The MIT License, Line by Line
writing.kemitchell.com
writing.kemitchell.com
The JavaScript and npm ecosystem are extremely dependency-heavy. Even if you only take a few yourself, the number of sub-dependencies of even a simple application are often in the hundreds.
Why does "everyone" ignore the attribution of their dependencies and sub-dependencies? Laziness? Risk of getting sued too low? What happens if Oracle buys all the left-pads in the world?
If you are using some js library with the MIT license in your frontend then you are distributing a copy of the software. You have to include the notice somewhere on your website (typically next to the library)
However, the license doesn't have to appear on the website portion specifically highlighted for human viewing. It merely needs to exist, say, at the top of every javascript file.
Or a link to where the text form of the license is.
Just because it's inconvenient, and just because people are ignoring it, doesn't mean it's being done as it should be...
Of course javascript optimizers and the like might throw a wrench in the works these days, but that's a pretty recent and specific problem.
Which is a real head scratcher, because as a rule, JavaScript developers use JavaScript package managers, and JavaScript package managers, especially npm, provide good license metadata and auditability. You can have an automated tool, usually a plugin for your front-end bundler, compile a pretty good notice file for you, no many how many direct and transitive dependencies you have.
I think there's also a chicken-and-egg problem, in that it's not exactly clear how to make the notices file for front-end code available. Link from website footer? At the top of the client bundle? Comment at the top of the client bundle, with a URL for the notices files?
> Q16: Is "minified" JavaScript Source Code?
> No. Minified JavaScript, while not an "executable" in the software engineering sense of the word, is difficult for humans to read, edit, and modify. As such, it is not "the preferred form for modification" and so it is not Source Code as defined by the license. Therefore, minified JavaScript is the Executable form, and the responsibilities set out in the license for distribution of the Executable form should be met when you distribute minified MPL-licensed JavaScript.
> This means, among other things, that you do not need to, and probably should not preserve the MPL boilerplate (which begins "This Source Code Form...") when minifying JavaScript. However, you do need to comply with section 3.2(a) by informing the recipients of the minified source how they can obtain a copy of the source code. How exactly you do this will depend on how they can obtain that copy, but one way would be to include a comment with a link to the source code in either the page which uses the JavaScript or in the JavaScript file itself.
> Note that treating minified JavaScript as an executable increases distributor flexibility by allowing MPL-licensed code to be combined into a single file with non-MPL JavaScript source code without requiring the non-MPL code to be distributed under the terms of the MPL.
I think the tl;dr is that this is feasible but not common, and there's no single widely-used default way of doing it.
E.g. Many packages put their copyright/license info in special inline comments (using /! ... / tags), and every minifier I've used keeps such tags by default. But including these tags in your bundles can be undesirable - if a dependency has: /! Copyright foo@bar / without specifying the package name, then your bundle will appear to be entirely (c) that author.
OTOH the huge majority of projects do include a valid license identifier in a package.json tag (since npm complains if you don't). But I don't think there's any widely-used default way of generating a good licenses declaration from them.
Does the phrase ''this permission notice'' cover the following disclaimer?
Also, what is the shortest possible license that is functionally equivalent to the MIT license?
The shortest ''license'' I've ever seen is this: https://git.suckless.org/dmenu/file/arg.h.html
/*
* Copy me if you can.
* by 20h
*/
Is this really a license? What about the SQLite blessing?The phrase "this permission notice" also cover the "NO WARRANTY" disclaimer for the software because you will have to include the license if you use it in another software but you can provide warranty under a close source license or your license states you will provide warranties. The "copyright notice" and "this permission notice" means the license.
The shortest possible license that is functionally equivalent to the MIT license is the ISC license, it was created to remove language that is not needed. Read the Wikipedia article here https://en.wikipedia.org/wiki/ISC_license. I do not know other licenses than this.
Technically it is a license but do not use it and it is just probably a joke. The SQL Blessing is technically probably a Public Domain waver.
This is not legal advice and I am not a lawyer.
- I don't know of anything in the Berne Convention or Title 17, U.S. Code, that would require the phrase "with or without fee" so I remove it.
- I use "work" instead of "software." There's no reason to be over-specific.
- I treat the entire text as one notice, rather than specifying each paragraph separately.
Copyright (c) 2021, MyOrganization
THIS WORK IS PROVIDED "AS IS," WITH NO EXPRESS OR IMPLIED WARRANTIES. THERE
IS NO WARRANTY OF MERCHANTABILITY, FITNESS, NON-INFRINGEMENT, OR TITLE.
