Repository navigation
Apache-2.0 でライセンスを明文化し、商標除外と第三者表示を整える - #58
Merged
Merged
Conversation
The repository is public but had no LICENSE, so the code was legally all-rights-reserved while the README claimed "free for personal and learning use" — a grant too vague to act on. Apache-2.0 lets people use, modify and redistribute the tester (including commercially) while requiring our copyright notice to travel with it, and its Section 6 keeps our product names, logos and product images out of the grant. NOTICE records the excluded brand assets and keeps the credit to the CodePen pen the first version was based on. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
The released exe bundles the WebView2 SDK, SharpCompress and (in self-contained builds) the .NET runtime, all of which require their copyright notice to be reproduced with a binary distribution — but nothing in the zip carried those notices. Collect them in THIRD-PARTY-NOTICES.md and copy LICENSE, NOTICE and that file next to the exe so every publish and release zip carries them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
keycodes.js pointed at vial-gui as its "source of truth" without saying what was taken from it. vial-gui is GPL-2.0, so a reader of an Apache-2.0 repository needs to see that the reference covers the keycode numbering — an interface fact — and not the code. Do the same for the vial-gui and kle-serial references in vial-layout.js. Comments only; no behavior change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
README says the product images under docs/ are outside the grant, but NOTICE named only the two headline images, so its list read as exhaustive. docs/design/ holds UI screenshots of the same branded screens; name them too. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
A reader landing on one file should be able to tell how it is licensed without walking back to the repository root, and SPDX tags let scanners do the same. Two-line REUSE-style header on the JS, CSS, HTML and C# sources; the shebang and the doctype stay first in their files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
The first version of the tester came from a public CodePen pen, and the NOTICE left open what that pen allowed. CodePen's licensing documentation says public pens are MIT licensed, which permits carrying that code into an Apache-2.0 work — so the origin raises no conflict with the license this repository now uses. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概要
public リポジトリなのに
LICENSEが無く、法的には全著作権留保だった。README.mdの「個人利用・学習目的で自由に使用できます」も改変・再配布・商用の可否が読み取れず、運用できる許諾ではなかった。
方針は 「利用可 / 当方の権利表示は必須 / 当方商標は利用不可」。これは Apache-2.0 の
第4条(
LICENSEとNOTICEの同梱・変更点の明示)と第6条(商標不許諾)にそのまま対応するので、Apache-2.0 を採用し、商標・製品画像の除外を
NOTICEに明記した。判断の経緯は knowledge-base の判断記録に残してある(techmech-keeb/knowledge-base#63)。
この PR と knowledge-base#63 は1つの変更単位で、ブランチ名を共有しているのはそのため。
変更内容
3b91518LICENSE(Apache-2.0 全文)、NOTICE(商標・ロゴ・製品画像の除外+CodePen クレジット)、README ライセンス節の差し替え915ad2aTHIRD-PARTY-NOTICES.mdを追加し、LICENSE/NOTICE/ 同ファイルを exe と同じ場所へ出力(csproj)。配布 zip にも入るa7947b4ui/keycodes.js/ui/vial-layout.jsの参照元に GPL-2.0 / MIT を明記(コメントのみ)f3a2708NOTICEの除外対象にdocs/design/のスクリーンショットも含める(README の記述と一致させる)3ecc1b544b253bNOTICEに記録補足:
名称・ロゴ、
docs/screenshot.png・docs/attract.png・docs/design/の UI スクリーンショット。フォーク配布時は名称と画像の差し替えを求める文面にしている。
同梱するのに、配布物に権利表示が入っていなかった。各ライセンス文は nupkg と上流リポジトリの
実ファイルから転記(WebView2 SDK 1.0.2903.40 = BSD 3-clause 形式、SharpCompress 0.38.0 = MIT、
dotnet/runtime = MIT。2026-09-13 取得)。
コードではない旨をコメントに明記した(
rmk-configの「事実 vs 表現」基準と同じ扱い)。検証
build-kiosk: success(3ecc1b5、run 34735184888)— csproj 変更後も publish が通り、UI の SHA-256 照合も通過visual-check: success(3ecc1b5、run 34735184874)node tools/visual-check.js: 90 枚すべて通過(SPDX ヘッダ付与後に再実行)node --test tools/boards.test.js tools/scroll-input.test.js tools/vial-layout.test.js: 24 件すべて passf3a2708/44b253bはNOTICEのみの変更のため CI 対象外(build-kiosk / visual-check の paths に該当しない)TechmechInputLab.exeと同じ階層にLICENSE/NOTICE/THIRD-PARTY-NOTICES.mdが並ぶことは、次の publish 成果物で目視確認が必要要確認)。未登録でもNOTICEの記載は「許諾に含めない」という意思表示として働く🤖 Generated with Claude Code
https://claude.ai/code/session_012wNSUjsfpkg256wh6Utxom
Generated by Claude Code