Skip to content

chore: add the project LICENSE and point every manifest at it - #2449

Merged
cliffhall merged 1 commit into
v2/mainfrom
v2/chore/2406-license
Sep 23, 2026
Merged

cliffhall merged 1 commit into
v2/mainfrom
v2/chore/2406-license

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Closes #2406

What changed

v2 had no LICENSE file anywhere, in the repository or the npm tarball, while four manifests declared plain MIT. This PR puts v2 back in the state v1/main is already in (#1017, #1036).

File Before After
LICENSE (new) missing identical to v1/main's: the MCP licensing-transition notice, then the Apache-2.0 and MIT texts, then the CC-BY-4.0 pointer for docs
package.json (published) "MIT" "SEE LICENSE IN LICENSE", the same value v1 uses
clients/{cli,tui,launcher}/package.json "MIT" "SEE LICENSE IN ../../LICENSE"
clients/web/package.json absent "SEE LICENSE IN ../../LICENSE"
every package-lock.json root entry mirrors the old manifest mirrors the new one; no other lockfile churn
README.md License section MIT. points at LICENSE and summarizes the transition terms

The client manifests are private: true and are never published, so their SEE LICENSE IN points at the root file by relative path instead of a copy nobody ships.

Tarball

npm always packs a root LICENSE, whatever files and .npmignore say. .npmignore does not exclude it in any case. Verified:

$ npm pack --dry-run --ignore-scripts | grep -i license
npm notice 12.2kB LICENSE

For the maintainer

The issue rightly says which text applies is a maintainer and legal decision. This PR copies v1's LICENSE verbatim, which is also the text modelcontextprotocol/typescript-sdk carries. If v2 should carry different terms, only the LICENSE file and the README summary need to change; the manifest values stay the same either way.

npm run local:gate passed.

🤖 Generated with Claude Code

v2 shipped with no LICENSE file anywhere in the repository or the npm
tarball, while four manifests declared plain "MIT". Restore the state
v1/main is in (#1017, #1036): the root LICENSE carries the MCP
licensing-transition notice with the Apache-2.0, MIT and CC-BY-4.0
terms, the published manifest says "SEE LICENSE IN LICENSE", and the
private client manifests point at the root file. README's License
section now describes the file instead of saying "MIT."

npm always packs a root LICENSE regardless of "files", so it lands in
the tarball (verified with npm pack --dry-run).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall cliffhall added the v2 Issues and PRs for v2 label Sep 23, 2026
@cliffhall
cliffhall requested a balanced review from Copilot September 23, 2026 00:29

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The implementation is internally consistent, but adopting licensing terms requires final maintainer or legal confirmation.

Review effort: Balanced
Findings: None

What changed in this PR

Adds the project’s established licensing terms and aligns all manifests and documentation.

Changes:

  • Adds the transition notice and Apache-2.0, MIT, and CC-BY-4.0 terms.
  • Updates manifest metadata, lockfiles, and README guidance.
File Description
LICENSE Adds the licensing terms used by v1 and the TypeScript SDK.
README.md Summarizes and links the licensing terms.
package.json Points published package metadata to LICENSE.
package-lock.json Synchronizes root package metadata.
clients/​web/​package.json Adds the root-license reference.
clients/​web/​package-lock.json Synchronizes web metadata.
clients/​cli/​package.json Replaces the MIT declaration with the root-license reference.
clients/​cli/​package-lock.json Synchronizes CLI metadata.
clients/​tui/​package.json Replaces the MIT declaration with the root-license reference.
clients/​tui/​package-lock.json Synchronizes TUI metadata.
clients/​launcher/​package.json Replaces the MIT declaration with the root-license reference.
clients/​launcher/​package-lock.json Synchronizes launcher metadata.
Files not reviewed (4)
  • clients/cli/package-lock.json: Generated file
  • clients/launcher/package-lock.json: Generated file
  • clients/tui/package-lock.json: Generated file
  • clients/web/package-lock.json: Generated file

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@cliffhall

Copy link
Copy Markdown
Member Author

Copilot review round 1: no findings, and no inline or suppressed comments, so nothing to change and no further round requested.

The overview's one note — that adopting licensing terms needs final maintainer/legal confirmation — is agreed and already called out in the PR body under For the maintainer: the LICENSE text is v1/main's verbatim (also what modelcontextprotocol/typescript-sdk carries), and only LICENSE plus the README summary would change if v2 should carry different terms.

@cliffhall cliffhall linked an issue Sep 23, 2026 that may be closed by this pull request
2 tasks done
@cliffhall
cliffhall merged commit 15f2d98 into v2/main Sep 23, 2026
5 checks passed
@cliffhall
cliffhall deleted the v2/chore/2406-license branch September 23, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v2 ships with no LICENSE file, and four manifests declare plain MIT

2 participants