NO AUTHOR SHALL BE LIABLE FOR ANY DAMAGES RELATING TO USE OF THIS WORK.
Permission to use, copy, modify, and/or distribute this work for any purpose
is hereby granted, provided this notice appears in all copies.A derivative isn't generally a copy. Which is one of the weaknesses of the ISC license that doesn't appear in either the N-Clause BSD licenses or the MIT license.
Because of the poor wording, permission is granted, but the notice is only required on things considered to be copies, rather than all the "children" of the original work.
You really want something like:
> The above copyright notice and this permission notice shall be included in all copies or substantial portions of the work.
See Ford Motor Co. v. Summit Motor Products, Inc., 930 F.2d 277, 291 (3d Cir. 1991), cert. denied 502 U.S. 939 (1991); Madrid v. Chronicle Books, Pixar, 209 F. Supp. 2d 1227, 1237 n. 5 (D. Wyo. 2002); Micro Consulting, Inc. v. Zubeldia, 813 F. Supp. 1514, 1531 (W.D.Okla. 1990)("a derivative work does not [implicate the underlying copyright] unless it has been substantially copied from the preexisting work" (emphasis added)).
This is because when it comes to copyright law there _is_ such a thing as something being too insubstantial to be considered copyright infringement. "de minimis" falls under fair use.
> You seem to be claiming that modified copies and partial copies are not copies for the purpose of copyright law.
Lets break it down a little bit more clearly:
> Permission to use, copy, modify, and/or distribute this work for any purpose is hereby granted, provided this notice appears in all copies.
+ You are granted the permission to modify.
+ You must provide the notice in all copies.
If a work is substantially modified from the original, such that it constitutes a new work, it would no longer be considered a copy of the original, which is why you are now granted copyright on the new work at all:
> "Unless sufficient of the pre-existing work is contained in the later work so as to constitute the latter an infringement of the former, the latter by definition is not a derivative work." 2 Nimmer on Copyright § 8.09[A], p. 8-138 (2004); see Litchfield v.Spielberg
If you arrive at this point, where you are no longer a derivative because of the substantial divergence from the original work, it may no longer be considered a copy under copyright law.
For a random example from software, the source code for "alpine" the mail client, and "nano" the text editor have an undisputed shared origin, but arguing that they share substantial similarities today would actually be a difficult case to present.
The permission to modify has allowed you to create this new work, but you are no longer required to show the notice, because what you have is no longer a copy.
Whereas the wording in license such as the 3-Clause BSD license:
> 1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
Do not allow you to differentiate between a new work and a copy, and close shut that particular escape hatch.
And if it is "no longer a derivative because of the substantial divergence from the original work" -- the situation where you have a problem with the ISC language -- then what right under 17 U.S.C. § 106 is implicated?
You can't have it both ways. Under situations involving copies of my work, the ISC license works fine. Under situations not involving copies of any my work within the meaning of copyright law, then copyright law has no applicability.
It's a stupid lawyer thing. A lot of us still write like this. I'm sorry.
> Does the phrase ''this permission notice'' cover the following disclaimer?
Arguable, but why would anyone bother chopping off the disclaimer?
> Also, what is the shortest possible license that is functionally equivalent to the MIT license?
Form and function aren't so neatly separated in natural language.
> Is this really a license?
It's a cute suckless thing. They're edgy like that, among other ways.
> What about the SQLite blessing?
SQLite holds their work out as in the public domain. But you can buy a license (and some commercial guarantees) to make your company's lawyers happy: https://sqlite.org/purchase/license
Last question, how much change in the software allowes me to add my name and where to add it, before or after original author(s)?
Not super helpful
It's called "A Practical Guide to WordPress and the GPL" and I must admit, it's easy to understand.
So, all goods have an implied warranty requiring they must be of at least average quality? How does that work? Does average have a different meeting in a legal context?
You call me up and I say "I never said it would work in a car, I just said it was an oil filter (true) which would fit into a 2019 Mazda (true)."
The law says "nice try, you can't be that pedantic. The ordinary purpose of oil filters it to actually filter oil in a car, so when you sold it, there was an understanding that it would work for that purpose."
ultimately, a judge.
Many legal systems, especially the American one, aren’t based on strict enumerable lists of what my lawyer friends would call “bright line tests”.
This is probably a good thing, all in all.
