From 0b5ca394dfee039b585eca52ead115bebe14d4db Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 30 Aug 2026 22:42:23 +0200 Subject: [PATCH 01/99] Set disclaimer --- content/software-licensing-eu.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 content/software-licensing-eu.md diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md new file mode 100644 index 0000000..154111d --- /dev/null +++ b/content/software-licensing-eu.md @@ -0,0 +1,23 @@ +# Software licensing + +```{objectives} + - Objective 1 +``` + +```{discussion} Limitations and context of this lesson + +This lesson is designed as practical educational material for researchers and research software engineers, not formal legal advice. + +* Regional Focus: Guidance is grounded in European Union directives and Nordic institutional frameworks. Specific rules may differ under non-EU legal frameworks (such as US copyright law). +* Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. +* Legal Grounding: Core concepts reflect European legal frameworks, including EU software directives, the Cyber Resilience Act regarding dependency tracking, and relevant national copyright exceptions. +* Scope: This lesson covers general principles of open-source reuse, copyright scope, and software adaptation. Complex corporate IP structures, patent strategies, or disputed ownership cases fall outside this scope. + +If you need formal guidance for publishing, commercializing, or licensing a specific project, consult your institution's Technology Transfer Office (TTO), Legal Affairs Department, or these primary reference tools: + +* [Joinup Licensing Assistant (JLA)](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses): Official European Commission portal to search and compare open software licenses. +* [JLA Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker): European Commission tool to verify if multi-licensed dependencies can be combined. +* [FSFE REUSE Initiative](https://reuse.software/): The modern European standard for managing machine-readable copyright notices and SPDX headers. +* [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/): Reference list of institutional software policies across research organizations. +``` + From 8d3873e3d6118fd4d235b39148797ea3060a12eb Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 31 Aug 2026 16:41:14 +0200 Subject: [PATCH 02/99] Start the introduction --- content/conf.py | 1 + content/software-licensing-eu.md | 85 +++++++++++++++++++++++++++++--- 2 files changed, 78 insertions(+), 8 deletions(-) diff --git a/content/conf.py b/content/conf.py index 2f54faf..8c6395a 100644 --- a/content/conf.py +++ b/content/conf.py @@ -42,6 +42,7 @@ "sphinx_rtd_theme_ext_color_contrast", "sphinx_coderefinery_branding", "lesson_metadata", + "sphinxcontrib.mermaid", ] # Settings for myst_nb: diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 154111d..2485ac1 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -8,16 +8,85 @@ This lesson is designed as practical educational material for researchers and research software engineers, not formal legal advice. -* Regional Focus: Guidance is grounded in European Union directives and Nordic institutional frameworks. Specific rules may differ under non-EU legal frameworks (such as US copyright law). +* Regional Focus: Guidance is grounded in European Union directives and Nordic institutional frameworks. * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. -* Legal Grounding: Core concepts reflect European legal frameworks, including EU software directives, the Cyber Resilience Act regarding dependency tracking, and relevant national copyright exceptions. -* Scope: This lesson covers general principles of open-source reuse, copyright scope, and software adaptation. Complex corporate IP structures, patent strategies, or disputed ownership cases fall outside this scope. +* Scope: This lesson covers general principles of open-source reuse, copyright scope, and software adaptation. -If you need formal guidance for publishing, commercializing, or licensing a specific project, consult your institution's Technology Transfer Office (TTO), Legal Affairs Department, or these primary reference tools: +If you need formal guidance reference below could be used: -* [Joinup Licensing Assistant (JLA)](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses): Official European Commission portal to search and compare open software licenses. -* [JLA Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker): European Commission tool to verify if multi-licensed dependencies can be combined. -* [FSFE REUSE Initiative](https://reuse.software/): The modern European standard for managing machine-readable copyright notices and SPDX headers. -* [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/): Reference list of institutional software policies across research organizations. +* [Directive 2009/24/EC of the European Parliament and of the Council](https://eur-lex.europa.eu/eli/dir/2009/24) +* [Joinup Licensing Assistant,JLA](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) +* [FSFE REUSE Initiative](https://reuse.software/) +* [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) +``` + +## Introduction + +- What parts of computer programs are protected by copyright + - Protected: Specific text and expression of a program in any form, including preparatory design work + - Not protected: Underlying ideas, mathematical algorithms, logic, and interface principles. + +## Difference in terminology in the US regulative text and EU regulation 2009/24/EC + +### 1. Modified Code & Works +* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). +* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). +* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. + +### 2. User Rights & Exceptions +* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). +* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). +* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. + +### 3. Waiver of Rights +* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). +* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. +* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. + +### 4. Work Ownership in Employment +* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). +* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). +* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. + +### 5. Non-Protectable Elements +* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). +* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). +* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. + + +## Claisfication + +```{mermaid} + flowchart TB + subgraph box[ ] + A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] + A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] + A --> D["All Rights Reserved / Proprietary"] + + B --> B1["Run & Modify?
Yes!"] + B --> B2["Sell copies as-is?
Yes!"] + B --> B3["Embed in closed product & sell?
Yes!"] + B --> B4["Must changes stay open?
No (Optional)"] + + C --> C1["Run & Modify?
Yes!"] + C --> C2["Sell copies as-is?
Yes!"] + C --> C3["Embed in closed product & sell?
No!"] + C --> C4["Must changes stay open?
Yes! (Mandatory)"] + + D --> D1["Run & Modify?
No! (Zero permission)"] + D --> D2["Sell copies as-is?
No!"] + D --> D3["Embed in closed product & sell?
No!"] + D --> D4["Can I change code?
No (Closed source)"] + end + classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; + classDef box fill:#ffffff; + class B1,B2,B3,B4,C1,C2 permissive; + class C3,C4,D1,D2,D3,D4 proprietary; + class box box; + class A,B,C,D mains; ``` From 1e5a4f66c3e4a137ba87e4e63c722eec3ee1f290 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Tue, 1 Sep 2026 00:25:25 +0200 Subject: [PATCH 03/99] first scenario --- content/software-licensing-eu.md | 24 +++++++++++++++++++++++- 1 file changed, 23 insertions(+), 1 deletion(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 2485ac1..270ed42 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -54,7 +54,7 @@ If you need formal guidance reference below could be used: * **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. -## Claisfication +## Claisfication of licenses related to software ```{mermaid} flowchart TB @@ -90,3 +90,25 @@ If you need formal guidance reference below could be used: class A,B,C,D mains; ``` +::::{exercise} Scenario 1: Own algorithm with external dependencies +You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code, but relies on third-party libraries referenced via dependency manifests (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). + +**Tasks**: +1. Can you apply any open-source license you want to your repository? +2. Practice selecting a **Permissive** open-source license using the [Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) by toggling the following options: + +| ๐ŸŸข **Can** | โšช **Must** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | +| [x] Commercial use | [x] Incl. Copyright | [x] OSI approved | +| [x] Modify/merge | | | +| [x] Distribute | | | + +:::{solution} +**Legal Reality**: Referenced external dependencies remain separate packages[cite: 1]. Because you have not pasted third-party source code directly into your repository files, you hold full copyright over your original codebase[cite: 1]. + +* **Outcome**: **Fully Permissible.** You own the original source code and can choose any open-source license (e.g., MIT, Apache-2.0, EUPL-1.2, GPL-3.0)[cite: 1]. +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: Selecting these filters returns licenses that grant maximum reuse and commercial rights while requiring only standard copyright attribution[cite: 1]. +* **User Obligation**: Downstream users who compile or run your software must comply with the individual licenses of external packages when fetching or linking them[cite: 1]. +::: +:::: From 91f2699a219cc1b083dcfda1b2d515c5fd6c577c Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Tue, 1 Sep 2026 23:48:04 +0200 Subject: [PATCH 04/99] update clasification diagram --- content/software-licensing-eu.md | 68 ++++++++++++++++++-------------- 1 file changed, 38 insertions(+), 30 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 270ed42..7e66263 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -58,36 +58,44 @@ If you need formal guidance reference below could be used: ```{mermaid} flowchart TB - subgraph box[ ] - A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] - A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] - A --> D["All Rights Reserved / Proprietary"] - - B --> B1["Run & Modify?
Yes!"] - B --> B2["Sell copies as-is?
Yes!"] - B --> B3["Embed in closed product & sell?
Yes!"] - B --> B4["Must changes stay open?
No (Optional)"] - - C --> C1["Run & Modify?
Yes!"] - C --> C2["Sell copies as-is?
Yes!"] - C --> C3["Embed in closed product & sell?
No!"] - C --> C4["Must changes stay open?
Yes! (Mandatory)"] - - D --> D1["Run & Modify?
No! (Zero permission)"] - D --> D2["Sell copies as-is?
No!"] - D --> D3["Embed in closed product & sell?
No!"] - D --> D4["Can I change code?
No (Closed source)"] - end - classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; - classDef box fill:#ffffff; - class B1,B2,B3,B4,C1,C2 permissive; - class C3,C4,D1,D2,D3,D4 proprietary; - class box box; - class A,B,C,D mains; + subgraph box[ ] + A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] + A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] + A --> D["All Rights Reserved / Proprietary"] + + B --> B1["Run & Modify?
Yes!"] + B --> B2["Sell copies as-is?
Yes!"] + B --> B3["Embed in closed product & sell?
Yes!"] + B --> B4["Must changes stay open?
No (Optional)"] + + C --> C1["Run & Modify?
Yes!"] + C --> C2["Sell copies as-is?
Yes!"] + C --> C3["Embed in closed product & sell?
No!"] + C --> C4["Must changes stay open?
Yes! (Mandatory)"] + + D --> D1["Run & Modify?
No! (Zero permission)"] + D --> D2["Sell copies as-is?
No!"] + D --> D3["Embed in closed product & sell?
No!"] + D --> D4["Can I change code?
