zxcvbn and Basecoat ship with no notice, and TRADEMARKS.md calls htmx a name Postulo only mentions #279
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#279
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The
LICENSEfile itself is correct and should not be touched. It is the verbatim AGPL-3.0 text, and the document forbids changing it in its own fourth line — "Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed." The<year>and<name of author>in its appendix are part of the FSF's text, not blanks waiting to be filled in.pyproject.toml:7declaresAGPL-3.0-or-laterandREADME.md:241agrees with it.What does not conform is everything around it.
The rule this project already set itself
scripts/sync-flags.mjs:12-14:sync-flags.mjs:53then copies that notice in.sync-vendor.mjscopies none, and the stylesheet build copies none.Where each shipped third-party work actually stands
TRADEMARKS.md?src/postulo/static/icons/, 43 files<!-- @license lucide-static v1.41.0 - ISC -->first linesrc/postulo/static/flags/LICENSE.txtbeside themsrc/postulo/static/css/app.css/*! tailwindcss v4.3.3 | MIT License */banner on line 1assets/css/app.css:24-26src/postulo/static/js/vendor/zxcvbn/, 1.7 MBsrc/postulo/static/js/vendor/htmx.min.js, 52 KBThe two in bold are the ones that matter. MIT asks that "the above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software", and neither basecoat-css (© 2025 Ronan Berder) nor @zxcvbn-ts (© 2012–2016 Dan Wheeler and Dropbox, Inc.; © 2021 @zxcvbn-ts) has one anywhere in the tree. The zxcvbn dist bundles carry no banner of their own, and
sync-vendor.mjs:41only strips the source-map pointer; both packages'LICENSEfiles sit innode_modulesand never leave it. Every copy distributed since the code was vendored has gone out that way.TRADEMARKS.mdis also wrong in two placesIts table is headed "In this repository now" and closes with "The first two are copyright licences and are satisfied by carrying their notices." But htmx and Tailwind CSS appear further down under "Named in the documentation and the interface" — the section for "the software it runs on and the services its plugins reach" — when both have code committed in this tree.
htmx.min.jsis not a name Postulo mentions; it is 52 KB of somebody else's source that Postulo serves to every page.htmx has no provenance at all
It is not in
package.json, not inpackage-lock.json, and not insync-vendor.mjs'sFILES. It arrived in the first commit (181c5728e, M1) and has not been touched since. The only record that it is 2.0.10 is aversion:"2.0.10"string inside the minified bundle.npm run sync:vendorcannot update it and nothing shows when it falls behind — which is a supply-chain question as much as a licensing one.Postulo never asserts its own copyright
There is no
Copyright (C) 2026 Tiago Aguedain any file: no header, noNOTICE, nowhere. The AGPL's own appendix asks that each file carry "at least the 'copyright' line and a pointer to where the full notice is found".TRADEMARKS.md:3names the licence but never the holder.package.jsonhas nolicensefield either, wherepyproject.toml:7has one.What would fix it
A sketch, open to a different shape:
sync-vendor.mjscopies each package's notice next to what it vendors, the waysync-flags.mjs:53does —src/postulo/static/js/vendor/zxcvbn/LICENSE.txt.app.css. A/*! basecoat-css v1.0.2 | MIT License */banner inassets/css/app.cssshould survive the Tailwind build the way Tailwind's own banner does; confirm that before relying on it.package.jsonat a pinned version and joinsFILESinsync-vendor.mjs, with its notice — which also gives a bump a diff worth reading. Whether to move off 2.0.10 at the same time is a separate question.TRADEMARKS.md's table gains basecoat-css, Tailwind CSS and htmx, and those names come out of the prose list below it. Worth deciding while there: a register of copyright licences may not belong in a file about trademarks at all, and could be aTHIRD-PARTY.mdthatTRADEMARKS.mdlinks to.NOTICEfile, a line inREADME.md, or per-file headers — per-file is a great deal of churn for little gain, so probably not that.package.jsongains"license": "AGPL-3.0-or-later".Not this issue
#212 already covers the AGPL §13 offer of source to people who reach an instance over the network, down to a
POSTULO_SOURCE_URLsetting and a footer link. That is the other half of conforming to the licence and it stays there.Two things outside this repository, noted so they are not lost:
postulo-templateshas noLICENSEfile at all, andpostulo-chromiumandpostulo-firefoxcarry theirs with CRLF line endings where every other repository uses LF.Done when
TRADEMARKS.mdlists all of them, and nothing whose code is in the tree is described as merely a name.