3 ms·
IANAL, but I've been involved in a few acquisitions and when you get to the part about code ownership, the acquiring company will often do a license scan of th
by cddotdotslash 5y ago
IANAL, but I've been involved in a few acquisitions and when you get to the part about code ownership, the acquiring company will often do a license scan of the entire dependencies folder (which includes sub dependencies). So if any of those files show up as GPL, you technically could be in violation.
Now, if a package licensed as MIT includes a dependency on a package licensed as GPL, I don't know if that's a violation by the parent project owner because the parent package doesn't actually distribute the GPL code, but rather includes a reference to it, so that the installer running "npm install" fetches it.
But I would imagine that the end user who is pulling those packages and actually installing all the dependencies would be in violation because the final packaged code used to deliver the service actually contains the GPL code.