No (Closed source)"] + subgraph osi["Open Source Initiative (OSI)"] + osi_H["๐Ÿ‘‰ Some exceptions exists"] + B["Permissive
(MIT, BSD, Apache-2.0)"] + C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] + end + end + classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; + classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; + classDef box fill:#ffffff; + class B1,B2,B3,B4,C1,C2 permissive; + class C3,C4,D1,D2,D3,D4 proprietary; + class box box; + class A,B,C,D mains; + class osi_H,osi osiBox; + ``` ::::{exercise} Scenario 1: Own algorithm with external dependencies From cb1e18f051b4fda7a099b4e414c1d2b3bfce0d37 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 2 Sep 2026 23:07:07 +0200 Subject: [PATCH 05/99] Make scenario 1 shorter --- content/software-licensing-eu.md | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 7e66263..b688374 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -99,11 +99,9 @@ If you need formal guidance reference below could be used: ``` ::::{exercise} Scenario 1: Own algorithm with external dependencies -You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code, but relies on third-party libraries referenced via dependency manifests (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). +You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code, but relies on third-party libraries referenced via dependency manifests, i.e. tell the user what dependencies are needed to be satisfied and they obtain it them selves (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). -**Tasks**: -1. Can you apply any open-source license you want to your repository? -2. Practice selecting a **Permissive** open-source license using the [Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) by toggling the following options: +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: | ๐ŸŸข **Can** | โšช **Must** | ๐ŸŸก **Support** | | :--- | :--- | :--- | @@ -112,11 +110,12 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your | [x] Distribute | | | :::{solution} -**Legal Reality**: Referenced external dependencies remain separate packages[cite: 1]. Because you have not pasted third-party source code directly into your repository files, you hold full copyright over your original codebase[cite: 1]. +**Legal Reality**: Referenced external dependencies remain separate packages. Because you have not pasted third-party source code directly into your repository files, you hold full copyright over your original codebase. -* **Outcome**: **Fully Permissible.** You own the original source code and can choose any open-source license (e.g., MIT, Apache-2.0, EUPL-1.2, GPL-3.0)[cite: 1]. +* **Outcome**: **Fully Permissible.** You own the original source code and can choose any open-source license. * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: Selecting these filters returns licenses that grant maximum reuse and commercial rights while requiring only standard copyright attribution[cite: 1]. -* **User Obligation**: Downstream users who compile or run your software must comply with the individual licenses of external packages when fetching or linking them[cite: 1]. +* **Why**: Selecting these filters returns licenses that grant maximum reuse and commercial rights while requiring only standard copyright attribution. +* **User Obligation**: Downstream users who compile or run your software must comply with the individual licenses of external packages when fetching or linking them. +* **Mixing, redistribution: ::: :::: From 596d35b4995cd98c12e6ffb01ace6432f2242b77 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 2 Sep 2026 23:29:02 +0200 Subject: [PATCH 06/99] include new lesson --- content/index.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/index.rst b/content/index.rst index 4486a72..49c059b 100644 --- a/content/index.rst +++ b/content/index.rst @@ -51,7 +51,7 @@ navigating and deciding on licenses. :hidden: social-coding - software-licensing + software-licensing-eu software-citation sharing-data From e77d6560467a2b32ccda7f9fd1cd519811ec37d5 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 2 Sep 2026 23:29:18 +0200 Subject: [PATCH 07/99] Scenario 2 --- content/software-licensing-eu.md | 46 +++++++++++++++++++++++++------- 1 file changed, 37 insertions(+), 9 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index b688374..d2cbf0c 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -99,23 +99,51 @@ If you need formal guidance reference below could be used: ``` ::::{exercise} Scenario 1: Own algorithm with external dependencies -You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code, but relies on third-party libraries referenced via dependency manifests, i.e. tell the user what dependencies are needed to be satisfied and they obtain it them selves (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). +You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). + +* **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. [Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: | ๐ŸŸข **Can** | โšช **Must** | ๐ŸŸก **Support** | | :--- | :--- | :--- | -| [x] Commercial use | [x] Incl. Copyright | [x] OSI approved | -| [x] Modify/merge | | | -| [x] Distribute | | | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | +| โ˜‘ Distribute | | | :::{solution} -**Legal Reality**: Referenced external dependencies remain separate packages. Because you have not pasted third-party source code directly into your repository files, you hold full copyright over your original codebase. +**Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. -* **Outcome**: **Fully Permissible.** You own the original source code and can choose any open-source license. +* **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: Selecting these filters returns licenses that grant maximum reuse and commercial rights while requiring only standard copyright attribution. -* **User Obligation**: Downstream users who compile or run your software must comply with the individual licenses of external packages when fetching or linking them. -* **Mixing, redistribution: +* **Why**: Filters select licenses granting maximum reuse while requiring only basic copyright attribution. +* **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. +* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined binary that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. +::: +:::: + +::::{exercise} Scenario 2: Implementing an algorithm from a paper +You read a published scientific paper or technical specification, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. + +* **Licensing Goal**: You want **reciprocal protection** anyone can use your implementation, but any downstream modifications distributed by others must remain open source. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | +| :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | +| โ˜‘ Distribute | | | + +:::{solution} +**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new, independent copyright. + +* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation and can choose any open-source license. +* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` +* **Why**: Selecting **"Copyleft/Share a."** and **"Disclose source"** filters out permissive licenses to isolate reciprocal terms. +* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under the same copyleft terms. +* **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. ::: :::: From 66f7026130baf0f79e90401bb9149c2d6c3507c6 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 12:06:00 +0200 Subject: [PATCH 08/99] make scenarios consitent --- content/software-licensing-eu.md | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index d2cbf0c..3889006 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -105,21 +105,21 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your [Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: -| ๐ŸŸข **Can** | โšช **Must** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | -| โ˜‘ Distribute | | | +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | :::{solution} **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. * **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **Selected Category**: **Permissive** (driven by our goal of maximum adoption). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: Filters select licenses granting maximum reuse while requiring only basic copyright attribution. +* **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). * **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. -* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined binary that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. +* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. ::: :::: @@ -130,11 +130,11 @@ You read a published scientific paper or technical specification, understand the [Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | -| :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | -| โ˜‘ Distribute | | | +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | :::{solution} **Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new, independent copyright. @@ -142,7 +142,7 @@ You read a published scientific paper or technical specification, understand the * **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation and can choose any open-source license. * **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). * **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -* **Why**: Selecting **"Copyleft/Share a."** and **"Disclose source"** filters out permissive licenses to isolate reciprocal terms. +* **Why**: Adding **`Copyleft/Share a.`** and **`Disclose source`** under the **Must** column isolates reciprocal terms while leaving all other baseline criteria identical. * **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under the same copyleft terms. * **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. ::: From 7a24dba4bca219bcd530666c8a67c493a87ee632 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 13:56:45 +0200 Subject: [PATCH 09/99] Ai licenses --- content/software-licensing-eu.md | 50 ++++++++++++++++++++++++++++++++ 1 file changed, 50 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 3889006..727563d 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -147,3 +147,53 @@ You read a published scientific paper or technical specification, understand the * **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. ::: :::: + +::::{exercise} Scenario 3: Directly embedding third-party Copyleft source code +You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. + +* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. + +* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. +* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` +* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. +* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. +::: +:::: + +::::{exercise} Scenario 4: Generating or assisting code using AI tools +You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. + +* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). + +* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. +* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). +* **Why**: AI generation does not introduce third-party license obligations unless the AI model directly copied, copyrighted copyleft code from its training data. +* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. +* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. +::: +:::: From 01fd8874b46237e41b62120709bf996b507cbac7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 16:08:34 +0200 Subject: [PATCH 10/99] Update to how much ai --- content/software-licensing-eu.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 727563d..092f6f3 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -189,6 +189,8 @@ You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to :::{solution} **Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). +* **How much AI assitance allowed**: There is no prenstage stated, if a dispute arrises *Human Authorship and Creative Control* used by the justice system. Treat AI like an boilerplate code generator, advanced autocomplete or research assistant and use it for actively guiding, reviewing, modifying, and structuring the code compared to *press a button to generate all the code* would be the direction to follow if you are planing to license it. +* **How to check if AI gave copyrighted material**: Manual code base search, built in facilities in AI tools like *Block suggestions matching public code* in GitHub Copilot. Automated license scanners like FOSSology or Snyk. * **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. * **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). From da785210282cd5979fa2fbc238be277756fd24eb Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 16:12:09 +0200 Subject: [PATCH 11/99] Update to how much ai --- content/software-licensing-eu.md | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 092f6f3..6bc6b22 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -189,12 +189,11 @@ You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to :::{solution} **Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). -* **How much AI assitance allowed**: There is no prenstage stated, if a dispute arrises *Human Authorship and Creative Control* used by the justice system. Treat AI like an boilerplate code generator, advanced autocomplete or research assistant and use it for actively guiding, reviewing, modifying, and structuring the code compared to *press a button to generate all the code* would be the direction to follow if you are planing to license it. -* **How to check if AI gave copyrighted material**: Manual code base search, built in facilities in AI tools like *Block suggestions matching public code* in GitHub Copilot. Automated license scanners like FOSSology or Snyk. +* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. +* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). * **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. * **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). -* **Why**: AI generation does not introduce third-party license obligations unless the AI model directly copied, copyrighted copyleft code from its training data. * **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. * **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. ::: From 0432f2ab065593b2c11f43a0a3b072fed1d3f2aa Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 16:32:15 +0200 Subject: [PATCH 12/99] embedding third-party Permissive source code --- content/software-licensing-eu.md | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 6bc6b22..d01d6b3 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -198,3 +198,27 @@ You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to * **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. ::: :::: +::::{exercise} Scenario 5: Directly embedding third-party Permissive source code +You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. + +* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. + +* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 3), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. +* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). +* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. +* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. +* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. +::: +:::: From f6d48f058c879637883bde4e22d2a8fc2ceb6561 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 16:34:36 +0200 Subject: [PATCH 13/99] linking against a Strong Copyleft --- content/software-licensing-eu.md | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index d01d6b3..68367c0 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -222,3 +222,28 @@ You find a useful helper module online licensed under a **Permissive license** ( * **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. ::: :::: + +::::{exercise} Scenario 6: Linking against a Strong Copyleft library (e.g., GSL or FFTW) +You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). + +* **Licensing Goal**: You want to publish your repository and need to select a license that complies with the inbound linking requirements of the GPL library. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Linking your code (statically or dynamically) with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. The strong copyleft obligation extends across the linking boundary. + +* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. You cannot license the overall project under a Permissive license (like MIT). +* **Selected Category**: **Copyleft / Reciprocal** (required by the linked GPL library). +* **JLA Expected Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` +* **Why**: The linked library's reciprocal license mandates that any distributed program depending on it must also provide source code access under compatible copyleft terms (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Users who distribute binaries or modified packages of your project must provide the full source code under the GPL-compatible copyleft license. +* **Mixing & Redistribution**: Anyone using or building upon your work must maintain the GPL-compatible copyleft license. If you want to avoid copyleft restrictions for your codebase, you must replace the GPL library dependency with a permissively licensed alternative (e.g., an MIT or BSD library). +::: +:::: From 3a9ef7e0754ab417e601b73b26518442dd92c29b Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 17:26:00 +0200 Subject: [PATCH 14/99] Move us EU diffrences to the bottom --- content/software-licensing-eu.md | 55 ++++++++++++++++---------------- 1 file changed, 28 insertions(+), 27 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 68367c0..00fd61d 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -26,33 +26,6 @@ If you need formal guidance reference below could be used: - Protected: Specific text and expression of a program in any form, including preparatory design work - Not protected: Underlying ideas, mathematical algorithms, logic, and interface principles. -## Difference in terminology in the US regulative text and EU regulation 2009/24/EC - -### 1. Modified Code & Works -* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). -* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). -* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. - -### 2. User Rights & Exceptions -* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). -* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). -* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. - -### 3. Waiver of Rights -* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). -* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. -* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. - -### 4. Work Ownership in Employment -* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). -* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). -* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. - -### 5. Non-Protectable Elements -* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). -* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). -* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. - ## Claisfication of licenses related to software @@ -247,3 +220,31 @@ You write your own original code from scratch, but your program includes or link * **Mixing & Redistribution**: Anyone using or building upon your work must maintain the GPL-compatible copyleft license. If you want to avoid copyleft restrictions for your codebase, you must replace the GPL library dependency with a permissively licensed alternative (e.g., an MIT or BSD library). ::: :::: + +## Difference in terminology in the US regulative text and EU regulation 2009/24/EC + +### 1. Modified Code & Works +* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). +* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). +* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. + +### 2. User Rights & Exceptions +* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). +* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). +* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. + +### 3. Waiver of Rights +* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). +* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. +* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. + +### 4. Work Ownership in Employment +* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). +* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). +* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. + +### 5. Non-Protectable Elements +* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). +* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). +* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. + From 8fd34d2a6625151485aa6f47344f07f66b628053 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 23:02:59 +0200 Subject: [PATCH 15/99] Objectives --- content/software-licensing-eu.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 00fd61d..25fc92f 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -1,7 +1,12 @@ -# Software licensing +# Software licensing focusing on open source ```{objectives} - - Objective 1 + +- Principles of open source license +- Difference between permissive and copyleft licenses. +- Determine software licence for your project folowing EU regulation. +- Navigate the Joinup Licensing Assistant to select a compliant license. + ``` ```{discussion} Limitations and context of this lesson From d4492906ce9e678128b972c0619c3ab87809304d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 3 Sep 2026 23:24:27 +0200 Subject: [PATCH 16/99] Rearangment --- content/software-licensing-eu.md | 158 +++++++++++++++++-------------- 1 file changed, 85 insertions(+), 73 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 25fc92f..9c15ee5 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -27,9 +27,9 @@ If you need formal guidance reference below could be used: ## Introduction -- What parts of computer programs are protected by copyright - - Protected: Specific text and expression of a program in any form, including preparatory design work - - Not protected: Underlying ideas, mathematical algorithms, logic, and interface principles. +Because copyright only protects the expression (code) and not the ideas, developers use licenses to define how that expression can be legally reused. We can classify these licenses into three main categories + * **Protected**: Specific text and expression of a program in any form, including preparatory design work + * **Not protected**: Underlying ideas, mathematical algorithms, logic, and interface principles. ## Claisfication of licenses related to software @@ -76,6 +76,42 @@ If you need formal guidance reference below could be used: ``` +## Difference in terminology in the US regulative text and EU regulation 2009/24/EC + +### 1. Modified Code & Works +* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). +* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). +* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. + +### 2. User Rights & Exceptions +* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). +* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). +* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. + +### 3. Waiver of Rights +* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). +* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. +* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. + +### 4. Work Ownership in Employment +* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). +* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). +* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. + +### 5. Non-Protectable Elements +* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). +* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). +* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. + + +## How to select a license + +Lets go through some examples on how to use the European Commission's Joinup Licensing Assistant (JLA) to select licenses. The JLA groups license clauses into four categories that map to the visual diagram above: + * ๐ŸŸข Can (Rights): What you are allowed to do (e.g., Run, Modify). Matches the "Yes!" bubbles in the diagram. + * โšช Must (Obligations): What you are required to do (e.g., Include Copyright for Permissive, or Share Alike for Copyleft). Maps to "Must changes stay open?". + * ๐Ÿ”ต Compatible: What context the code is used in (e.g., For software). + * ๐ŸŸก Support: External verification (e.g., OSI approved). Maps to the blue dashed box. + ::::{exercise} Scenario 1: Own algorithm with external dependencies You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). @@ -97,7 +133,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). * **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. -* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. +* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed compiled binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. ::: :::: @@ -126,12 +162,12 @@ You read a published scientific paper or technical specification, understand the ::: :::: -::::{exercise} Scenario 3: Directly embedding third-party Copyleft source code -You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. +::::{exercise} Scenario 3: Directly embedding third-party Permissive source code +You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. -* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. +* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): | ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | | :--- | :--- | :--- | :--- | @@ -140,48 +176,24 @@ You find a useful utility function or module online licensed under a **Copyleft | โ˜‘ Distribute | | | | :::{solution} -**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. +**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. -* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. -* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. -* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. +* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 3), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. +* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). +* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. +* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. +* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. ::: :::: -::::{exercise} Scenario 4: Generating or assisting code using AI tools -You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. - -* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). - -* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. -* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). -* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. -* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). -* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. -* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. -::: -:::: -::::{exercise} Scenario 5: Directly embedding third-party Permissive source code -You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. +::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code +You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. -* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). +* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: | ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | | :--- | :--- | :--- | :--- | @@ -190,18 +202,19 @@ You find a useful helper module online licensed under a **Permissive license** ( | โ˜‘ Distribute | | | | :::{solution} -**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. +**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. -* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 3), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. -* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). -* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. -* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. -* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. +* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. +* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` +* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. +* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. ::: :::: -::::{exercise} Scenario 6: Linking against a Strong Copyleft library (e.g., GSL or FFTW) + +::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). * **Licensing Goal**: You want to publish your repository and need to select a license that complies with the inbound linking requirements of the GPL library. @@ -226,30 +239,29 @@ You write your own original code from scratch, but your program includes or link ::: :::: -## Difference in terminology in the US regulative text and EU regulation 2009/24/EC - -### 1. Modified Code & Works -* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). -* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). -* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. +::::{exercise} Scenario 6: Generating or assisting code using AI tools +You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. -### 2. User Rights & Exceptions -* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). -* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). -* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. +* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. -### 3. Waiver of Rights -* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). -* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. -* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): -### 4. Work Ownership in Employment -* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). -* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). -* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | -### 5. Non-Protectable Elements -* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). -* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). -* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. +:::{solution} +**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). + +* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. +* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). +* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. +* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). +* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. +* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. +::: +:::: From 33bfeaf45211d03131cd6d40841481fc2f46621d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 00:07:37 +0200 Subject: [PATCH 17/99] typo fixes --- content/software-licensing-eu.md | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 9c15ee5..9a01264 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -1,10 +1,9 @@ # Software licensing focusing on open source ```{objectives} - -- Principles of open source license +- Principles of open source licensing +- Determine the software license for your project following EU regulation - Difference between permissive and copyleft licenses. -- Determine software licence for your project folowing EU regulation. - Navigate the Joinup Licensing Assistant to select a compliant license. ``` @@ -25,11 +24,14 @@ If you need formal guidance reference below could be used: * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` -## Introduction +## Introduction + +In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: + + * **Protected**: The specific source code text, expression, binaries, and preparatory design work. + * **Not protected**: Underlying mathematical algorithms, ideas, programming logic, and interface principles. -Because copyright only protects the expression (code) and not the ideas, developers use licenses to define how that expression can be legally reused. We can classify these licenses into three main categories - * **Protected**: Specific text and expression of a program in any form, including preparatory design work - * **Not protected**: Underlying ideas, mathematical algorithms, logic, and interface principles. +Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. ## Claisfication of licenses related to software @@ -56,7 +58,7 @@ Because copyright only protects the expression (code) and not the ideas, develop D --> D3["Embed in closed product & sell?