The law therefore specifies things in general terms and uses 'reasonableness', or "fitness for purpose", or what would be expected by an "average bystander" (in English law), etc. in the same way this piece of legislation does.
This allows courts and juries to then make a judgement on the infinite number of particular cases that get before them.
Also, check out my new cryptocurrency that skirts all SEC laws. http://orangegrovecoin.com
Vanishingly few if any contain 11 or fewer yolks.
this is the pedantic part. Normal usage of average means "pretty much what I expected", which is what they are trying to convey, imo.
In any case, "average" does not mean "arithmetic mean." It means, mathematically, any of the median, mode, or mean or in standard vernacular, of typical or usual characteristics (i.e., close to mode).
You don't get to just arbitrarily pick a definition that fits your viewpoint and start going "all due respect" on other people.
In this case we're not in a mathematical context though.
Ludicrously pedantic nitpick: this only applies to finite sets - consider the sequence 1,1/2,1/3,1/4,... (the harmonic series). The average (mean, median, mode[0]) is (depending on how pedantic you want to be) either 0 or 0+ε[1], but in any case strictly less than any positive real number, while every element of the sequence is a positive real number.
So it's not true by definition; it's a consequence of the basic sanity constraints that you're working with.
0: Strictly speaking mode only applies to continuous ditributions (ie, with a continuous probability density function) or fully discrete distibutions (eg heads vs tails), but 0 is the only (real number) x such that for any sufficiently small positive distance δ, the number of elements in x±δ is strictly greater than the number in x±2δ but not in x±δ (namely, all but a finite number of the inifitely many elements in x±2δ are also in x±δ).
1: Where ε is some surreal number[2] strictly less than any positive real number, but not necessarily 1/ω specifically.
When is that not the case? I'll grant you that not all distributions are "normal" distributions, so when is it not the case that 40 percent are not below average?
(2) Goods to be merchantable must be at least such as: (a) Pass without objection in the trade under the contract description; and (b) In the case of fungible goods, are of fair average quality within the description; and (c) Are fit for the ordinary purposes for which such goods are used; and (d) Run, within the variations permitted by the agreement, of even kind, quality and quantity within each unit and among all units involved; and (e) Are adequately contained, packaged and labeled as the agreement may require; and (f) Conform to the promises or affirmations of fact made on the container or label if any.
Here is what the official comments to the UCC say:
Paragraphs (a) and (b) of subsection (2) are to be read together. Both refer, as indicated above, to the standards of that line of the trade which fits the transaction and the seller's business. “Fair average” is a term directly appropriate to agricultural bulk products and means goods centering around the middle belt of quality, not the least or the worst that can be understood in the particular trade by the designation, but such as can pass “without objection.” Of course a fair percentage of the least is permissible but the goods are not “fair average” if they are all of the least or worst quality possible under the description. In cases of doubt as to what quality is intended, the price at which a merchant closes a contract is an excellent index of the nature and scope of his obligation under the present section.
So if you understand (a) and (b) in unison, it means that you can't sell someone a lot of goods but then send them all below-average quality units. But, of course, a truck load of apples can still have a "fair percentage" of low-quality apples. Where you're selling a single item, like a computer, then (a) is the better lens of looking at it.
None of this is legal advice. I'm not your lawyer.
These are all default rules, like most of contract law. A particular contract can by its express terms lay down a different rule, such as disclaiming any warranty (as-is) or specifying its own terms of warranty (an express warranty).
[1] What you described is just a straight-up breach of contract, even in the absence of a warranty. If you order USDA Choice meat, a shipment of USDA Select meat is such a breach of contract. In agriculture, and especially outside of meat, some of a shipment will always fall outside of the quality range. This is dealt with in the grading definition. So when you buy USDA Grade AA eggs, that actually means that at least 72% of the eggs are AA, and of the remaining, 10% are at least A and the balance can be B (basically... see https://www.ams.usda.gov/grades-standards/shell-egg-grades-a... ).
What’s the reasoning behind asking users to carry around a notice? Why not just let users go without it? Is it for legal reasons or for crediting the authors? I’ve released MIT licensed software before and frankly when someone is using my code, I really don’t care about credit or leaving behind a legacy or such things.
I think, as others have pointed out in the replies, 0BSD or MIT-0 is more suitable for me.
Why not go with [CC0] in that case? It's a lot more robust, and recommended by the FSF over options like the Unlicense.
Is there an alternative you'd recommend?
