“This project violates the MIT license of Gemstash”
github.com
github.com
I can find parts that depend on the gemstash project being installed, but nothing that appears to actually have been taken from the gemstash project .
I'd someone here sees some, i'd really appreciate letting us know (here, or email me at dannyb@google) so we can go fix it.
https://github.com/GoogleCloudPlatform/google-cloud-gemserve... https://github.com/bundler/gemstash/blob/master/.gitignore
I hope Google can afford a good lawyer!
https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
[1]: https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
Is the allegation that it was forked and then more than half of gemstash deleted? Seriously, read the code, even the gem architecture is different. "I found some gemstash code which btw is MIT and can be embedded all day long" does not deserve lawyer threats, and I say that disliking Google.
More embarrassed for the issue author here, who went straight for an outrage jugular without understanding the entire situation, and probably submitted this thread to HN too.
Hi Andre, I'm Max from Google's open source office.
Thanks for bringing this to our attention. We've stared at both repos, and we're having trouble finding any actual copy/pasted code between them.
We don't strip license headers or change code licenses intentionally. We always aim to respect open source licenses. If we made a mistake here, please help us fix it.
It looks like GoogleCloudPlatform/google-cloud-gemserver depends on gemstash existing, but we can't find any copied code. It doesn't appear to be a fork.
We'd really appreciate it if you could give us pointers to the code you think was copied from your project, so we can fix it.
There's no distinction between source and binary code.
We've all made mistakes, most of us were just fortunate enough that it didn't end up as the top link in Hacker News.
I would have thought Google would have been far more cautious.
https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
If there is a lack of caution I think it's on @indirect's side.
Giving constructive feedback / discussion that may lead to GCP supporting the OP's project may be a better way than going directly to "I'm going to get my lawyers involved".
From the current discussion it also looks like some people don't even agree that this repo steals from the OP.
> As I'm sure you're aware, the MIT license [...] does not allow you to change the license.
This demonstrates a poor understanding of licensing. The MIT license is a permissive license, not a reciprocal ("viral") one. I.e., you're free to incorporate it into other projects even when those projects themselves are not licensed as MIT.
This wouldn't look so silly if it weren't the case that:
1. The MIT license text's brevity is very to-the-point
2. It goes further than similar licenses (e.g., ISC, BSD) and explicitly names sublicensing when enumerating its (inexhaustive) list of permissable uses
3. The other software project in question is licensed under Apache License version 2.0, which is more or less functionally equivalent to MIT, modulo some patent termination stuff.
EDIT to everyone commenting about "relicensed MIT files", and "changing the license": Stop that.
If you mean that it's required to reproduce the text of the license and the copyright notice somewhere in the end result (a la Firefox's about:license), then say that. This conversation would go a lot smoother that way instead of you endlessly repeating about a "license change". Say what you mean.
It doesn't; while the MIT is a permissive license, that doesn't mean that it lets you change the license.
> you're free to incorporate it into other projects even when those projects themselves are not licensed as MIT.
This is true, but you still have to follow its terms, just like any other license.
(I have not actually looked at the repo or investigated the details in this specific case.)
The original project is licensed under MIT. The Google project said to incorporate that code is licensed under Apache 2.0. This is permitted by the terms of the MIT license.
If there is any wrongdoing here, it looks like a failure to `git add ./NOTICES.txt`, and that's as simple as the remedy to it would be, too.
You can have MIT-licensed files in an Apache-licensed project, you can not strip out their original licenses and put yours instead.
You cannot take code licensed under MIT, delete the MIT license, and supply a different license instead.
> This is permitted by the terms of the MIT license.
It is permitted to include MIT licensed code in a project that also contains Apache licensed code, but it is not permitted to change the MIT licensed code to be Apache licensed.
The result is a project where different code has different licensing.
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
That is, you cannot remove the copyright notice nor the text of the MIT license.
(Yes, this is a very easy thing to fix.)
Quoting from the license: > The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
So if this was a fork, the MIT license was violated.
Sure but you are not allowed to relicense it nilly willy, only the copyright holder can do that (which incidentally is part of the reason for the copyright assignment of the FSF of big projects).