No!"] D --> D4["Can I change code?
No (Closed source)"] subgraph osi["Open Source Initiative (OSI)"] - osi_H["๐Ÿ‘‰ Some exceptions exists"] + osi_H["๐Ÿ‘‰ Some exceptions exist"] B["Permissive
(MIT, BSD, Apache-2.0)"] C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] end @@ -129,7 +131,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. * **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. -* **Selected Category**: **Permissive** (driven by our goal of maximum adoption). +* **Selected Category**: **Permissive** (driven by you goal of maximum adoption). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). * **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. From 42d344f682c3da48fecd57f191dae7c48d37ff8d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 23:35:44 +0200 Subject: [PATCH 18/99] Containers --- content/software-licensing-eu.md | 83 +++++++++++++++++++++++++++++++- 1 file changed, 82 insertions(+), 1 deletion(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 9a01264..a2a633b 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -4,7 +4,9 @@ - Principles of open source licensing - Determine the software license for your project following EU regulation - Difference between permissive and copyleft licenses. +- Regualtions for AI generated and AI assited code - Navigate the Joinup Licensing Assistant to select a compliant license. +- Understand the licensing distinction between container recipes and container images ``` @@ -33,6 +35,19 @@ In the European Union, software protection is governed by copyright law, which m Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. +### Scope of this Lesson: What Counts as "Software"? + +Under EU statutory law (Directive 2009/24/EC) and international legal frameworks, software is legally defined as **a set of instructions to be used directly or indirectly in a computer to bring about a certain result**, protected under copyright as a literary work. + +Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: + +* **Source Code**: Original algorithms written from scratch or implemented from scientific papers. +* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. +* **Container Recipes**: Infrastructure as Code text files (`Dockerfile`, Apptainer `.def`). +* **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). +* **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. +* **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. + ## Claisfication of licenses related to software @@ -77,7 +92,23 @@ Because copyright only protects the expression and not the underlying ideas, dev class osi_H,osi osiBox; ``` - +### Best Practice: In-File Identification using SPDX + +Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. + +Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: + - In a container recipe + ```dockerfile + # SPDX-License-Identifier: MIT + FROM ubuntu:24.04 + ``` + - In a python script + ```python + # SPDX-License-Identifier: 0BSD + import numpy as np + ``` + +--- ## Difference in terminology in the US regulative text and EU regulation 2009/24/EC ### 1. Modified Code & Works @@ -267,3 +298,53 @@ You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to ::: :::: +::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) +You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` file) to make your research reproducible. The recipe contains text commands that pull a base image, install system packages (`apt-get`), clone code from GitHub, and download data. + +* **Licensing Goal**: You want **maximum adoption** for your build recipe and zero restrictions on who can use or modify your setup instructions. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images, packages, or repositories in build commands does not transfer third-party copyright onto your text file. + +* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions you write and can choose any license for your recipe file. +* **If Generated by AI**: Using AI tools (Copilot, ChatGPT) to generate or refactor a `Dockerfile` follows standard AI code rules. As long as you review, adapt, and configure the recipe for your project, you hold the copyright and retain total freedom over its license. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: The recipe file itself is source code. Referencing third-party packages in `RUN` or `FROM` steps is legally equivalent to writing an `import` statement or listing dependencies in `requirements.txt`. +* **User Obligation**: Users who download your recipe file must preserve your copyright notice. +* **Mixing & Redistribution**: Anyone can freely share or modify your `Dockerfile` or `.def` file under your chosen permissive license, regardless of whether the tools installed by the recipe are Permissive, Copyleft, or Proprietary. +::: +:::: +::::{exercise} Scenario 9: Including AI prompt templates in LLM applications +You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). + +* **Licensing Goal**: You want **maximum adoption** for your application and want to ensure your prompt templates are legally covered under the same open-source license as your Python code. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Copyrightability depends on creative complexity. Simple, functional prompts lack the minimal threshold of creative human expression and carry no copyright. However, complex, highly structured prompt templates are legally classified as literary text assets and are fully protected by copyright. + +* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are treated like source code assets. Applying your overall repository license automatically covers these prompt files. +* **Simple vs. Engineered Prompts**: Short commands (e.g., *"Fix this Dockerfile"*) are uncopyrightable instructions. Complex system prompts, XML-formatted templates, or multi-step reasoning frameworks meet the threshold of creative human authorship. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: Permissive open-source licenses cover software text assets, allowing downstream developers to incorporate, modify, and execute your prompt templates in their own AI pipelines. +* **User Obligation**: Standard attribution obligations apply. Downstream users who copy your prompt files must preserve your copyright notice and file headers (e.g., `# SPDX-License-Identifier: MIT`). +* **Mixing & Redistribution**: Downstream users can freely adapt your prompt templates or integrate them into closed commercial LLM applications, provided they maintain your original copyright attribution in the template files. +::: +:::: From 53bca29d1f0e3a9c19f74bb245c4d2d324c34483 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 23:49:33 +0200 Subject: [PATCH 19/99] Restructure global context --- content/software-licensing-eu.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index a2a633b..7fabb7b 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -49,6 +49,37 @@ Because copyright protection hinges on functional execution combined with creati * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. +## Global Context: Software Engineering Across Legal Borders + +Software development is an inherently cosmopolitan business. Research software engineers routinely collaborate across continents, fetch dependencies from global registries, and commit code to international repositories. + +However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating in the EU or collaborating globally. + +* **Code Adaptation / Refactoring** + * **US Concept:** **Derivative Work** (broadly interpreted judicial doctrine). + * **EU Concept:** **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). + * **Practical Impact:** EU law avoids the vague term "derivative work." Any code modification is classified as a specific statutory act of adaptation or translation. + +* **User Rights & Interoperability** (Run, debug, reverse engineer) + * **US Concept:** **Fair Use** (flexible balancing test evaluated case-by-case in court). + * **EU Concept:** **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation under Art. 6). + * **Practical Impact:** EU user rights are fixed by statute and **cannot be overridden by contract**, removing reliance on judicial interpretation. + +* **Code Ownership** (Employee authorship) + * **US Concept:** **Work Made for Hire** (the employer is legally recognized as the primary author). + * **EU Concept:** **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). + * **Practical Impact:** The individual developer remains the legal author, but all economic exploitation rights automatically transfer to the employer for code created during employment duties. + +* **Waiving Rights & Public Domain** (Giving up control) + * **US Concept:** **Public Domain Dedication** (authors can fully surrender both economic and moral rights). + * **EU & Asian Civil Law Concept:** **Economic Rights Transfer / Non-Waivable Moral Rights**. + * **Practical Impact:** Civil law traditions (EU, China, Japan, South Korea) do not allow complete waivers of moral rights (e.g., the author's right to attribution). Always use permissive open-source licenses (MIT, 0BSD) rather than informal public domain claims. + +* **Collaborating with Asian Ecosystems & Chinese AI Tools** + * **Civil Law Alignment:** Legal frameworks in China, Japan, and South Korea mirror EU civil law rather than US common law, strictly protecting moral rights and requiring formal contract grants. + * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. + * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. + ## Claisfication of licenses related to software ```{mermaid} From ae17b9ab9be0889bd07f5bbfbc1d336790d908b7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 23:53:00 +0200 Subject: [PATCH 20/99] References --- content/software-licensing-eu.md | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 7fabb7b..8ba5421 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -20,7 +20,9 @@ This lesson is designed as practical educational material for researchers and re If you need formal guidance reference below could be used: -* [Directive 2009/24/EC of the European Parliament and of the Council](https://eur-lex.europa.eu/eli/dir/2009/24) +* EU Directive 2009/24/EC: [EUR-Lex - Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) +* US Title 17 ยง 117: [LII / Cornell - 17 U.S. Code ยง 117](https://www.law.cornell.edu/uscode/text/17/117) +* China Software Protection Regulations: [WIPO Lex - Regulations on Computer Software Protection](https://www.wipo.int/wipolex/en/legislation/details/13109) * [Joinup Licensing Assistant,JLA](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) * [FSFE REUSE Initiative](https://reuse.software/) * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) @@ -30,14 +32,14 @@ If you need formal guidance reference below could be used: In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: - * **Protected**: The specific source code text, expression, binaries, and preparatory design work. - * **Not protected**: Underlying mathematical algorithms, ideas, programming logic, and interface principles. + * Protected: The specific source code text, expression, binaries, and preparatory design work. + * Not protected: Underlying mathematical algorithms, ideas, programming logic, and interface principles. Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. ### Scope of this Lesson: What Counts as "Software"? -Under EU statutory law (Directive 2009/24/EC) and international legal frameworks, software is legally defined as **a set of instructions to be used directly or indirectly in a computer to bring about a certain result**, protected under copyright as a literary work. +Under EU statutory law (Directive 2009/24/EC) and international legal frameworks, software is legally defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result, protected under copyright as a literary work. Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: From 0f3c0bff8380a1f8c83759390bc73dd1316c1899 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 23:55:51 +0200 Subject: [PATCH 21/99] Scenario 8 --- content/software-licensing-eu.md | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 8ba5421..1009d32 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -356,6 +356,32 @@ You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` * **Mixing & Redistribution**: Anyone can freely share or modify your `Dockerfile` or `.def` file under your chosen permissive license, regardless of whether the tools installed by the recipe are Permissive, Copyleft, or Proprietary. ::: :::: + +::::{exercise} Scenario 8: Distributing a Built Container Image (Docker Hub or Apptainer .sif) +You build a complete container runtime image (as an Apptainer `.sif` file or an image pushed to Docker Hub/GitHub Container Registry). The compiled image contains a base Linux OS, installed system libraries, runtime dependencies, and your application code. + +* **Licensing Goal**: Fulfill legal obligations imposed by distributing a bundled, compiled binary filesystem image containing third-party works. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Unlike a text recipe file, a compiled container image (`.sif` or registry image) is a **bundle of third-party software works**. You do not hold exclusive copyright over the entire image filesystem. + +* **Outcome**: **Mandatory Compliance (Restricted Choice).** You cannot assign a single permissive license to the distributed image. Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. +* **Selected Category**: **Copyleft / Reciprocal** (if any layer or installed package contains Copyleft software, such as GPL libraries). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` +* **Why**: If your built image bundles a Strong Copyleft component (e.g., a GPL shared library installed via `apt-get` that your application links to), distributing that bundled binary image triggers reciprocal source disclosure requirements for the entire image payload (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including making source code available for any copyleft components contained in the image layers. +* **Mixing & Redistribution**: Downstream users who pull your image must abide by the strictest component license in the container. To keep your distributed application unencumbered, ensure all packages installed into your image layers use permissive licenses. +::: +:::: + ::::{exercise} Scenario 9: Including AI prompt templates in LLM applications You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). From 8599445fddb8e6a9a433ec47fd85a948d77f214a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 4 Sep 2026 23:58:35 +0200 Subject: [PATCH 22/99] Fix typos --- content/software-licensing-eu.md | 48 ++++++++------------------------ 1 file changed, 11 insertions(+), 37 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 1009d32..3b6c4bf 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -4,7 +4,7 @@ - Principles of open source licensing - Determine the software license for your project following EU regulation - Difference between permissive and copyleft licenses. -- Regualtions for AI generated and AI assited code +- Regulations for AI-generated - Navigate the Joinup Licensing Assistant to select a compliant license. - Understand the licensing distinction between container recipes and container images @@ -82,7 +82,7 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. -## Claisfication of licenses related to software +## Classification of licenses ```{mermaid} flowchart TB @@ -131,44 +131,18 @@ Once you select a license, apply it to individual source files and build recipes Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: - In a container recipe - ```dockerfile - # SPDX-License-Identifier: MIT - FROM ubuntu:24.04 - ``` + +```dockerfile +# SPDX-License-Identifier: MIT +FROM ubuntu:24.04 +``` - In a python script - ```python - # SPDX-License-Identifier: 0BSD - import numpy as np - ``` +```python +# SPDX-License-Identifier: 0BSD +import numpy as np +``` --- -## Difference in terminology in the US regulative text and EU regulation 2009/24/EC - -### 1. Modified Code & Works -* **US Concept**: **Derivative Work** (broadly defined in the US Copyright Act). -* **EU Concept**: **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). -* **Practical Impact**: EU law avoids the term "derivative work." Any code modifications are classified as specific statutory acts of adaptation or translation. - -### 2. User Rights & Exceptions -* **US Concept**: **Fair Use** (flexible judicial