zxcvbn and Basecoat ship with no notice, and TRADEMARKS.md calls htmx a name Postulo only mentions #279

Closed
opened 2026-09-19 08:40:14 +00:00 by tiagoagueda · 0 comments
Owner

The LICENSE file itself is correct and should not be touched. It is the verbatim AGPL-3.0 text, and the document forbids changing it in its own fourth line — "Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed." The <year> and <name of author> in its appendix are part of the FSF's text, not blanks waiting to be filled in. pyproject.toml:7 declares AGPL-3.0-or-later and README.md:241 agrees with it.

What does not conform is everything around it.

The rule this project already set itself

scripts/sync-flags.mjs:12-14:

The licence travels with the artwork. flag-icons is MIT, which asks that the notice go wherever the files go, so it is copied in beside them rather than only mentioned in the README.

sync-flags.mjs:53 then copies that notice in. sync-vendor.mjs copies none, and the stylesheet build copies none.

Where each shipped third-party work actually stands

Work Where Licence Notice ships? In TRADEMARKS.md?
Lucide icons src/postulo/static/icons/, 43 files ISC yes — every file keeps its <!-- @license lucide-static v1.41.0 - ISC --> first line yes
flag-icons src/postulo/static/flags/ MIT yes — LICENSE.txt beside them yes
Tailwind CSS compiled into src/postulo/static/css/app.css MIT yes — the /*! tailwindcss v4.3.3 | MIT License */ banner on line 1 no — listed as a name only
basecoat-css compiled into the same file, from assets/css/app.css:24-26 MIT no no
@zxcvbn-ts, three bundles src/postulo/static/js/vendor/zxcvbn/, 1.7 MB MIT no no
htmx 2.0.10 src/postulo/static/js/vendor/htmx.min.js, 52 KB 0BSD not required no — listed as a name only

The two in bold are the ones that matter. MIT asks that "the above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software", and neither basecoat-css (© 2025 Ronan Berder) nor @zxcvbn-ts (© 2012–2016 Dan Wheeler and Dropbox, Inc.; © 2021 @zxcvbn-ts) has one anywhere in the tree. The zxcvbn dist bundles carry no banner of their own, and sync-vendor.mjs:41 only strips the source-map pointer; both packages' LICENSE files sit in node_modules and never leave it. Every copy distributed since the code was vendored has gone out that way.

TRADEMARKS.md is also wrong in two places

Its table is headed "In this repository now" and closes with "The first two are copyright licences and are satisfied by carrying their notices." But htmx and Tailwind CSS appear further down under "Named in the documentation and the interface" — the section for "the software it runs on and the services its plugins reach" — when both have code committed in this tree. htmx.min.js is not a name Postulo mentions; it is 52 KB of somebody else's source that Postulo serves to every page.

htmx has no provenance at all

It is not in package.json, not in package-lock.json, and not in sync-vendor.mjs's FILES. It arrived in the first commit (181c5728e, M1) and has not been touched since. The only record that it is 2.0.10 is a version:"2.0.10" string inside the minified bundle. npm run sync:vendor cannot update it and nothing shows when it falls behind — which is a supply-chain question as much as a licensing one.

There is no Copyright (C) 2026 Tiago Agueda in any file: no header, no NOTICE, nowhere. The AGPL's own appendix asks that each file carry "at least the 'copyright' line and a pointer to where the full notice is found". TRADEMARKS.md:3 names the licence but never the holder. package.json has no license field either, where pyproject.toml:7 has one.

What would fix it

A sketch, open to a different shape:

  • sync-vendor.mjs copies each package's notice next to what it vendors, the way sync-flags.mjs:53 does — src/postulo/static/js/vendor/zxcvbn/LICENSE.txt.
  • The Basecoat notice reaches app.css. A /*! basecoat-css v1.0.2 | MIT License */ banner in assets/css/app.css should survive the Tailwind build the way Tailwind's own banner does; confirm that before relying on it.
  • htmx enters package.json at a pinned version and joins FILES in sync-vendor.mjs, with its notice — which also gives a bump a diff worth reading. Whether to move off 2.0.10 at the same time is a separate question.
  • TRADEMARKS.md's table gains basecoat-css, Tailwind CSS and htmx, and those names come out of the prose list below it. Worth deciding while there: a register of copyright licences may not belong in a file about trademarks at all, and could be a THIRD-PARTY.md that TRADEMARKS.md links to.
  • Postulo asserts its copyright somewhere. A NOTICE file, a line in README.md, or per-file headers — per-file is a great deal of churn for little gain, so probably not that.
  • package.json gains "license": "AGPL-3.0-or-later".

Not this issue

#212 already covers the AGPL §13 offer of source to people who reach an instance over the network, down to a POSTULO_SOURCE_URL setting and a footer link. That is the other half of conforming to the licence and it stays there.

Two things outside this repository, noted so they are not lost: postulo-templates has no LICENSE file at all, and postulo-chromium and postulo-firefox carry theirs with CRLF line endings where every other repository uses LF.

