TRADEMARKS.md: the marks already in the tree, and the rule for the ones coming #107

Closed
opened 2026-09-07 16:38:16 +00:00 by tiagoagueda · 0 comments
Owner

Observation

make a trademarks

#106 decided that a plugin may ship a third party's mark with a notice beside it, unmodified,
outside the AGPL grant, claiming no endorsement — and that this is a rule rather than an
exception for Europass. The rule needs somewhere to live before the first plugin logo lands.

It is not hypothetical: there is already an unmarked trademark in the tree

assets/support/buy-me-a-coffee.png

Added by #79, and it is exactly the thing #106 is about: somebody else's mark, shipped in an
AGPL repository, with nothing beside it saying whose it is. Every fork redistributes it. That
is almost certainly fine — it is an approved banner, used to link to the account it belongs
to, which is what approved banners are for — but the repository does not say so anywhere, and
that is the gap this closes.

Two more sets of third-party artwork are in the tree and are accounted for, differently:

What Where Covered by
Lucide icons, 40 files src/postulo/static/icons/ ISC, and each file keeps its @license comment
flag-icons, 241 files src/postulo/static/flags/ MIT, notice copied in beside them (#88)
Buy Me a Coffee banner assets/support/ nothing

The first two are copyright licences and are handled. A mark is not licensed at all, which is
why it needs a different kind of note rather than a third licence file.

And Postulo's own name has never been mentioned

assets/brand/postulo.png and seven derived files under src/postulo/static/brand/. The
README says the code is AGPL and says nothing about the name or the logo, so a reader has no
way to know what a fork may call itself.

That matters more here than in most projects, because of what the README promises. Never
paywalled
is a commitment about the project, not about the code — the licence cannot
enforce it, and a fork that added a paid tier and kept the name would break the promise for
everybody who had heard it. A trademark note is the only instrument that speaks to that, and
it is worth having for that reason rather than for control.

It is also explicitly permitted by the licence Postulo uses. AGPL-3.0 §7 lists the terms a
work may add, and clause (e) is "Declining to grant rights under trademark law for use of
some trade names, trademarks, or service marks"
. So this is not a restriction bolted on to a
free licence; it is the licence's own provision.

What the document says

  • The code is AGPL and the name is not. What that means in practice, in plain terms.
  • What anybody may do without asking: run it, fork it, redistribute it unmodified under
    the name, say truthfully that something works with Postulo, name a plugin
    postulo-something — which is the ecosystem's own convention and must be explicitly
    allowed, since eight repositories already use it.
  • Name your instance whatever you like. site.instance_name() exists so an operator can,
    and nothing in a trademark note should read as discouraging it.
  • What to do with a materially modified fork: give it another name, or say plainly that
    it is a modified version and not endorsed. The Firefox/Iceweasel arrangement, without the
    argument.
  • Third-party marks used here, named with their owners, and the four conditions from #106.
  • No endorsement, stated once and meant.

Scope

  • TRADEMARKS.md at the root.
  • The README's licence section points at it — it currently explains Lucide and flag-icons in
    a paragraph, and that paragraph is the right size for a licence note and the wrong place
    for a marks policy.
  • A notice beside assets/support/buy-me-a-coffee.png, the way the flags carry theirs.
  • A test that the document still names every directory of third-party artwork in the tree, so
    it cannot quietly fall out of date the next time something is vendored.

Classification

Documentation. Prerequisite for #106's artwork; useful on its own regardless.

## Observation > make a trademarks #106 decided that a plugin may ship a third party's mark with a notice beside it, unmodified, outside the AGPL grant, claiming no endorsement — and that this is a rule rather than an exception for Europass. The rule needs somewhere to live before the first plugin logo lands. ## It is not hypothetical: there is already an unmarked trademark in the tree ``` assets/support/buy-me-a-coffee.png ``` Added by #79, and it is exactly the thing #106 is about: somebody else's mark, shipped in an AGPL repository, with nothing beside it saying whose it is. Every fork redistributes it. That is almost certainly fine — it is an approved banner, used to link to the account it belongs to, which is what approved banners are for — but the repository does not say so anywhere, and that is the gap this closes. Two more sets of third-party artwork are in the tree and *are* accounted for, differently: | What | Where | Covered by | | --- | --- | --- | | Lucide icons, 40 files | `src/postulo/static/icons/` | ISC, and each file keeps its `@license` comment | | flag-icons, 241 files | `src/postulo/static/flags/` | MIT, notice copied in beside them (#88) | | Buy Me a Coffee banner | `assets/support/` | **nothing** | The first two are copyright licences and are handled. A mark is not licensed at all, which is why it needs a different kind of note rather than a third licence file. ## And Postulo's own name has never been mentioned `assets/brand/postulo.png` and seven derived files under `src/postulo/static/brand/`. The README says the code is AGPL and says nothing about the name or the logo, so a reader has no way to know what a fork may call itself. That matters more here than in most projects, because of what the README promises. **Never paywalled** is a commitment about the project, not about the code — the licence cannot enforce it, and a fork that added a paid tier and kept the name would break the promise for everybody who had heard it. A trademark note is the only instrument that speaks to that, and it is worth having for that reason rather than for control. It is also explicitly permitted by the licence Postulo uses. AGPL-3.0 §7 lists the terms a work may add, and clause (e) is *"Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks"*. So this is not a restriction bolted on to a free licence; it is the licence's own provision. ## What the document says - **The code is AGPL and the name is not.** What that means in practice, in plain terms. - **What anybody may do without asking**: run it, fork it, redistribute it unmodified under the name, say truthfully that something works with Postulo, name a plugin `postulo-something` — which is the ecosystem's own convention and must be explicitly allowed, since eight repositories already use it. - **Name your instance whatever you like.** `site.instance_name()` exists so an operator can, and nothing in a trademark note should read as discouraging it. - **What to do with a materially modified fork**: give it another name, or say plainly that it is a modified version and not endorsed. The Firefox/Iceweasel arrangement, without the argument. - **Third-party marks used here**, named with their owners, and the four conditions from #106. - **No endorsement**, stated once and meant. ## Scope - `TRADEMARKS.md` at the root. - The README's licence section points at it — it currently explains Lucide and flag-icons in a paragraph, and that paragraph is the right size for a licence note and the wrong place for a marks policy. - A notice beside `assets/support/buy-me-a-coffee.png`, the way the flags carry theirs. - A test that the document still names every directory of third-party artwork in the tree, so it cannot quietly fall out of date the next time something is vendored. ## Classification Documentation. Prerequisite for #106's artwork; useful on its own regardless.
tiagoagueda added this to the 0.3.0 milestone 2026-09-07 16:38:16 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Postulo/postulo#107
No description provided.