipients. This notice accompanies both binary and source.
|
||||
See Mozilla's [MPL/GPL guidance](https://www.mozilla.org/en-US/MPL/2.0/combining-mpl-and-gpl/)
|
||||
and [MPL FAQ](https://www.mozilla.org/en-US/MPL/2.0/FAQ/#q14-may-i-combine-mpl-licensed-code-and-lgpl-licensed-code-in-the-same-executable-program).
|
||||
|
||||
The Mac CLI links Apple's system libraries; Linux dynamically links system
|
||||
libraries including glibc. Each target's requirements and linked libraries are
|
||||
recorded with its release verification. A new dependency, target or licence
|
||||
expression requires reviewing the affected notices before distribution.
|
||||
Reference in New Issue
Block a user