but Apache allows redistribution under the same terms? so how this supposed to work?
but Apache allows redistribution under the same terms? so how this supposed to work?
They might as well just say that if you have revenue over $1M they'd appreciate if you gave them money since the license doesn't seem to actually impose any sort of legal obligation to do so.
This is definitely the stupidest license I've heard of. I'm currently in the same situation, thinking about how to open source one of my projects while retaining the ability to make some money somehow, and this is something I never even considered because it's so stupid.
SQLite is public domain, and makes money by selling "licenses" to such companies (they're called something else, but it allows the company buying it to file it in their "licenses" folder and tick a checkbox; https://www.sqlite.org/copyright.html).
In the longer term, I'm guessing this pushes everyone pretty strongly towards SkiaSharp instead.
(doesn't stop mega-corps using it as a cloud service/internally though)
Another option is to do what Duende did. I think Duende (Identity Server) handled the situation pretty well.
https://duendesoftware.com/products/identityserver
> Standard License Pricing > Free for development, testing and personal projects—only pay for production. Try it now! Learn about our free Community Edition.
> Our Community Edition license is feature equivalent to our Enterprise Edition, but only includes standard support.
> Community Edition allows hosting IdentityServer on your own infrastructure (including your cloud). It is not for scenarios where you redistribute IdentityServer, or build software for third parties. In this case you either need a redistribution license, or the end-customer needs a standard license.
> For-profit companies/individuals with less than 1M USD annual gross revenue > Non-profit organization with a published annual budget less than 1M USD > Registered charities
The whole point of being in breach of contract is that you can be sued for it.
"The transitive clause is actually really important, I'll explain why.
I've explicitly called out the following to ensure that the Split License is non viral.
Once granted, You must reference the granted license only in all documentation.
In practical terms this means that If you are granted a license, that's the one you're use, not the Split License which exists to derive the license to be granted to you.
So if you're OSS, you should only be concerned about and reference the Apache 2.0 license - downstream consumers shouldn't need to care.
That, on the surface makes the whole transitive/direct thing seem redundant except for the fact we have to use the Split License in NuGet packages, so if someone is looking up their supply chain then they can reference the transitive clause to determine liability (none).
Can it be exploited. Yes, but as I've said elsewhere. "Evil Corp is gonna evil". They're actually more likely to simply ignore the license."
However, that's irrelevant because they are licensing it to the open source project under the apache license.
Once the open source project has it under the apache license, you can copy it from the open source project under the apache license, because the apache license allows that, and the split license won't apply in the first place.
The linked page even says "Once granted, You must reference the granted license only in all documentation," so if they have the source code in their repository it will literally just say that it's apache licensed with zero mention of the split license by the explicit instructions of the creators of imagesharp.
If they say that's NOT the case, because they are imposing additional restrictions, then they aren't actually licensing it to the open source project under the apache license in the first place.
Otherwise, they realize that this is a massive loophole but are still hoping that companies will just pay up. I think this is what's actually the case (and why the hoped the .net foundation would accept it), but they don't want to come out and say that explicitly because then it would defeat the point.
"Works in Source or Object form are licensed to You under the Apache License, Version 2.0 if ... you are consuming the Work in for use in software licensed under an Open Source or Source Available license."
So at that point the author of said open source project gets to redistribute the source of the library under AL - and only AL defines what further derived works can and cannot do with it.
It does in a court of law. A defendant would likely need to demonstrate good faith that they're using the source code of the project from which they acquired the license to ImageSharp. What matters is a judges interpretation, and intent matters.
If you license your code to anyone under the Apache License, that person is then free to redistribute the code under the terms granted by the Apache License, which is obviously missing this $1,000,000 revenue restriction.
They’re not trying to both have and eat their cake. They chose a license with a known exploit because they think it’ll be best for their users, and they accept the consequences of that. This is (IMO) a good balance to strike, and better than I imagined before reading through the license itself and its rationale. It’s explicitly:
- we want to impose the least burden possible on those least able to bear it
- we think we’ll be more sustainable because in balance those able to bear it are more likely to choose to with this model than the previous one… excepting those who wouldn’t regardless of the terms.
Quite a lot of mutual good and goodwill is the product of norms which are effectively social agreements rather than enforcement protocols and regimes. Will some jerk take advantage of this and eat their cake? Yeah, duh. But it’s better for probably the vast majority of their users than a more onerous license which is viral, and (AFAICT) no worse for anyone but themselves. A one-sided compromise in favor of everyone else.
This situation, not so much. They're making a fully open source version available on purpose.
In the summertime I lock my exterior door(s) when I go to bed, even if I have left the windows open. It’s obviously trivial to enter my home if you’re motivated. I’m aware of the contradiction. Closing and locking the door isn’t impenetrable fortification, but it is a clear expression of my will. Opening the window isn’t an invitation to enter my home, it’s a flaw I’m willing to accept to enjoy cool air after hot summer days. If you come into my home through my window under those circumstances, you’re clearly availing yourself of an obvious loophole in my home security arrangement… but you’re being a jerk nonetheless.
People set expectations all the time in all sorts of flawed ways where their expectations might not be met. This is one of them. I agree with the quote in my previous comment: not even a perfect license with no conceivable loophole will prevent someone from exploiting the obvious loophole that a license is a social agreement with its own limited capacity to enforce. Even if you theoretically have bulletproof legal recourse, you have to have legal resources to get it. There’s no license I can imagine which doesn’t have that loophole.
But yeah so, “jerk” was hardly the point of my comment. But if that’s the nit you want to pick, violating someone’s express permission to their belongings because you understand their intent but you’ve found an exception in how it was expressed… that does mean you’re being a jerk. You’re welcome to disagree however fundamentally, but you know what their intention is in limiting how they share their resources and you know you’re only entitled to it by disregarding that to take what you want.