If this truely was an intern who did this, "you refuse to support" and "you depend on the work it does" are kind of stretches.
Obviously stripping the crediting and copyright details is an incredibly poor decision, but not like this intern has any part of Google's decision to support Ruby Together or not.
Sure, the intern is not personally morally culpable, but they were told what project to work on by a manager, no? And any open-source release was approved by a fairly sizable Google committee that is deeply aware of what open-source projects Google depends on and which ones they choose to support, isn't it?
If this were on the intern's personal GitHub account on their own time (and Google were so kind as to allow the intern to do work on their own time and retain copyright), this would be a totally different matter, yes.
But I've managed someone who took code from the internet (multiple files, a whole sub-project, really) and tried to pass it off as their own. I pointed out they left the license info at the top of the files, and so it was pretty easy to tell it violated the license terms. I got push-back about it, saying they just wanted to deliver the feature (the code didn't do that, but whatever). I said I was glad the code didn't get deployed, and said we could work on requirements so a clean room implementation could be done. So far, yes, teachable.
Then he committed the same code with the license information removed.
Then I fired him.
There's simply no other way to handle these situations. It's unprofessional in the extreme to plagiarize, and is a lawsuit magnet to boot.
It also doesn't seem clear that the code was forked at all, making this whole exercise pointless.
"Hi Andre, I'm Max from Google's open source office.
Thanks for bringing this to our attention. We've stared at both repos, and we're having trouble finding any actual copy/pasted code between them.
We don't strip license headers or change code licenses intentionally. We always aim to respect open source licenses. If we made a mistake here, please help us fix it.
It looks like GoogleCloudPlatform/google-cloud-gemserver depends on gemstash existing, but we can't find any copied code. It doesn't appear to be a fork.
We'd really appreciate it if you could give us pointers to the code you think was copied from your project, so we can fix it."
Whoever used a throwaway account to get this onto the front page of HN, less than an hour after that issue was posted on GitHub: that was an irresponsible and wrong thing to do.
Edit >> Adding References (Excuse my formatting.)
gemstash.rb
* https://github.com/bundler/gemstash/blob/master/lib/gemstash...
* https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
version.rb
* https://github.com/bundler/gemstash/blob/master/lib/gemstash...
* https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
setup
* https://github.com/bundler/gemstash/blob/master/bin/setup
* https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
Just a few examples of similarities. The file location is identical as well.
https://github.com/bundler/bundler/blob/master/lib/bundler/t...
I'm not familiar with ruby, but what if it's just how ruby projects are set up usually?
The version file content, and the file structure might just be both taken from a tutorial on how to create a basic ruby package?
This happens for other languages, a lot of CMakeLists.txt files looks very similar for instance, including the exact location of version files and whatnot if people follow tutorials like [1]
Yep. I feel sorry for the dude.
Hoping the intern learns lots, and that he isn't raked over the coals.
But removing a copyright where condition #1 is a single sentence that tells you not to remove the copyright? And replacing it with a different license? That certainly isn't ignorance.
https://github.com/GoogleCloudPlatform/google-cloud-gemserve...
If it actually turns out that the intern did't violate the MIT license after all (as some seem to suggest), he should retain an attorney for having his reputation smeared.
A bit emotional, aren't we? If the intern did wrong, you already have the high ground without arguments like this.
It may not be a license violation, but "Google Cloud Gemserver", if it is functionally similar to Gemstash's own functionality, sounds like a rebranding, which... feels uncomfortable?
In other words, does the law make a distinction between a git repo and a website like GitHub?
according to the complaint he removed the existing licenses and replaced them with apache. That sounds kinda sneaky
That can't be the whole of it, though, right? Because the MIT license allows relicensing. For example, I can redistribute an MIT-licensed project as part of a GPL-licensed one, although I do still have to include the original MIT license as part of the project, even if the whole project is redistributed under different terms.
It's not really the right way to handle a relicensing, but to be quite honest, it's easy to make minor technical mistakes with free software licensing even if you're acting in good faith and trying to do something that is ultimately permitted by the license
Heck, even the term "MIT license" is technically not recommended by the FSF, as it's ambiguous (they recommend the unambiguous and equivalent term "X11 license")