doctrine evaluated case-by-case in court). -* **EU Concept**: **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation for interoperability under Art. 6). -* **Practical Impact**: EU user rights are fixed by statute and cannot be overridden by contract, avoiding reliance on judicial interpretation. - -### 3. Waiver of Rights -* **US Concept**: **Public Domain Dedication** (authors can fully surrender economic and moral rights). -* **EU Concept**: **Economic Rights Transfer / Non-Waivable Moral Rights**. -* **Practical Impact**: European legal traditions do not allow full waiver of moral rights (e.g., right to attribution), requiring permissive open licenses rather than pure public domain dedications. - -### 4. Work Ownership in Employment -* **US Concept**: **Work Made for Hire** (the employer is legally recognized as the primary author). -* **EU Concept**: **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). -* **Practical Impact**: The individual developer remains the author, but all economic rights automatically transfer to the employer for code created during employment duties. - -### 5. Non-Protectable Elements -* **US Concept**: **Idea-Expression Dichotomy** (established primarily through court case law). -* **EU Concept**: **Expression vs. Ideas, Principles, & Interfaces** (explicitly codified under Directive 2009/24/EC Art. 1(2)). -* **Practical Impact**: EU statutory law explicitly excludes algorithms, programming languages, logic, and interface principles from copyright protection. - ## How to select a license From d45adbb945f18294ed1b1c78409164cafac10bb3 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 5 Sep 2026 00:18:00 +0200 Subject: [PATCH 23/99] Fix typos --- content/software-licensing-eu.md | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 3b6c4bf..9d8c673 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -3,11 +3,10 @@ ```{objectives} - Principles of open source licensing - Determine the software license for your project following EU regulation -- Difference between permissive and copyleft licenses. -- Regulations for AI-generated -- Navigate the Joinup Licensing Assistant to select a compliant license. +- Difference between permissive and copyleft licenses +- Regulations for AI-generated and AI-assisted code +- Navigate the Joinup Licensing Assistant to select a compliant license - Understand the licensing distinction between container recipes and container images - ``` ```{discussion} Limitations and context of this lesson @@ -169,7 +168,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. * **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. -* **Selected Category**: **Permissive** (driven by you goal of maximum adoption). +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). * **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). * **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. @@ -218,7 +217,7 @@ You find a useful helper module online licensed under a **Permissive license** ( :::{solution} **Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. -* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 3), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. +* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 4), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. * **Selected Category**: **Copyleft** (or Permissive, depending on your intent). * **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). * **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. @@ -293,7 +292,7 @@ You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to | โ˜‘ Distribute | | | | :::{solution} -**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship** and are generally **ineligible** for copyright protection. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). +**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). * **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. * **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). From fb2c87dbb09615c5e17333a46e5c04c12182c37b Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 5 Sep 2026 00:19:43 +0200 Subject: [PATCH 24/99] Encoperate Claude suggesitons --- content/software-licensing-eu.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 9d8c673..0524a88 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -63,8 +63,8 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista * **User Rights & Interoperability** (Run, debug, reverse engineer) * **US Concept:** **Fair Use** (flexible balancing test evaluated case-by-case in court). - * **EU Concept:** **Statutory Exceptions** (strictly codified rights, such as error correction under Art. 5(1) or decompilation under Art. 6). - * **Practical Impact:** EU user rights are fixed by statute and **cannot be overridden by contract**, removing reliance on judicial interpretation. + * **EU Concept:** **Statutory Exceptions** (Directive 2009/24/EC Articles 5 & 6). + * **Practical Impact:** EU law splits user rights into **non-waivable statutory rights** (backup copies under Art. 5(2), studying/testing under Art. 5(3), and decompilation for interoperability under Art. 6, which cannot be overridden by contract under Art. 8) and **contract-overridable default rules** (error correction under Art. 5(1), which applies unless an employment or vendor contract specifies otherwise). * **Code Ownership** (Employee authorship) * **US Concept:** **Work Made for Hire** (the employer is legally recognized as the primary author). @@ -347,11 +347,11 @@ You build a complete container runtime image (as an Apptainer `.sif` file or an **Legal Reality**: Unlike a text recipe file, a compiled container image (`.sif` or registry image) is a **bundle of third-party software works**. You do not hold exclusive copyright over the entire image filesystem. * **Outcome**: **Mandatory Compliance (Restricted Choice).** You cannot assign a single permissive license to the distributed image. Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Selected Category**: **Copyleft / Reciprocal** (if any layer or installed package contains Copyleft software, such as GPL libraries). +* **Selected Category**: **Copyleft / Reciprocal** (if your application links against or incorporates Copyleft components inside the container). * **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why**: If your built image bundles a Strong Copyleft component (e.g., a GPL shared library installed via `apt-get` that your application links to), distributing that bundled binary image triggers reciprocal source disclosure requirements for the entire image payload (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including making source code available for any copyleft components contained in the image layers. -* **Mixing & Redistribution**: Downstream users who pull your image must abide by the strictest component license in the container. To keep your distributed application unencumbered, ensure all packages installed into your image layers use permissive licenses. +* **Why (Linking vs. Aggregation)**: If your application links against or embeds a Strong Copyleft library (`GPL-3.0`) installed in the container, distributing that image triggers copyleft disclosure obligations for your compiled application. However, if GPL components in the image are merely independent system utilities or standalone tools, GPL's "mere aggregation" provisions applyโ€”the GPL license governs those specific tools, but does not extend to your independent application binaries. +* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including providing source access for any GPL components or linked works contained in the layers. +* **Mixing & Redistribution**: Downstream users who pull your image must abide by individual component licenses. To keep your application source code unencumbered, ensure your app links only against permissively licensed libraries inside the container layers. ::: :::: From 90c41d3a4181da44856272d88c4015e9a8e634af Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 5 Sep 2026 00:23:57 +0200 Subject: [PATCH 25/99] Fix JLA link --- content/software-licensing-eu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 0524a88..ad3aff2 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -22,7 +22,7 @@ If you need formal guidance reference below could be used: * EU Directive 2009/24/EC: [EUR-Lex - Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) * US Title 17 ยง 117: [LII / Cornell - 17 U.S. Code ยง 117](https://www.law.cornell.edu/uscode/text/17/117) * China Software Protection Regulations: [WIPO Lex - Regulations on Computer Software Protection](https://www.wipo.int/wipolex/en/legislation/details/13109) -* [Joinup Licensing Assistant,JLA](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) +* [Joinup Licensing Assistant,JLA](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) * [FSFE REUSE Initiative](https://reuse.software/) * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` From de4fb87e735843920243805789b26a69f6d6059f Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 5 Sep 2026 23:53:48 +0200 Subject: [PATCH 26/99] include LLM improvment suggestions --- content/software-licensing-eu.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index ad3aff2..ac87c6f 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -1,5 +1,7 @@ # Software licensing focusing on open source +# Software licensing focusing on open source + ```{objectives} - Principles of open source licensing - Determine the software license for your project following EU regulation From 4a0c59f1f06b39f0eeaea6b86c8cbf2a355e2ca6 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 6 Sep 2026 22:13:38 +0200 Subject: [PATCH 27/99] polish scope and objectives --- content/software-licensing-eu.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index ac87c6f..9673d0c 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -4,9 +4,9 @@ ```{objectives} - Principles of open source licensing -- Determine the software license for your project following EU regulation - Difference between permissive and copyleft licenses - Regulations for AI-generated and AI-assisted code +- Determine the software license for your project following EU regulation - Navigate the Joinup Licensing Assistant to select a compliant license - Understand the licensing distinction between container recipes and container images ``` @@ -15,11 +15,11 @@ This lesson is designed as practical educational material for researchers and research software engineers, not formal legal advice. -* Regional Focus: Guidance is grounded in European Union directives and Nordic institutional frameworks. +* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. -* Scope: This lesson covers general principles of open-source reuse, copyright scope, and software adaptation. +* Scope: This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. -If you need formal guidance reference below could be used: +If you need formal guidance reference below and legal experts at your host institute could be used: * EU Directive 2009/24/EC: [EUR-Lex - Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) * US Title 17 ยง 117: [LII / Cornell - 17 U.S. Code ยง 117](https://www.law.cornell.edu/uscode/text/17/117) From b3caf2191af419142af0879907554e565d0930c4 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 6 Sep 2026 22:27:17 +0200 Subject: [PATCH 28/99] Update timing, keep the old lessons for comparisen --- content/index.rst | 5 +++-- content/software-licensing-eu.md | 8 ++++---- 2 files changed, 7 insertions(+), 6 deletions(-) diff --git a/content/index.rst b/content/index.rst index 49c059b..0dad5cf 100644 --- a/content/index.rst +++ b/content/index.rst @@ -40,7 +40,7 @@ navigating and deciding on licenses. :delim: ; 20 min ; :doc:`social-coding` - 30 min ; :doc:`software-licensing` + 90 min ; :doc:`software-licensing-eu` 20 min ; :doc:`software-citation` 10 min ; :doc:`sharing-data` @@ -77,7 +77,8 @@ Who is the course for? .. toctree:: :maxdepth: 1 :caption: About - + + software-licensing All lessons CodeRefinery reusing diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 9673d0c..265bbf1 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -17,13 +17,13 @@ This lesson is designed as practical educational material for researchers and re * Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. -* Scope: This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. +* This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. If you need formal guidance reference below and legal experts at your host institute could be used: -* EU Directive 2009/24/EC: [EUR-Lex - Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) -* US Title 17 ยง 117: [LII / Cornell - 17 U.S. Code ยง 117](https://www.law.cornell.edu/uscode/text/17/117) -* China Software Protection Regulations: [WIPO Lex - Regulations on Computer Software Protection](https://www.wipo.int/wipolex/en/legislation/details/13109) +* [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) +* [US Title 17 ยง 117-Limitations on exclusive rights: Computer programs](https://www.law.cornell.edu/uscode/text/17/117) +* [China Software Protection Regulations,State Council Decree](https://www.wipo.int/wipolex/en/legislation/details/13109) * [Joinup Licensing Assistant,JLA](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) * [FSFE REUSE Initiative](https://reuse.software/) * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) From de87a56c04d3e5cdee9bb1ac98358d7db1c16b14 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 7 Sep 2026 17:19:09 +0200 Subject: [PATCH 29/99] Updates, may be relevent to issue #56 --- content/software-licensing-eu.md | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 265bbf1..52d3fb3 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -1,7 +1,5 @@ # Software licensing focusing on open source -# Software licensing focusing on open source - ```{objectives} - Principles of open source licensing - Difference between permissive and copyleft licenses @@ -19,7 +17,7 @@ This lesson is designed as practical educational material for researchers and re * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. * This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. -If you need formal guidance reference below and legal experts at your host institute could be used: +If you need formal guidance reference below and legal experts at your host institute could be of help: * [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) * [US Title 17 ยง 117-Limitations on exclusive rights: Computer programs](https://www.law.cornell.edu/uscode/text/17/117) From acc8a1208bef59cfa74aa198ed2d26545b6ff899 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 7 Sep 2026 21:43:52 +0200 Subject: [PATCH 30/99] Fixed urls , related to #165 --- content/software-licensing-eu.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 52d3fb3..eda7804 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -20,8 +20,8 @@ This lesson is designed as practical educational material for researchers and re If you need formal guidance reference below and legal experts at your host institute could be of help: * [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) -* [US Title 17 ยง 117-Limitations on exclusive rights: Computer programs](https://www.law.cornell.edu/uscode/text/17/117) -* [China Software Protection Regulations,State Council Decree](https://www.wipo.int/wipolex/en/legislation/details/13109) +* [Compendium of U.S. Copyright Office Practices (3rd Ed.) โ€“ Chapter 700, Section 721: Computer Programs](https://www.copyright.gov/comp3/) +* [Chinese Regulations on Computer Software Protection,(search:"่ฎก็ฎ—ๆœบ่ฝฏไปถไฟๆŠคๆกไพ‹")](https://xzfg.moj.gov.cn/) * [Joinup Licensing Assistant,JLA](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) * [FSFE REUSE Initiative](https://reuse.software/) * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) From b18645dcf8ea857aa0ecb41c63aab583e9e0e0d4 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 7 Sep 2026 22:24:39 +0200 Subject: [PATCH 31/99] Fix software definition according to EU regualtions --- content/software-licensing-eu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index eda7804..530080f 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -38,7 +38,7 @@ Because copyright only protects the expression and not the underlying ideas, dev ### Scope of this Lesson: What Counts as "Software"? -Under EU statutory law (Directive 2009/24/EC) and international legal frameworks, software is legally defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result, protected under copyright as a literary work. +Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is commonly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. Under EU statutory law (Directive 2009/24/EC), computer programsโ€”including their preparatory design materialโ€”are protected under copyright as literary works. Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: From ecd8e6dcbf0b79e6786ad62a613c816c6f12f442 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 7 Sep 2026 22:32:47 +0200 Subject: [PATCH 32/99] For rendering mermaid --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 2a7e803..d98c203 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,6 +1,7 @@ Sphinx sphinx_rtd_theme sphinx_rtd_theme_ext_color_contrast +sphinxcontrib.mermaid myst_nb git+https://github.com/rkdarst/sphinx-copybutton.git@exclude-unselectable-3 sphinx-lesson From f2e71b723e84098be55eb1e4699810cd36e460e5 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 11 Sep 2026 17:35:09 +0200 Subject: [PATCH 33/99] Highlight not legal advice --- content/software-licensing-eu.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md index 530080f..0572a31 100644 --- a/content/software-licensing-eu.md +++ b/content/software-licensing-eu.md @@ -11,7 +11,7 @@ ```{discussion} Limitations and context of this lesson -This lesson is designed as practical educational material for researchers and research software engineers, not formal legal advice. +This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** * Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. From df7516ec25db9a14a16a6b553570c5633e21b781 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 11 Sep 2026 17:57:41 +0200 Subject: [PATCH 34/99] Change file name to address comments by @bast --- content/index.rst | 2 +- content/software-licensing-eu.md | 382 ------------------ content/software-licensing-old.md | 350 ++++++++++++++++ content/software-licensing.md | 648 ++++++++++++++++-------------- 4 files changed, 691 insertions(+), 691 deletions(-) delete mode 100644 content/software-licensing-eu.md create mode 100644 content/software-licensing-old.md diff --git a/content/index.rst b/content/index.rst index 0dad5cf..4dd6ec5 100644 --- a/content/index.rst +++ b/content/index.rst @@ -78,7 +78,7 @@ Who is the course for? :maxdepth: 1 :caption: About - software-licensing + software-licensing-old.md All lessons CodeRefinery reusing diff --git a/content/software-licensing-eu.md b/content/software-licensing-eu.md deleted file mode 100644 index 0572a31..0000000 --- a/content/software-licensing-eu.md +++ /dev/null @@ -1,382 +0,0 @@ -# Software licensing focusing on open source - -```{objectives} -- Principles of open source licensing -- Difference between permissive and copyleft licenses -- Regulations for AI-generated and AI-assisted code -- Determine the software license for your project following EU regulation -- Navigate the Joinup Licensing Assistant to select a compliant license -- Understand the licensing distinction between container recipes and container images -``` - -```{discussion} Limitations and context of this lesson - -This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** - -* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. -* Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. -* This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. - -If you need formal guidance reference below and legal experts at your host institute could be of help: - -* [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) -* [Compendium of U.S. Copyright Office Practices (3rd Ed.) โ€“ Chapter 700, Section 721: Computer Programs](https://www.copyright.gov/comp3/) -* [Chinese Regulations on Computer Software Protection,(search:"่ฎก็ฎ—ๆœบ่ฝฏไปถไฟๆŠคๆกไพ‹")](https://xzfg.moj.gov.cn/) -* [Joinup Licensing Assistant,JLA](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) -* [FSFE REUSE Initiative](https://reuse.software/) -* [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) -``` - -## Introduction - -In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: - - * Protected: The specific source code text, expression, binaries, and preparatory design work. - * Not protected: Underlying mathematical algorithms, ideas, programming logic, and interface principles. - -Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. - -### Scope of this Lesson: What Counts as "Software"? - -Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is commonly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. Under EU statutory law (Directive 2009/24/EC), computer programsโ€”including their preparatory design materialโ€”are protected under copyright as literary works. - -Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: - -* **Source Code**: Original algorithms written from scratch or implemented from scientific papers. -* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. -* **Container Recipes**: Infrastructure as Code text files (`Dockerfile`, Apptainer `.def`). -* **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). -* **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. -* **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. - - -## Global Context: Software Engineering Across Legal Borders - -Software development is an inherently cosmopolitan business. Research software engineers routinely collaborate across continents, fetch dependencies from global registries, and commit code to international repositories. - -However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating in the EU or collaborating globally. - -* **Code Adaptation / Refactoring** - * **US Concept:** **Derivative Work** (broadly interpreted judicial doctrine). - * **EU Concept:** **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). - * **Practical Impact:** EU law avoids the vague term "derivative work." Any code modification is classified as a specific statutory act of adaptation or translation. - -* **User Rights & Interoperability** (Run, debug, reverse engineer) - * **US Concept:** **Fair Use** (flexible balancing test evaluated case-by-case in court). - * **EU Concept:** **Statutory Exceptions** (Directive 2009/24/EC Articles 5 & 6). - * **Practical Impact:** EU law splits user rights into **non-waivable statutory rights** (backup copies under Art. 5(2), studying/testing under Art. 5(3), and decompilation for interoperability under Art. 6, which cannot be overridden by contract under Art. 8) and **contract-overridable default rules** (error correction under Art. 5(1), which applies unless an employment or vendor contract specifies otherwise). - -* **Code Ownership** (Employee authorship) - * **US Concept:** **Work Made for Hire** (the employer is legally recognized as the primary author). - * **EU Concept:** **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). - * **Practical Impact:** The individual developer remains the legal author, but all economic exploitation rights automatically transfer to the employer for code created during employment duties. - -* **Waiving Rights & Public Domain** (Giving up control) - * **US Concept:** **Public Domain Dedication** (authors can fully surrender both economic and moral rights). - * **EU & Asian Civil Law Concept:** **Economic Rights Transfer / Non-Waivable Moral Rights**. - * **Practical Impact:** Civil law traditions (EU, China, Japan, South Korea) do not allow complete waivers of moral rights (e.g., the author's right to attribution). Always use permissive open-source licenses (MIT, 0BSD) rather than informal public domain claims. - -* **Collaborating with Asian Ecosystems & Chinese AI Tools** - * **Civil Law Alignment:** Legal frameworks in China, Japan, and South Korea mirror EU civil law rather than US common law, strictly protecting moral rights and requiring formal contract grants. - * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. - * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. - -## Classification of licenses - -```{mermaid} - flowchart TB - subgraph box[ ] - A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] - A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] - A --> D["All Rights Reserved / Proprietary"] - - B --> B1["Run & Modify?
Yes!"] - B --> B2["Sell copies as-is?
Yes!"] - B --> B3["Embed in closed product & sell?
Yes!"] - B --> B4["Must changes stay open?
No (Optional)"] - - C --> C1["Run & Modify?
Yes!"] - C --> C2["Sell copies as-is?
Yes!"] - C --> C3["Embed in closed product & sell?
No!"] - C --> C4["Must changes stay open?
Yes! (Mandatory)"] - - D --> D1["Run & Modify?
No! (Zero permission)"] - D --> D2["Sell copies as-is?
No!"] - D --> D3["Embed in closed product & sell?
No!"] - D --> D4["Can I change code?
No (Closed source)"] - subgraph osi["Open Source Initiative (OSI)"] - osi_H["๐Ÿ‘‰ Some exceptions exist"] - B["Permissive
(MIT, BSD, Apache-2.0)"] - C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] - end - end - classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; - classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; - classDef box fill:#ffffff; - class B1,B2,B3,B4,C1,C2 permissive; - class C3,C4,D1,D2,D3,D4 proprietary; - class box box; - class A,B,C,D mains; - class osi_H,osi osiBox; - -``` -### Best Practice: In-File Identification using SPDX - -Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. - -Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: - - In a container recipe - -```dockerfile -# SPDX-License-Identifier: MIT -FROM ubuntu:24.04 -``` - - In a python script -```python -# SPDX-License-Identifier: 0BSD -import numpy as np -``` - ---- - -## How to select a license - -Lets go through some examples on how to use the European Commission's Joinup Licensing Assistant (JLA) to select licenses. The JLA groups license clauses into four categories that map to the visual diagram above: - * ๐ŸŸข Can (Rights): What you are allowed to do (e.g., Run, Modify). Matches the "Yes!" bubbles in the diagram. - * โšช Must (Obligations): What you are required to do (e.g., Include Copyright for Permissive, or Share Alike for Copyleft). Maps to "Must changes stay open?". - * ๐Ÿ”ต Compatible: What context the code is used in (e.g., For software). - * ๐ŸŸก Support: External verification (e.g., OSI approved). Maps to the blue dashed box. - -::::{exercise} Scenario 1: Own algorithm with external dependencies -You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). - -* **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. - -* **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). -* **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. -* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed compiled binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. -::: -:::: - -::::{exercise} Scenario 2: Implementing an algorithm from a paper -You read a published scientific paper or technical specification, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. - -* **Licensing Goal**: You want **reciprocal protection** anyone can use your implementation, but any downstream modifications distributed by others must remain open source. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new, independent copyright. - -* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation and can choose any open-source license. -* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -* **Why**: Adding **`Copyleft/Share a.`** and **`Disclose source`** under the **Must** column isolates reciprocal terms while leaving all other baseline criteria identical. -* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under the same copyleft terms. -* **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. -::: -:::: - -::::{exercise} Scenario 3: Directly embedding third-party Permissive source code -You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. - -* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. - -* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 4), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. -* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). -* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. -* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. -* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. -::: -:::: - - -::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code -You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. - -* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. - -* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. -* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. -* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. -::: -:::: - - -::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) -You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). - -* **Licensing Goal**: You want to publish your repository and need to select a license that complies with the inbound linking requirements of the GPL library. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Linking your code (statically or dynamically) with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. The strong copyleft obligation extends across the linking boundary. - -* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. You cannot license the overall project under a Permissive license (like MIT). -* **Selected Category**: **Copyleft / Reciprocal** (required by the linked GPL library). -* **JLA Expected Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` -* **Why**: The linked library's reciprocal license mandates that any distributed program depending on it must also provide source code access under compatible copyleft terms (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Users who distribute binaries or modified packages of your project must provide the full source code under the GPL-compatible copyleft license. -* **Mixing & Redistribution**: Anyone using or building upon your work must maintain the GPL-compatible copyleft license. If you want to avoid copyleft restrictions for your codebase, you must replace the GPL library dependency with a permissively licensed alternative (e.g., an MIT or BSD library). -::: -:::: - -::::{exercise} Scenario 6: Generating or assisting code using AI tools -You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. - -* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). - -* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. -* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). -* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. -* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). -* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. -* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. -::: -:::: - -::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) -You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` file) to make your research reproducible. The recipe contains text commands that pull a base image, install system packages (`apt-get`), clone code from GitHub, and download data. - -* **Licensing Goal**: You want **maximum adoption** for your build recipe and zero restrictions on who can use or modify your setup instructions. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images, packages, or repositories in build commands does not transfer third-party copyright onto your text file. - -* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions you write and can choose any license for your recipe file. -* **If Generated by AI**: Using AI tools (Copilot, ChatGPT) to generate or refactor a `Dockerfile` follows standard AI code rules. As long as you review, adapt, and configure the recipe for your project, you hold the copyright and retain total freedom over its license. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: The recipe file itself is source code. Referencing third-party packages in `RUN` or `FROM` steps is legally equivalent to writing an `import` statement or listing dependencies in `requirements.txt`. -* **User Obligation**: Users who download your recipe file must preserve your copyright notice. -* **Mixing & Redistribution**: Anyone can freely share or modify your `Dockerfile` or `.def` file under your chosen permissive license, regardless of whether the tools installed by the recipe are Permissive, Copyleft, or Proprietary. -::: -:::: - -::::{exercise} Scenario 8: Distributing a Built Container Image (Docker Hub or Apptainer .sif) -You build a complete container runtime image (as an Apptainer `.sif` file or an image pushed to Docker Hub/GitHub Container Registry). The compiled image contains a base Linux OS, installed system libraries, runtime dependencies, and your application code. - -* **Licensing Goal**: Fulfill legal obligations imposed by distributing a bundled, compiled binary filesystem image containing third-party works. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Unlike a text recipe file, a compiled container image (`.sif` or registry image) is a **bundle of third-party software works**. You do not hold exclusive copyright over the entire image filesystem. - -* **Outcome**: **Mandatory Compliance (Restricted Choice).** You cannot assign a single permissive license to the distributed image. Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Selected Category**: **Copyleft / Reciprocal** (if your application links against or incorporates Copyleft components inside the container). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why (Linking vs. Aggregation)**: If your application links against or embeds a Strong Copyleft library (`GPL-3.0`) installed in the container, distributing that image triggers copyleft disclosure obligations for your compiled application. However, if GPL components in the image are merely independent system utilities or standalone tools, GPL's "mere aggregation" provisions applyโ€”the GPL license governs those specific tools, but does not extend to your independent application binaries. -* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including providing source access for any GPL components or linked works contained in the layers. -* **Mixing & Redistribution**: Downstream users who pull your image must abide by individual component licenses. To keep your application source code unencumbered, ensure your app links only against permissively licensed libraries inside the container layers. -::: -:::: - -::::{exercise} Scenario 9: Including AI prompt templates in LLM applications -You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). - -* **Licensing Goal**: You want **maximum adoption** for your application and want to ensure your prompt templates are legally covered under the same open-source license as your Python code. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Copyrightability depends on creative complexity. Simple, functional prompts lack the minimal threshold of creative human expression and carry no copyright. However, complex, highly structured prompt templates are legally classified as literary text assets and are fully protected by copyright. - -* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are treated like source code assets. Applying your overall repository license automatically covers these prompt files. -* **Simple vs. Engineered Prompts**: Short commands (e.g., *"Fix this Dockerfile"*) are uncopyrightable instructions. Complex system prompts, XML-formatted templates, or multi-step reasoning frameworks meet the threshold of creative human authorship. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: Permissive open-source licenses cover software text assets, allowing downstream developers to incorporate, modify, and execute your prompt templates in their own AI pipelines. -* **User Obligation**: Standard attribution obligations apply. Downstream users who copy your prompt files must preserve your copyright notice and file headers (e.g., `# SPDX-License-Identifier: MIT`). -* **Mixing & Redistribution**: Downstream users can freely adapt your prompt templates or integrate them into closed commercial LLM applications, provided they maintain your original copyright attribution in the template files. -::: -:::: diff --git a/content/software-licensing-old.md b/content/software-licensing-old.md new file mode 100644 index 0000000..112a713 --- /dev/null +++ b/content/software-licensing-old.md @@ -0,0 +1,350 @@ +# Software licensing + +```{objectives} +- Knowing about what derivative work is and whether we can share it. +- Get familiar with terminology around licensing. +- Practical advice for software licensing. +``` + + +## Copyright + +```{figure} img/tate.jpg +:alt: Photo of somebody taking a photo of an artwork that contains the text "WHO OWNS WHAT?" +:width: 50% +``` + +- **Trademark**: Protects a name/brand from impersonation. +- **Patent**: Protects a novel, non-obvious, technical invention. +- **Copyright**: Protects **creative expression**: software, writing, graphics, photos, certain datasets, this presentation. + Practically "forever" (lifetime of author + 70 years). + +Copyright controls whether and how we can distribute the original work or the **derivative work**. + + +## Derivative work: Sampling/remixing + +```{figure} img/ai/record-player.png +:alt: Generated image of a monk operating a record player +:width: 50% +``` +[Midjourney, CC-BY-NC 4.0] + +```{figure} img/ai/turntable.png +:alt: Generated image of a monk operating two record players +:width: 50% +``` +[Midjourney, CC-BY-NC 4.0] + +- Changing and distributing software is similar to changing and distributing + music +- You can do almost anything if you don't distribute it + +**Often we don't have the choice**: +- We are expected to publish software +- Sharing can be good insurance against being locked out + + +### Exercise: Derivative work + +````{discussion} Licensing-1: What constitutes derivative work? +This question 5 below can be used as a starting point and copied to the collaborative +document or form input for an online poll: + +```markdown +## Question 5: Which of these are derivative works? + +**Choose many**. Vote by adding an `o` character: + +- A. Download some code from a website and add on to it + - votes: + +- B. Download some code and use one of the functions in your code + - votes: + +- C. Changing code you got from somewhere + - votes: + +- D. Extending code you got from somewhere + - votes: + +- E. Completely rewriting code you got from somewhere + - votes: + +- F. Rewriting code to a different programming language + - votes: + +- G. Linking to libraries (static or dynamic), plug-ins, and drivers + - votes: + +- H. Clean room design (somebody explains you the code but you have never seen it) + - votes: + +- I. You read a paper, understand algorithm, write own code + - votes: +``` + +```{solution} +- Derivative work: A-F +- Not derivative work: G-I +- E and F: This depends on how you do it, see clean room design. +``` +```` + + +```{admonition} Plagiarism vs. Intellectual Property Rights = Research Ethics vs Law +*This insert can be skipped and left as reading exercise* + +In academic context it is important to consider also *plagiarism* and how it relates to copyright and more broadly Intellectual Property Rights ([a clear explanation at this page](https://scholarworks.duke.edu/copyright-advice/copyright-faq/copyright-and-plagiarism/)). Plagiarism is the practice of taking somebody else's ideas or work and claim them as your own: it is the **unacknowledged** use of another person's work. Intellectual Property Rights (IPRs) infringement instead is the **unauthorised** use of another's work. + +IPRs can be classified in two main groups ([WTO](https://www.wto.org/english/tratop_e/trips_e/intel1_e.htm)): i) Copyright and rights related to copyright (computer programs are here) and ii) Industrial properties like trademarks, and inventions (which may include specific technical implementations of systems or code) protected by patents. + +In research ethics, plagiarism is one of the three definition of research misconduct (along with *fabrication* and *falsification*, see ALLEA, [European Code of Conduct for Research Integrity](https://allea.org/wp-content/uploads/2023/06/European-Code-of-Conduct-Revised-Edition-2023.pdf)). Plagiarism is not illegal per se, but it can lead to serious consequences like the retraction of published work. One can engage in plagiarism, without necessarily breaking any IPR law (e.g. write a new book by reusing the plot of an old book that is not under copyright anymore). Copyright infringment instead is illegal and it can result in criminal charges (e.g. fines). Copyright however protects the particular expression of an idea or fact (for example, the specific source code of a program, but not the underlying algorithm itself). + +There is no pre-defined "number of lines of code", "seconds of a song", or "pixels of an image" that can clearly set the basis for plagiarism or IPR infringement. However in the context of research, it can be possible to use *Quotation Exception* (in EU, [ref](https://www.copyrightexceptions.eu/exceptions/info53d/)) and *Fair use* (in USA, [ref](https://en.wikipedia.org/wiki/Fair_use)). Fair use has become controversial recently as it is used as legal basis for training large language models based on scraped internet data ([See for example Henderson, P., Li, X., Jurafsky, D., Hashimoto, T., Lemley, M. A., & Liang, P. (2023). Foundation models and fair use. Journal of Machine Learning Research, 24(400), 1-79.](https://www.jmlr.org/papers/v24/23-0569.html)) +``` + +### Derivative work and containers + +Containers are a bit more tricky when it comes to licenses. + +- Distribution of container recipes: it's like distributing source code +- Distribution of container images: it can be considered like distributing a binary compiled software + +The latter case is a bit more nuanced and the interested reader should read more about "Mere Aggregation" at [GPL-FAQ](https://www.gnu.org/licenses/gpl-faq.html#MereAggregation). Briefly, if the container image just bundles separate programs that talk through normal system interfaces, it is an **aggregate** and each keeps its own license (like a CD-ROM with various packages). If the components are tightly integrated into one program (e.g. a pipeline with various parts that the container can run as a single program), the image may be treated as a **derivative work**, and stricter license obligations (e.g. GPL copyleft) can apply. + +--- + +## Taxonomy of software licenses + +```{figure} img/license-models.png +:alt: "European Union Public Licence (EUPL): guidelines July 2021" + +European Commission, Directorate-General for Informatics, Schmitz, P., European Union Public Licence (EUPL): guidelines July 2021, Publications Office, 2021, +``` + +Comments: +- Arrows represent compatibility (A -> B: B can reuse A) +- Proprietary/custom: Derivative work typically not possible (no arrow goes from proprietary to open) +- Permissive: Derivative work does not have to be shared +- Copyleft/reciprocal: Derivative work must be made available under the same license terms +- NC (non-commercial) and ND (non-derivative) exist for data licenses but not really for software licenses + +**Great resource for comparing software licenses**: [Joinup Licensing Assistant](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) +- Provides comments on licenses +- Easy to compare licenses ([example](https://joinup.ec.europa.eu/licence/compare/BSD-3-Clause;Apache-2.0)) +- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) +- Not biased by some company agenda + +If you would like to learn more about licenses, check out our slide deck: ["Software licensing +and open source explained with +cakes"](https://cicero.xyz/v3/remark/0.14.0/github.com/coderefinery/social-coding/main/licensing-and-cakes.md/). + + +## Exercise: Licensing situations + +````{exercise} Licensing-2: Consider some common licensing situations +1. What is the StackOverflow license for code you copy and paste? +2. A journal requests that you release your software during publication. You have + copied a portion of the code from another package, which you have forgotten. + Can you satisfy the journal's request? +3. You want to fix a bug in a project someone else has released, but there is no license. What risks are there? +4. How would you ask someone to add a license? +5. You incorporate MIT, GPL, and BSD3 licensed code into your project. What possible licenses can you pick for your project? +6. You do the same as above but add in another license that looks strong copyleft. What possible licenses can you use now? +7. Do licenses apply if you don't distribute your code? Why or why not? +8. Which licenses are most/least attractive for companies with proprietary software? + +```{solution} +1. As indicated [here](https://stackoverflow.com/help/licensing), all publicly accessible user contributions are licensed under [Creative Commons Attribution-ShareAlike](https://creativecommons.org/licenses/by-sa/4.0/) license. See Stackoverflow [Terms of service](https://stackoverflow.com/legal/terms-of-service/public#licensing) for more detailed information. +2. "Standard" licensing rules apply. So in this case, you would need to remove the portion of code you have copied from another package before being able to release your software. +3. By default you are no authorized to use the content of a repository when there is no license. And derivative work is also not possible by default. Other risks: it may not be clear whether you can use and distribute (publish) the bugfixed code. For the repo owners it may not be clear whether they can use and distributed the bugfixed code. However, the authors may have forgotten to add a license so we suggest you to contact the authors (e.g. make an issue) and ask whether they are willing to add a license. +4. As mentionned in 3., the easiest is to fill an issue and explain the reasons why you would like to use this software (or update it). +5. Combining software with different licenses can be tricky and it is important to understand compatibilities (or lack of compatibilities) of the various licenses. GPL license is the most protective (BSD and MIT are quite permissive) so for the resulting combined software you could use a GPL license. However, re-licensing may not be necessary. +6. Derivative work would need to be shared under this strong copyleft license (e.g. AGPL or GPL), unless the components are only plugins or libraries. +7. If you keep your code for yourself, you may think you do not need a license. However, remember that in most companies/universities, your employer is "owning" your work and when you leave you may not be allowed to "distribute your code to your future self". So the best is always to add a license! +8. The least attractive licenses for companies with proprietary software are licenses where you would need to keep an open license when creating derivative work. For instance GPL and and AGPL. The most attractive licenses are permissive licenses where they can reuse, modify and relicense with no conditions. For instance MIT, BSD and Apache License. +``` +```` + + +## When should I add a license? + +**Choose a license early in the project, even before you publish it**. Later in +the project it may become complicated to change it. Agreeing on a software +license does not mean that you have to make it open immediately. You can also +follow the **"open core" approach**: You don't have to open source all your +work. Core can be open and on a public branch. Unpublished code can be on a +private repository. + +However, we recommend to **work as if the code is public even though it still +may be private** (thanks to E. Glerean for this great suggestion): This is to +avoid surprises about code in the history with incompatible license years later +when you decide to open the project. + + +## How to add a license if your work is derivative work + +Your code is derivative work if you have started from an existing code and +made changes to it or if you incorporated an existing code into your code. + +If your code is derivative work, then **you need to check the license of the +original code**. Depending on the license, your choices might be limited. In +this case we recommend to use these two resources: +- [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) +- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) + +If the original code does not have a license, you may not be able to distribute your +derivative code. You can try to contact the authors and ask them to clarify +the license of their code. + +Practical steps for **incorporating something small into your own project** with a license +that allows you to do so (as +an example incorporating a function or two from another project): +- Create a `LICENSES/` folder in your project and "put the unmodified license text + (i.e., the license text template without any copyright notices) in your + `LICENSES/` folder" (). This + way if you reuse code from multiple projects, you can keep there multiple + license files. +- **Put the code that you incorporate into a separate file or separate files**. This makes + it later easier to see what was incorporated, and