diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5f92172..cbce133 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -148,10 +148,10 @@ jobs: type=sha,format=short # The action derives the licences label from this repository's # Apache-2.0, and its labels override the Dockerfile's. The image also - # bundles the transpiler, whose LICENSE is PolyForm Noncommercial - # 1.0.0 as modified by its own sections (see README, License). + # bundles the transpiler, whose LICENSE from codegen 1.2.0 is the + # PineForge Source License 1.1 (see README, License). labels: | - org.opencontainers.image.licenses=Apache-2.0 AND LicenseRef-PolyForm-Noncommercial-1.0.0-Personal-Trading + org.opencontainers.image.licenses=Apache-2.0 AND LicenseRef-PineForge-Source-License-1.1 - name: Build + push (multi-arch) uses: docker/build-push-action@v6 diff --git a/README.md b/README.md index d3ced2e..4767cca 100644 --- a/README.md +++ b/README.md @@ -235,23 +235,27 @@ terms, so that licence does not cover the whole image: - **`pineforge-engine`** (`libpineforge.a` and headers): Apache-2.0, with Eigen under MPL-2.0 — see the engine's [`LEGAL.md`](https://github.com/pineforge-4pass/pineforge-engine/blob/main/LEGAL.md). -- **`pineforge-codegen`** (the transpiler): source-available under the PolyForm - Noncommercial License 1.0.0 with a Personal Trading exception. Companies, - funds, embedding in a product and hosted or public-facing services need a - commercial licence — see its +- **`pineforge-codegen`** (the transpiler): source-available. From codegen + 1.2.0 (images from 1.2.0 on) it is under the PineForge Source License 1.1; + earlier releases, and the images up to 1.1.0 that bundle them, keep the + PolyForm Noncommercial License 1.0.0 with a Personal Trading exception that + they shipped with. Personal trading is free; investment management, use by + or for a company or fund, embedding in a product and hosted or public-facing + services need a commercial licence — see its [`LICENSE`](https://github.com/pineforge-4pass/pineforge-codegen-oss/blob/main/LICENSE) and [`LEGAL.md`](https://github.com/pineforge-4pass/pineforge-codegen-oss/blob/main/LEGAL.md). - **Debian base image, g++, Eigen and Python**: their upstream licences. The image's `org.opencontainers.image.licenses` label names the licences of the -PineForge components: -`Apache-2.0 AND LicenseRef-PolyForm-Noncommercial-1.0.0-Personal-Trading`, -Apache-2.0 for the engine and this repository's files, and a `LicenseRef` for -the transpiler's LICENSE, which is the PolyForm Noncommercial License 1.0.0 as -modified by its Personal Trading and Commercial Use sections (so not the SPDX -`PolyForm-Noncommercial-1.0.0` text). The base image's packages, Eigen -included, keep the upstream licences listed above. Images up to 1.0.0 carry -`Apache-2.0` in that label. +PineForge components: `Apache-2.0 AND LicenseRef-PineForge-Source-License-1.1` +from 1.2.0 on, Apache-2.0 for the engine and this repository's files, and a +`LicenseRef` for the transpiler's LICENSE, the PineForge Source License 1.1 (no +SPDX identifier exists for it). The base image's packages, Eigen included, keep +the upstream licences listed above. Images 1.0.1 to 1.1.0 carry +`Apache-2.0 AND LicenseRef-PolyForm-Noncommercial-1.0.0-Personal-Trading` +(the transpiler's earlier LICENSE, the PolyForm Noncommercial License 1.0.0 as +modified by its Personal Trading and Commercial Use sections), and images up +to 1.0.0 carry `Apache-2.0`. ## Harness / engine ABI diff --git a/docker/Dockerfile b/docker/Dockerfile index 3bffe8f..862fdee 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -71,7 +71,7 @@ LABEL org.opencontainers.image.title="pineforge-release" \ org.opencontainers.image.revision="${RELEASE_GIT_SHA}" \ org.opencontainers.image.created="${RELEASE_BUILD_DATE}" \ org.opencontainers.image.source="https://github.com/pineforge-4pass/pineforge-release" \ - org.opencontainers.image.licenses="Apache-2.0 AND LicenseRef-PolyForm-Noncommercial-1.0.0-Personal-Trading" \ + org.opencontainers.image.licenses="Apache-2.0 AND LicenseRef-PineForge-Source-License-1.1" \ io.pineforge.engine.version="${ENGINE_VERSION}" \ io.pineforge.codegen.version="${CODEGEN_VERSION}" diff --git a/tests/test_release_workflows.py b/tests/test_release_workflows.py index 95d3035..9b2d7a1 100644 --- a/tests/test_release_workflows.py +++ b/tests/test_release_workflows.py @@ -146,7 +146,7 @@ def test_licences_label_covers_the_bundled_transpiler(self): # docker/metadata-action's labels override the Dockerfile's, and it # derives org.opencontainers.image.licenses from the repository's # Apache-2.0, so publish.yml must set the label itself. - expr = "Apache-2.0 AND LicenseRef-PolyForm-Noncommercial-1.0.0-Personal-Trading" + expr = "Apache-2.0 AND LicenseRef-PineForge-Source-License-1.1" body = _step(self.text, "Image metadata") self.assertIn(f"org.opencontainers.image.licenses={expr}\n", body) self.assertIn("labels: ${{ steps.meta.outputs.labels }}", self.text)