5 ms·
Could you elaborate on what you mean by this? Were you wanting people to be able to publish proofs that they've reviewed the legal standing of the code as well
by mindB 8y ago
Could you elaborate on what you mean by this? Were you wanting people to be able to publish proofs that they've reviewed the legal standing of the code as well as the code itself for problems?
- fiddlerwoaroof 8y agoIt would be useful to know if the MIT library you’re depending on pulls in a AGPL transitive dependency.
- mindB 8y agoI don't see how a cryptographic WoT system is necessary for that kind of concern. That sounds like more tooling needed around the language's basic packaging system.
- alexchamberlain 8y agoYeah. For example, the original author could declare they own the copyright on xyz release and its released under a certain licence
- wyldfire 8y agoThat's stipulated by the crate metadata and the only authority of that claim is the author's, right? Why would you want/need bolstering of that claim by a web-of-trust? What would it mean if the WoT identified a different copyright owner than the author or a different license from the one the author offers?