Done when

  • Every third-party work committed in this tree either carries its notice beside it or provably needs none, and the sync scripts keep it that way instead of a person remembering.
  • TRADEMARKS.md lists all of them, and nothing whose code is in the tree is described as merely a name.
  • Postulo says who holds its copyright.
The `LICENSE` file itself is correct and should not be touched. It is the verbatim AGPL-3.0 text, and the document forbids changing it in its own fourth line — *"Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed."* The `<year>` and `<name of author>` in its appendix are part of the FSF's text, not blanks waiting to be filled in. `pyproject.toml:7` declares `AGPL-3.0-or-later` and `README.md:241` agrees with it. What does not conform is everything around it. ## The rule this project already set itself `scripts/sync-flags.mjs:12-14`: > The licence travels with the artwork. flag-icons is MIT, which asks that the notice go wherever the files go, so it is copied in beside them rather than only mentioned in the README. `sync-flags.mjs:53` then copies that notice in. `sync-vendor.mjs` copies none, and the stylesheet build copies none. ## Where each shipped third-party work actually stands | Work | Where | Licence | Notice ships? | In `TRADEMARKS.md`? | | --- | --- | --- | --- | --- | | Lucide icons | `src/postulo/static/icons/`, 43 files | ISC | yes — every file keeps its `<!-- @license lucide-static v1.41.0 - ISC -->` first line | yes | | flag-icons | `src/postulo/static/flags/` | MIT | yes — `LICENSE.txt` beside them | yes | | Tailwind CSS | compiled into `src/postulo/static/css/app.css` | MIT | yes — the `/*! tailwindcss v4.3.3 \| MIT License */` banner on line 1 | **no** — listed as a name only | | **basecoat-css** | compiled into the same file, from `assets/css/app.css:24-26` | MIT | **no** | **no** | | **@zxcvbn-ts**, three bundles | `src/postulo/static/js/vendor/zxcvbn/`, 1.7 MB | MIT | **no** | **no** | | htmx 2.0.10 | `src/postulo/static/js/vendor/htmx.min.js`, 52 KB | 0BSD | not required | **no** — listed as a name only | The two in bold are the ones that matter. MIT asks that *"the above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software"*, and neither basecoat-css (© 2025 Ronan Berder) nor @zxcvbn-ts (© 2012–2016 Dan Wheeler and Dropbox, Inc.; © 2021 @zxcvbn-ts) has one anywhere in the tree. The zxcvbn dist bundles carry no banner of their own, and `sync-vendor.mjs:41` only strips the source-map pointer; both packages' `LICENSE` files sit in `node_modules` and never leave it. Every copy distributed since the code was vendored has gone out that way. ## `TRADEMARKS.md` is also wrong in two places Its table is headed *"In this repository now"* and closes with *"The first two are copyright licences and are satisfied by carrying their notices."* But htmx and Tailwind CSS appear further down under *"Named in the documentation and the interface"* — the section for *"the software it runs on and the services its plugins reach"* — when both have code committed in this tree. `htmx.min.js` is not a name Postulo mentions; it is 52 KB of somebody else's source that Postulo serves to every page. ## htmx has no provenance at all It is not in `package.json`, not in `package-lock.json`, and not in `sync-vendor.mjs`'s `FILES`. It arrived in the first commit (`181c5728e`, M1) and has not been touched since. The only record that it is 2.0.10 is a `version:"2.0.10"` string inside the minified bundle. `npm run sync:vendor` cannot update it and nothing shows when it falls behind — which is a supply-chain question as much as a licensing one. ## Postulo never asserts its own copyright There is no `Copyright (C) 2026 Tiago Agueda` in any file: no header, no `NOTICE`, nowhere. The AGPL's own appendix asks that each file carry *"at least the 'copyright' line and a pointer to where the full notice is found"*. `TRADEMARKS.md:3` names the licence but never the holder. `package.json` has no `license` field either, where `pyproject.toml:7` has one. ## What would fix it A sketch, open to a different shape: - `sync-vendor.mjs` copies each package's notice next to what it vendors, the way `sync-flags.mjs:53` does — `src/postulo/static/js/vendor/zxcvbn/LICENSE.txt`. - The Basecoat notice reaches `app.css`. A `/*! basecoat-css v1.0.2 | MIT License */` banner in `assets/css/app.css` should survive the Tailwind build the way Tailwind's own banner does; confirm that before relying on it. - htmx enters `package.json` at a pinned version and joins `FILES` in `sync-vendor.mjs`, with its notice — which also gives a bump a diff worth reading. Whether to move off 2.0.10 at the same time is a separate question. - `TRADEMARKS.md`'s table gains basecoat-css, Tailwind CSS and htmx, and those names come out of the prose list below it. Worth deciding while there: a register of copyright licences may not belong in a file about trademarks at all, and could be a `THIRD-PARTY.md` that `TRADEMARKS.md` links to. - Postulo asserts its copyright somewhere. A `NOTICE` file, a line in `README.md`, or per-file headers — per-file is a great deal of churn for little gain, so probably not that. - `package.json` gains `"license": "AGPL-3.0-or-later"`. ## Not this issue #212 already covers the AGPL §13 offer of source to people who reach an instance over the network, down to a `POSTULO_SOURCE_URL` setting and a footer link. That is the other half of conforming to the licence and it stays there. Two things outside this repository, noted so they are not lost: `postulo-templates` has no `LICENSE` file at all, and `postulo-chromium` and `postulo-firefox` carry theirs with CRLF line endings where every other repository uses LF. ## Done when - Every third-party work committed in this tree either carries its notice beside it or provably needs none, and the sync scripts keep it that way instead of a person remembering. - `TRADEMARKS.md` lists all of them, and nothing whose code is in the tree is described as merely a name. - Postulo says who holds its copyright.
tiagoagueda added this to the 0.4.0 milestone 2026-09-19 08:40:14 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo#279
No description provided.