what was written from scratch. + On top of the file(s) which you have incorporated into your project add (and + adapt) the following header ([more examples](https://reuse.software/faq/)): + ```python + # SPDX-FileCopyrightText: 2023 Jane Doe + # + # SPDX-License-Identifier: MIT + ``` + The [REUSE](https://reuse.software/) initiative was started by the [Free + Software Foundation Europe](https://fsfe.org/) to make licensing of software + projects easier. It is OK if you prefer to not follow this strict format but + the advantage of following it is that the + [reuse-tool](https://github.com/fsfe/reuse-tool) makes it then easy to verify + and update license headers if you have many files from different sources. +- If it does not make sense to have several files in your project (e.g. when incorporating + something into a notebook), then add a note/comment + about the license and where the code came from on top of the function. +- Although it is not dictated by the license but it can still be nice to + acknowledge the incorporated functions/code in your README/documentation and to cite + their work if you publish a paper about your code. +- Some licenses are more permissive (you can keep your changes private) but some licenses + require you to publish the changes (share-alike). + +Practical steps for making **changes to an existing project** with a license +that allows you to do so: +- If the project is on GitHub or GitLab or similar, first fork the project + (copy it into your user space where you can make changes). +- For the BSD and MIT licenses you are not obliged to state your changes but it can + still be helpful for others if you do. You can state your changes in the + header of the files you have modified. It can be helpful to state + bigger-picture changes in the README file of the project. +- Some licenses are more permissive (you can keep your changes private) but some licenses + require you to publish the changes (share-alike). + + +### If your work is not derivative work + +If you have started "from scratch", and not used any existing code, or +incorporated existing code into your code, then you may consider your code to +be not derivative work. + +Before you may choose a license, clarify the following points with, for +example, your supervisor, collaborators, or principal investigator: +- Does your work contract, grant, or collaboration agreement dictate a + specific license? +- Is there an intent to commercialize the code? +- When there is unknown or mixed ownership: If there are multiple persons or + organizations as owners of the code, all must agree to the license. + +**Do not invent your own license**. Choose one of the standard licenses, otherwise +compatibility is not clear: + - [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) + - [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) + +Practical steps: +- Create a `LICENSES/` folder ([example](https://github.com/bast/runtest/tree/main/LICENSES)). +- Put the unmodified license text + (i.e., the license text template without any copyright notices) in plain + text format into the folder ([example](https://github.com/bast/runtest/tree/main/LICENSES)). Here are + the two above licenses in plain text: + [EUPL](https://joinup.ec.europa.eu/sites/default/files/custom-page/attachment/2020-03/EUPL-1.2%20EN.txt) + and [MIT](https://en.wikipedia.org/wiki/MIT_License#License_terms) (but the + latter contains a copyright notice which we rather want to have on top of + files). +- Add copyright and license information to each file following + which uses a standard format with + so-called [SPDX identifiers](https://spdx.org/licenses/). Example below + ([example](https://github.com/bast/runtest/blob/3b210d2e9bdbdc1903a1dab9da32e161d390092d/runtest/tuple_comparison.py#L1-L3)): + ```python + # SPDX-FileCopyrightText: 2023 Jane Doe + # + # SPDX-License-Identifier: EUPL-1.2 + ``` + The [REUSE](https://reuse.software/) initiative was started by the [Free + Software Foundation Europe](https://fsfe.org/) to make licensing of software + projects easier. It is OK if you prefer to not follow this strict format but + the advantage of following it is that the + [reuse-tool](https://github.com/fsfe/reuse-tool) makes it then easy to verify + and update license headers if you have many files from different sources. +- For really small projects with one or two files the above may seem excessive + and some projects choose to not have copyright information on top of their + files and they only have one `LICENSE` file and that is + OK for really small projects. + + + +```{admonition} Licensing code produced by generative AI systems + +With generative AI tools for coding such as GitHub copilot, Cursor, or even basic chat implementations (ChatGPT, Claude, Grok, ...) the responsibility fully lays on the person who is going to use (and publish) the generated code. You can never blame the autopilot or the company who invented it, only the driver (you!). + +There are various risks in using generative AI code (this is not a taxonomy). A few examples: + +- Risks for the derivative work: you think your code is doing what you asked, but you did not review it and your results are false +- Risks for the system in use: your generated code has software security issues, e.g. an import is a *typosquat* of an actual library (e.g. "microsoft" is spelled "rnicrosoft" and depending on the font you might totally miss it...) +- Risks related to licenses/IPR: you have generated code that is actually verbatim copy of fully copyrighted code, or code that requires a strict copyleft license. Plagiarism (ethics) also applies. + +If we focus on the last one, a recent paper ([ref](https://arxiv.org/html/2408.02487v1)) estimates that around 2% of AI generated code is "strikingly similar to existing open-source implementations". Generative AI tools are typically not able to provide an exact reference of where certain bits of generated code were copied from, so it is the responsibility of the researcher to verify that the produced code is citing and referencing the license of other published pieces of software. Possibly, future AI systems for code generation can be trained on code that share the same set of licenses (e.g. based only on MIT) to mitigate these risks. + +``` + +--- + + +## Great resources + +- [Research institution policies to support research software (compiled by the Research Software Alliance)](https://www.researchsoft.org/software-policies/) +- Guide from the Aalto University in Finland: ["Opening your Software at Aalto University"](https://www.aalto.fi/en/open-science-and-research/opening-your-software-at-aalto-university) +- [Draft: Research software licensing guide](https://research-software.uit.no/blog/2023-software-licensing-guide/) +- [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) +- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) +- [Social coding lesson material](https://coderefinery.github.io/social-coding/) by [CodeRefinery](https://coderefinery.org/) +- [Citation File Format (CFF)](https://citation-file-format.github.io/) +- [License Selector](https://ufal.github.io/public-license-selector/) +- [GitHub licensing guide](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/licensing-a-repository) +- [Choosing an open-source licence](https://www.software.ac.uk/resources/guides/choosing-open-source-licence) +- [Understanding Open Source and Free Software Licensing](http://www.oreilly.com/openbook/osfreesoft/) +- [Software Licenses in Plain English](https://tldrlegal.com) +- [Don's Bibliography of Ethical Source Reading and Resources](https://github.com/DEGoodmanWilson/Ethical-Resources) +- [Mikko Vรคlimรคki: The Rise of Open Source Licensing](http://lib.tkk.fi/Diss/2005/isbn9529187793/isbn9529187793.pdf) +- [Lawrence Rosen: Open Source Licensing](http://www.rosenlaw.com/oslbook.htm) +- [Aalto IPR Cheatsheet](https://users.aalto.fi/~darstr1/cheatsheets/ipr-cheatsheet.pdf) +- [Contributor License Agreements](https://jacobian.org/2009/sep/17/contributor-license-agreements/) +- [4OSS recommendations](https://softdev4research.github.io/recommendations/) +- [4OSS lesson](https://softdev4research.github.io/4OSS-lesson/) +- [Intellectual Property Rights (IPR), Licensing And Patents](http://oss-watch.ac.uk/resources/ipr) +- [Dispelling Open Source Confusion: An Introduction to Licenses](http://depth-first.com/articles/2006/12/29/dispelling-open-source-confusion-an-introduction-to-licenses/) +- (can send automatic pull request to your GitHub repo) +- +- +- Nadia Asparouhova (formerly Nadia Eghbal): "Working in Public: The Making and Maintenance of Open Source Software" (Stripe Press) +- [Open Source Guides](https://opensource.guide/) +- [The Architecture of Open Source Applications](http://aosabook.org) +- Christopher M. Kelty: ["Two Bits: The Cultural Significance of Free Software"](https://twobits.net/) (Duke University Press, 2008) +- [Open Source (Almost) Everything](http://tom.preston-werner.com/2011/11/22/open-source-everything.html) +- [99 ways to ruin an open source project](http://opensoul.org/99ways/) +- [Open Source Casebook](https://google.github.io/opencasebook/) + +```{keypoints} +- **You cannot ignore licensing**: default is "no one can make copies or + derivative works". +``` diff --git a/content/software-licensing.md b/content/software-licensing.md index 112a713..0572a31 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -1,350 +1,382 @@ -# Software licensing +# Software licensing focusing on open source ```{objectives} -- Knowing about what derivative work is and whether we can share it. -- Get familiar with terminology around licensing. -- Practical advice for software licensing. +- Principles of open source licensing +- Difference between permissive and copyleft licenses +- Regulations for AI-generated and AI-assisted code +- Determine the software license for your project following EU regulation +- Navigate the Joinup Licensing Assistant to select a compliant license +- Understand the licensing distinction between container recipes and container images ``` +```{discussion} Limitations and context of this lesson -## Copyright +This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** -```{figure} img/tate.jpg -:alt: Photo of somebody taking a photo of an artwork that contains the text "WHO OWNS WHAT?" -:width: 50% -``` - -- **Trademark**: Protects a name/brand from impersonation. -- **Patent**: Protects a novel, non-obvious, technical invention. -- **Copyright**: Protects **creative expression**: software, writing, graphics, photos, certain datasets, this presentation. - Practically "forever" (lifetime of author + 70 years). - -Copyright controls whether and how we can distribute the original work or the **derivative work**. +* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. +* Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. +* This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. +If you need formal guidance reference below and legal experts at your host institute could be of help: -## Derivative work: Sampling/remixing - -```{figure} img/ai/record-player.png -:alt: Generated image of a monk operating a record player -:width: 50% -``` -[Midjourney, CC-BY-NC 4.0] - -```{figure} img/ai/turntable.png -:alt: Generated image of a monk operating two record players -:width: 50% +* [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) +* [Compendium of U.S. Copyright Office Practices (3rd Ed.) โ€“ Chapter 700, Section 721: Computer Programs](https://www.copyright.gov/comp3/) +* [Chinese Regulations on Computer Software Protection,(search:"่ฎก็ฎ—ๆœบ่ฝฏไปถไฟๆŠคๆกไพ‹")](https://xzfg.moj.gov.cn/) +* [Joinup Licensing Assistant,JLA](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) +* [FSFE REUSE Initiative](https://reuse.software/) +* [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` -[Midjourney, CC-BY-NC 4.0] -- Changing and distributing software is similar to changing and distributing - music -- You can do almost anything if you don't distribute it +## Introduction + +In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: + + * Protected: The specific source code text, expression, binaries, and preparatory design work. + * Not protected: Underlying mathematical algorithms, ideas, programming logic, and interface principles. + +Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. + +### Scope of this Lesson: What Counts as "Software"? + +Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is commonly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. Under EU statutory law (Directive 2009/24/EC), computer programsโ€”including their preparatory design materialโ€”are protected under copyright as literary works. + +Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: + +* **Source Code**: Original algorithms written from scratch or implemented from scientific papers. +* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. +* **Container Recipes**: Infrastructure as Code text files (`Dockerfile`, Apptainer `.def`). +* **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). +* **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. +* **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. + + +## Global Context: Software Engineering Across Legal Borders + +Software development is an inherently cosmopolitan business. Research software engineers routinely collaborate across continents, fetch dependencies from global registries, and commit code to international repositories. + +However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating in the EU or collaborating globally. + +* **Code Adaptation / Refactoring** + * **US Concept:** **Derivative Work** (broadly interpreted judicial doctrine). + * **EU Concept:** **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). + * **Practical Impact:** EU law avoids the vague term "derivative work." Any code modification is classified as a specific statutory act of adaptation or translation. + +* **User Rights & Interoperability** (Run, debug, reverse engineer) + * **US Concept:** **Fair Use** (flexible balancing test evaluated case-by-case in court). + * **EU Concept:** **Statutory Exceptions** (Directive 2009/24/EC Articles 5 & 6). + * **Practical Impact:** EU law splits user rights into **non-waivable statutory rights** (backup copies under Art. 5(2), studying/testing under Art. 5(3), and decompilation for interoperability under Art. 6, which cannot be overridden by contract under Art. 8) and **contract-overridable default rules** (error correction under Art. 5(1), which applies unless an employment or vendor contract specifies otherwise). + +* **Code Ownership** (Employee authorship) + * **US Concept:** **Work Made for Hire** (the employer is legally recognized as the primary author). + * **EU Concept:** **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). + * **Practical Impact:** The individual developer remains the legal author, but all economic exploitation rights automatically transfer to the employer for code created during employment duties. + +* **Waiving Rights & Public Domain** (Giving up control) + * **US Concept:** **Public Domain Dedication** (authors can fully surrender both economic and moral rights). + * **EU & Asian Civil Law Concept:** **Economic Rights Transfer / Non-Waivable Moral Rights**. + * **Practical Impact:** Civil law traditions (EU, China, Japan, South Korea) do not allow complete waivers of moral rights (e.g., the author's right to attribution). Always use permissive open-source licenses (MIT, 0BSD) rather than informal public domain claims. + +* **Collaborating with Asian Ecosystems & Chinese AI Tools** + * **Civil Law Alignment:** Legal frameworks in China, Japan, and South Korea mirror EU civil law rather than US common law, strictly protecting moral rights and requiring formal contract grants. + * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. + * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. + +## Classification of licenses + +```{mermaid} + flowchart TB + subgraph box[ ] + A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] + A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] + A --> D["All Rights Reserved / Proprietary"] + + B --> B1["Run & Modify?
Yes!"] + B --> B2["Sell copies as-is?
Yes!"] + B --> B3["Embed in closed product & sell?
Yes!"] + B --> B4["Must changes stay open?
No (Optional)"] + + C --> C1["Run & Modify?
Yes!"] + C --> C2["Sell copies as-is?
Yes!"] + C --> C3["Embed in closed product & sell?
No!"] + C --> C4["Must changes stay open?