That may prove to be a distinction without a difference if it's ever tested in court, but "giving up copyright" is scary to management so it's meaningful in practice.
A lot of this is mostly theoretical legal stuff but lawyers worry about that sort of thing with the result that a lot of companies won't touch public domain software even if they know its provenance.
> This work is placed in the public domain.
> In regions where this is not possible, the author grants unlimited license to this work.
Unfortunately, the CC0 explicitly does not waive patent rights, the Unlicense doesn't mention patents at all, the Blue Oak Model License and Apache 2.0 don't attempt to place the work into the public domain, and 0BSD and MIT-0 neither address patents nor attempt to place the work into the public domain. None of these licenses aggressively waive all of the author's rights to their work; I wonder why there isn't a strong public-domain no-patents-or-anything-else license ?
But it really ought to be drafted by professionals, and vetted by the wider community. None of this amateurish "crayon license" foolishness.
Creative Commons probably isn't interested. Their patent language was surely deliberate.
Then use a different license. In 1-clause BSD and Boost licenses the requirement of preserving copyright notices applies only to source code, while 0BSD and CC0 don't require that at all.
DO WHAT THE FUCK YOU WANT TO PUBLIC LICENSE
Version 2, December 2004
Copyright (C) 2004 Your Name <name@example.com>
Everyone is permitted to copy and distribute verbatim or modified
copies of this license document, and changing it is allowed as long
as the name is changed.
DO WHAT THE FUCK YOU WANT TO PUBLIC LICENSE
TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION
0. You just DO WHAT THE FUCK YOU WANT TO.> gets me out of any legal responsibility/liability
The license you posted doesn't disclaim any warranties or liabilities. I suggest reading what TFA's "Warranty Disclaimer" section says about UCC defaults. The way I read it (IANAL), you would have more liability with the license you posted than you would under the MIT license.
That's why contracts like proprietary licenses, buying a house, renting are so verbose.
"do wtf you want" is very unclear from a legal PoV.
And then I found [1]:
> CC0 was not explicitly rejected, but the License Review Committee was unable to reach consensus that it should be approved, and Creative Commons eventually withdrew the application. The most serious of the concerns raised had to do with the effects of clause 4(a), which reads: "No ... patent rights held by Affirmer are waived, abandoned, surrendered, licensed or otherwise affected by this document.". While many open source licenses simply do not mention patents, it is exceedingly rare for open source licenses to explicitly disclaim any conveyance of patent rights, and the Committee felt that approving such a license would set a dangerous precedent, and possibly even weaken patent infringement defenses available to users of software released under CC0.
For the record, the FSF also recommends against using CC0 for software for the exact same reason [2].
I was surprised because my first impression was that this clause does not legally do anything more, anything less than a license that does not explicitly grants the rights to use the related software patents anyway. But I can imagine that without an explicit mention, a judge could still decide that a user receiving a program could reasonably feel allowed to use the related patents from its authors.
Anyway, CC0 should not be used or software indeed I guess, given the vagueness around it.
Yes, many lawyers believe in implicit patent license: http://en.swpat.org/wiki/Implicit_patent_licence
In commercial desktop software I have shipped, it has been a section in help>about with a long list of third party libs each showing a text document.
It is possible and quite easy, if you plan ahead. Notably, Debian binary packages include extensive copyright information.
For anything distributed as source it’s easy enough.
Additionally, the Berne Convention recognizes a "moral right" to claim authorship.
The combination of the copyright and permission notice says
"This is mine AND you can do these things with it if you want."
Claiming ownership by itself does not result in it being open source.
Saying you're giving permissions, but without claiming the right to be able to do so, also does not result in it being open source.
It was typical for software to be distributed in physical media (floppy disks, and, later, CD-ROMs) through brick-and-mortar retail stores. It was not uncommon for someone to sell physical media with otherwise-free software, and so it was desirable to make end-users aware that the software was available for free. The GPL's "accompany it with a written offer... of the corresponding source code" is also an interesting holdover from this era (nowadays everyone just distributes source over the Internet, instead of sending checks and CDs through the mail).
Copyright notices were also typically visible when you first started a program in the 80s and 90s. These were relegated to "about" menus when it became the norm to "design a launch screen that’s nearly identical to the first screen of your app" to make apps feel faster.
This is a minor nitpick and shouldn't be read as an overall criticism of the author or this post, which is better than the one I did. However, I will note that non-infringement and title are, in fact, implied warranties in the UCC. I'm not sure why the author missed it.
