4 ms·
So if I accept pull requests without asking people to sign a CLA, what kind of ramifications could this have for my project in the future? Also, if the license
by udp 14y ago
So if I accept pull requests without asking people to sign a CLA, what kind of ramifications could this have for my project in the future?
Also, if the license says "Copyright <author> et al." (as many license headers do), does the copyright actually belong to the contributors as well as the author? How is this determined?
- Nursie 14y ago(IANAL) Git isn't my primary source control solution -- edit: corrected in view of useful information below -- If you accept pull requests and pull data into your repo from other folks without a asking them to assign copyright or sign a very open CLA then that means the copyright is now joint. The ramifications of this tend to be that you cannot re-license the code without their permission, unless the original license says you can. Example - your project is GPL, you accept submissions from a bunch of other people. You decide you want to release a closed-source binary-only commercially-supported extra-special version with plugins and hotsauce. You can't unless you get permission from everyone that's contributed to the project, because the rights you have to their submissions are governed by the GPL. With copyright assignment, you as the now sole copyright holder could do this. Ramifications will vary by license and by what you want to do.
- tholmes 14y agoYou have the right idea about pull but you're mixing up pull and pull request. Pull is a git verb that means to get code from another location. A pull request is asking someone else to get my changes. So for an example, if you found a bug in some open source software you used you could make a change in the code that fixed it and then file a pull request with the original author of the software. This asks them to incorporate your changes.
- Nursie 14y agoThanks, wasn't sure on that point! I assumed a pull request was someone asking you/your server if they could pull data from it, not requesting you/your server pull data from elsewhere. Now I know.
- zobzu 14y agothats why the licenses recommend to put the license on top of EVERY SINGLE FILE. Failing to do so, is, well, not a good idea. The pull request will then either contain a join copyright (then only THIS file has a joint copyright), either no change to copyright (explicitly assigning the copyright to you alone) that's if the copyright goes to <your name, email>, not "et al", obviously
- merijnv 14y agoThe writer of a patch is the copyright holder of that patch, as a result you cannot legally distribute your code with the patch applied unless you have a valid license from the patch writer (Because part of the code is copyrighted by the patch writer, who has exclusive rights to distribution and reproduction). If the patch is submitted under the BSD/GPL/MIT license or similar, you are fine. All of those explicitly grant anyone that complies with those licenses to redistribute the patch code (and thus the patched project), with the usual restriction that your license is compatible and that said copyright notice and author names must be reproduced in the resulting entity. Normally you'd maintain an AUTHORS/CONTRIBUTORS files listing everyone's name in addition to the license files. There's no real hard and fast rule for this, though. Keeping the names in the contributed files would also work, for example. The situation is somewhat murky if the patch writer specifies no license. In this case you are technically not allowed to redistribute the patched code. If the codebase is on github and licensed under some open source license you could (try to) argue in court that that implies the patch is submitted under the same license as the original code, but whether that defense works is up to the judge.