Requirement (Gold level): The project MUST include a license and copyright statement in each source file
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 548
- Forks
- 133
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 2
Description
We agreed on #1175 to open an issue to follow up a discussion about the these requirements for Node.js (cc: @mhdawson @ljharb @RafaelGSS)
The project MUST include a copyright statement in each source file, identifying the copyright holder (e.g., the [project name] contributors).
The project MUST include a license statement in each source file. This MAY be done by including the following inside a comment near the beginning of each file: SPDX-License-Identifier: SPDX license expression for project
Context
- Discussion during the last meeting (Minute 28:20)
- CII Best Practices: Copyright Per File
- Team Discussion 1
- Team Discussion 2
Potential actions
- Discuss with the OSSF in order to remove these requirements or clarify the need for them
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing issue #1175 and the cited CII Best Practices requirement, then read the linked security-wg team discussions. Done means reaching and documenting a decision with the OSSF about whether the per-file copyright and SPDX requirements should remain or be clarified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100