The implied warranty of noninfringement can be disclaimed under § 2-316, and vendors almost universally do so (preferring to make specific express warranties instead when they perceive a market need).
The UCC nerds are out in force this round!
I think this is a very carefully couched way of saying "the MIT license doesn't protect the licensee from being sued by the licensor for patent violation." If person A has a patent on algorithm X, and he wrote open source code which implements X, and he licenses this code to person B under the MIT (or BSD) license, and B uses the code, it's feasible for A to sue B for patent violation.
For this reason alone, I think MIT and BSD are awful, archaic licenses that should be avoided at all costs. The Apache 2.0 license is a great substitute.
I'm with you on this, though. It doesn't have to be broke. We can fix it.
Blue Oak Council, a nonprofit I'm a part of, published a tier-ranked list of permissive licenses. All of those at the top handle patent explicitly: https://blueoakcouncil.org/list
We also published a model permissive license, which comes with a very explicit, very broad patent grant: https://blueoakcouncil.org/license/1.0.0
Turns out I'm still a tyro.
† From Wikipedia, WIPO non-members: Kosovo, Federated States of Micronesia, Palau, South Sudan, and the states with limited recognition. Palestine has observer status.
> United States law calculates copyright terms differently for individual and “corporate” authors.
make me wonder what it is like in, say, France or Germany.
One can sell or give permission the right to publish, duplicate, whatever (Verwertungsrecht).
Writing a book on company time and money automatically awards the company the rights to publish, make money, etc.
Writing a book in you spare time with "work related knowledge" might award the company with a claim for buying (at fair value) the publishing rights.
If you write a bestseller on company time you might also be entitled to a compensation in addition to your payrole. (But always best to have a contract beforehand)
But on the whole Germany is in the Berne convention.
Except there really isn't any agreement on some of the finer details of the license, no matter how much you want to study and understand it. Does the license text have to be included in only the source code or the compiled software? What if the source code of the derived software isn't made public? What is "substantial portions" of the software? Can a MIT project be relicensed? What is the point of any of these clauses then?
While it is a great license, I wish something closer to just public domain would have become the OSS default, since that is what 99% of developers want anyways.
It's not everything anyone ever wanted, but we think it's a lot closer.
If you are serious about adoption, I suggest providing an official header to embed in files. Something simple like this:
// Licensed under https://blueoakcouncil.org/license/1.0.0
Also "instructions on how to use this license in your software project" would be helpful. (Paste the text of the license into a file named "LICENSE", "LICENSE.md", or similar. Add the header as a comment to every file...)We've shied away from declaring one "right" way to use the license, because norms, conventions, and expectations vary so much across development communities. What's right and normal for, say, Maven artifacts would seem a bit strange in, say, an npm package or a C library.
Personally, I don't care what OSI says. If someone else wants to go and ask them about it, more power to them.
Among more sophisticated users I don't think there's disagreement on this point. The answer is "no", if by "relicense" you mean "remove the MIT license and put in something else". You can never legitimately remove the MIT license from a file unless you're the copyright holder or their authorized agent.
Where there's less than total agreement is whether the MIT license may be subsumed by another license — e.g. the Apache License 2.0 — when an MIT licensed work is bundled within a package. Can you claim that the complete package is available "under the Apache License 2.0", omitting the fact that the licenses are actually polyglot?
The answer to that question seems to be "everybody does that" and "in practice, the legal risk seems to approach zero", but in theory should two licenses ever prove to have incompatible provisions then things could get sticky in a court case.
Assuming the example is the original work of the author of the post (and again, assuming no other terms), then that post author would hold copyright to the work. You would have no license to copy or distribute it.
I have great confidence that SO's terms include a section wherein contributors grant license or grant copyright to SO. At that point (again, assuming no other terms), you would still have no right or license to copy or distribute the work.
Assuming SO has a very permissive license to the work, including the ability to re-license it, they can grant you a license to copy or distribute the work. At that point you are bound by the terms of the license SO grants you.
Read the terms to get specifics.
Thanks to the 197? Law that provided automatic copyright the instant anyone says or does anything copyrightable.
I'm sure SO TOS states by using this site you assign or grant copyrights to SO. Same as HN and any site otherwise they'd be liable for reproducing what I wrote in this comment which in USA is automatically copyrighted to me the moment I hit "reply".
https://writing.kemitchell.com/2019/03/09/Deprecation-Notice...
I am glad to see an actual IP lawyer's view on this thing.