4 ms·
If you're a big enterprise with lots of open source dependencies, you have to audit your ENTIRE dependency chain to see which of them are MIT licensed, and incl
by idealmedtech 5y ago
If you're a big enterprise with lots of open source dependencies, you have to audit your ENTIRE dependency chain to see which of them are MIT licensed, and include the license text for each one.
It's a pain, so many big shops avoid MIT, and more restrictive licenses like GPL
- BiteCode_dev 5y agoI'd like the OP to answer, because this argument is pretty much usable for most FOSS licences, not specifically MIT. Besides, legally, you should know all the licences of all your dependancies, and pulling that out is usually scripted in big shops. So given the strong aversion demonstrating in the comment, I'm expecting something different.
- gmfawcett 5y agoSo you're happy to build your commercial product upon the free works of hundreds of FOSS developers, but only if you can't be arsed to give them attribution? Cry me a river! An enterprise has a responsibility to manage its licenses. Complaining that it's not fun is just childish.
- idealmedtech 5y agoI think also it becomes an issue where you have to preclude a source file with ~10+ copies of the same license for each dependencies. It's the way you have to satisfy the attribution requirement (eg "must include this text," rather than "must include a link to this text somewhere in the source tree") that presents the issue. It's part of why, as I said in the original comment, lots of big shops do _everything_ in house, even when there's a higher quality open source alternative. They simply don't use projects with attribution requirements that are too strict.