Yes! (Mandatory)"] + + D --> D1["Run & Modify?
No! (Zero permission)"] + D --> D2["Sell copies as-is?
No!"] + D --> D3["Embed in closed product & sell?
No!"] + D --> D4["Can I change code?
No (Closed source)"] + subgraph osi["Open Source Initiative (OSI)"] + osi_H["๐Ÿ‘‰ Some exceptions exist"] + B["Permissive
(MIT, BSD, Apache-2.0)"] + C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] + end + end + classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; + classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; + classDef box fill:#ffffff; + class B1,B2,B3,B4,C1,C2 permissive; + class C3,C4,D1,D2,D3,D4 proprietary; + class box box; + class A,B,C,D mains; + class osi_H,osi osiBox; -**Often we don't have the choice**: -- We are expected to publish software -- Sharing can be good insurance against being locked out - - -### Exercise: Derivative work - -````{discussion} Licensing-1: What constitutes derivative work? -This question 5 below can be used as a starting point and copied to the collaborative -document or form input for an online poll: +``` +### Best Practice: In-File Identification using SPDX -```markdown -## Question 5: Which of these are derivative works? +Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. -**Choose many**. Vote by adding an `o` character: +Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: + - In a container recipe -- A. Download some code from a website and add on to it - - votes: +```dockerfile +# SPDX-License-Identifier: MIT +FROM ubuntu:24.04 +``` + - In a python script +```python +# SPDX-License-Identifier: 0BSD +import numpy as np +``` -- B. Download some code and use one of the functions in your code - - votes: +--- -- C. Changing code you got from somewhere - - votes: +## How to select a license -- D. Extending code you got from somewhere - - votes: +Lets go through some examples on how to use the European Commission's Joinup Licensing Assistant (JLA) to select licenses. The JLA groups license clauses into four categories that map to the visual diagram above: + * ๐ŸŸข Can (Rights): What you are allowed to do (e.g., Run, Modify). Matches the "Yes!" bubbles in the diagram. + * โšช Must (Obligations): What you are required to do (e.g., Include Copyright for Permissive, or Share Alike for Copyleft). Maps to "Must changes stay open?". + * ๐Ÿ”ต Compatible: What context the code is used in (e.g., For software). + * ๐ŸŸก Support: External verification (e.g., OSI approved). Maps to the blue dashed box. -- E. Completely rewriting code you got from somewhere - - votes: +::::{exercise} Scenario 1: Own algorithm with external dependencies +You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). -- F. Rewriting code to a different programming language - - votes: +* **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. -- G. Linking to libraries (static or dynamic), plug-ins, and drivers - - votes: +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: -- H. Clean room design (somebody explains you the code but you have never seen it) - - votes: +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | -- I. You read a paper, understand algorithm, write own code - - votes: -``` +:::{solution} +**Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. -```{solution} -- Derivative work: A-F -- Not derivative work: G-I -- E and F: This depends on how you do it, see clean room design. -``` -```` +* **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). +* **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. +* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed compiled binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. +::: +:::: +::::{exercise} Scenario 2: Implementing an algorithm from a paper +You read a published scientific paper or technical specification, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. -```{admonition} Plagiarism vs. Intellectual Property Rights = Research Ethics vs Law -*This insert can be skipped and left as reading exercise* +* **Licensing Goal**: You want **reciprocal protection** anyone can use your implementation, but any downstream modifications distributed by others must remain open source. -In academic context it is important to consider also *plagiarism* and how it relates to copyright and more broadly Intellectual Property Rights ([a clear explanation at this page](https://scholarworks.duke.edu/copyright-advice/copyright-faq/copyright-and-plagiarism/)). Plagiarism is the practice of taking somebody else's ideas or work and claim them as your own: it is the **unacknowledged** use of another person's work. Intellectual Property Rights (IPRs) infringement instead is the **unauthorised** use of another's work. +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: -IPRs can be classified in two main groups ([WTO](https://www.wto.org/english/tratop_e/trips_e/intel1_e.htm)): i) Copyright and rights related to copyright (computer programs are here) and ii) Industrial properties like trademarks, and inventions (which may include specific technical implementations of systems or code) protected by patents. +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | -In research ethics, plagiarism is one of the three definition of research misconduct (along with *fabrication* and *falsification*, see ALLEA, [European Code of Conduct for Research Integrity](https://allea.org/wp-content/uploads/2023/06/European-Code-of-Conduct-Revised-Edition-2023.pdf)). Plagiarism is not illegal per se, but it can lead to serious consequences like the retraction of published work. One can engage in plagiarism, without necessarily breaking any IPR law (e.g. write a new book by reusing the plot of an old book that is not under copyright anymore). Copyright infringment instead is illegal and it can result in criminal charges (e.g. fines). Copyright however protects the particular expression of an idea or fact (for example, the specific source code of a program, but not the underlying algorithm itself). +:::{solution} +**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new, independent copyright. -There is no pre-defined "number of lines of code", "seconds of a song", or "pixels of an image" that can clearly set the basis for plagiarism or IPR infringement. However in the context of research, it can be possible to use *Quotation Exception* (in EU, [ref](https://www.copyrightexceptions.eu/exceptions/info53d/)) and *Fair use* (in USA, [ref](https://en.wikipedia.org/wiki/Fair_use)). Fair use has become controversial recently as it is used as legal basis for training large language models based on scraped internet data ([See for example Henderson, P., Li, X., Jurafsky, D., Hashimoto, T., Lemley, M. A., & Liang, P. (2023). Foundation models and fair use. Journal of Machine Learning Research, 24(400), 1-79.](https://www.jmlr.org/papers/v24/23-0569.html)) -``` +* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation and can choose any open-source license. +* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` +* **Why**: Adding **`Copyleft/Share a.`** and **`Disclose source`** under the **Must** column isolates reciprocal terms while leaving all other baseline criteria identical. +* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under the same copyleft terms. +* **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. +::: +:::: -### Derivative work and containers +::::{exercise} Scenario 3: Directly embedding third-party Permissive source code +You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. -Containers are a bit more tricky when it comes to licenses. +* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). -- Distribution of container recipes: it's like distributing source code -- Distribution of container images: it can be considered like distributing a binary compiled software +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): -The latter case is a bit more nuanced and the interested reader should read more about "Mere Aggregation" at [GPL-FAQ](https://www.gnu.org/licenses/gpl-faq.html#MereAggregation). Briefly, if the container image just bundles separate programs that talk through normal system interfaces, it is an **aggregate** and each keeps its own license (like a CD-ROM with various packages). If the components are tightly integrated into one program (e.g. a pipeline with various parts that the container can run as a single program), the image may be treated as a **derivative work**, and stricter license obligations (e.g. GPL copyleft) can apply. +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | ---- +:::{solution} +**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. -## Taxonomy of software licenses +* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 4), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. +* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). +* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. +* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. +* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. +::: +:::: -```{figure} img/license-models.png -:alt: "European Union Public Licence (EUPL): guidelines July 2021" -European Commission, Directorate-General for Informatics, Schmitz, P., European Union Public Licence (EUPL): guidelines July 2021, Publications Office, 2021, -``` +::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code +You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. -Comments: -- Arrows represent compatibility (A -> B: B can reuse A) -- Proprietary/custom: Derivative work typically not possible (no arrow goes from proprietary to open) -- Permissive: Derivative work does not have to be shared -- Copyleft/reciprocal: Derivative work must be made available under the same license terms -- NC (non-commercial) and ND (non-derivative) exist for data licenses but not really for software licenses - -**Great resource for comparing software licenses**: [Joinup Licensing Assistant](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) -- Provides comments on licenses -- Easy to compare licenses ([example](https://joinup.ec.europa.eu/licence/compare/BSD-3-Clause;Apache-2.0)) -- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) -- Not biased by some company agenda - -If you would like to learn more about licenses, check out our slide deck: ["Software licensing -and open source explained with -cakes"](https://cicero.xyz/v3/remark/0.14.0/github.com/coderefinery/social-coding/main/licensing-and-cakes.md/). - - -## Exercise: Licensing situations - -````{exercise} Licensing-2: Consider some common licensing situations -1. What is the StackOverflow license for code you copy and paste? -2. A journal requests that you release your software during publication. You have - copied a portion of the code from another package, which you have forgotten. - Can you satisfy the journal's request? -3. You want to fix a bug in a project someone else has released, but there is no license. What risks are there? -4. How would you ask someone to add a license? -5. You incorporate MIT, GPL, and BSD3 licensed code into your project. What possible licenses can you pick for your project? -6. You do the same as above but add in another license that looks strong copyleft. What possible licenses can you use now? -7. Do licenses apply if you don't distribute your code? Why or why not? -8. Which licenses are most/least attractive for companies with proprietary software? - -```{solution} -1. As indicated [here](https://stackoverflow.com/help/licensing), all publicly accessible user contributions are licensed under [Creative Commons Attribution-ShareAlike](https://creativecommons.org/licenses/by-sa/4.0/) license. See Stackoverflow [Terms of service](https://stackoverflow.com/legal/terms-of-service/public#licensing) for more detailed information. -2. "Standard" licensing rules apply. So in this case, you would need to remove the portion of code you have copied from another package before being able to release your software. -3. By default you are no authorized to use the content of a repository when there is no license. And derivative work is also not possible by default. Other risks: it may not be clear whether you can use and distribute (publish) the bugfixed code. For the repo owners it may not be clear whether they can use and distributed the bugfixed code. However, the authors may have forgotten to add a license so we suggest you to contact the authors (e.g. make an issue) and ask whether they are willing to add a license. -4. As mentionned in 3., the easiest is to fill an issue and explain the reasons why you would like to use this software (or update it). -5. Combining software with different licenses can be tricky and it is important to understand compatibilities (or lack of compatibilities) of the various licenses. GPL license is the most protective (BSD and MIT are quite permissive) so for the resulting combined software you could use a GPL license. However, re-licensing may not be necessary. -6. Derivative work would need to be shared under this strong copyleft license (e.g. AGPL or GPL), unless the components are only plugins or libraries. -7. If you keep your code for yourself, you may think you do not need a license. However, remember that in most companies/universities, your employer is "owning" your work and when you leave you may not be allowed to "distribute your code to your future self". So the best is always to add a license! -8. The least attractive licenses for companies with proprietary software are licenses where you would need to keep an open license when creating derivative work. For instance GPL and and AGPL. The most attractive licenses are permissive licenses where they can reuse, modify and relicense with no conditions. For instance MIT, BSD and Apache License. -``` -```` - - -## When should I add a license? - -**Choose a license early in the project, even before you publish it**. Later in -the project it may become complicated to change it. Agreeing on a software -license does not mean that you have to make it open immediately. You can also -follow the **"open core" approach**: You don't have to open source all your -work. Core can be open and on a public branch. Unpublished code can be on a -private repository. - -However, we recommend to **work as if the code is public even though it still -may be private** (thanks to E. Glerean for this great suggestion): This is to -avoid surprises about code in the history with incompatible license years later -when you decide to open the project. - - -## How to add a license if your work is derivative work - -Your code is derivative work if you have started from an existing code and -made changes to it or if you incorporated an existing code into your code. - -If your code is derivative work, then **you need to check the license of the -original code**. Depending on the license, your choices might be limited. In -this case we recommend to use these two resources: -- [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) -- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) - -If the original code does not have a license, you may not be able to distribute your -derivative code. You can try to contact the authors and ask them to clarify -the license of their code. - -Practical steps for **incorporating something small into your own project** with a license -that allows you to do so (as -an example incorporating a function or two from another project): -- Create a `LICENSES/` folder in your project and "put the unmodified license text - (i.e., the license text template without any copyright notices) in your - `LICENSES/` folder" (). This - way if you reuse code from multiple projects, you can keep there multiple - license files. -- **Put the code that you incorporate into a separate file or separate files**. This makes - it later easier to see what was incorporated, and what was written from scratch. - On top of the file(s) which you have incorporated into your project add (and - adapt) the following header ([more examples](https://reuse.software/faq/)): - ```python - # SPDX-FileCopyrightText: 2023 Jane Doe - # - # SPDX-License-Identifier: MIT - ``` - The [REUSE](https://reuse.software/) initiative was started by the [Free - Software Foundation Europe](https://fsfe.org/) to make licensing of software - projects easier. It is OK if you prefer to not follow this strict format but - the advantage of following it is that the - [reuse-tool](https://github.com/fsfe/reuse-tool) makes it then easy to verify - and update license headers if you have many files from different sources. -- If it does not make sense to have several files in your project (e.g. when incorporating - something into a notebook), then add a note/comment - about the license and where the code came from on top of the function. -- Although it is not dictated by the license but it can still be nice to - acknowledge the incorporated functions/code in your README/documentation and to cite - their work if you publish a paper about your code. -- Some licenses are more permissive (you can keep your changes private) but some licenses - require you to publish the changes (share-alike). - -Practical steps for making **changes to an existing project** with a license -that allows you to do so: -- If the project is on GitHub or GitLab or similar, first fork the project - (copy it into your user space where you can make changes). -- For the BSD and MIT licenses you are not obliged to state your changes but it can - still be helpful for others if you do. You can state your changes in the - header of the files you have modified. It can be helpful to state - bigger-picture changes in the README file of the project. -- Some licenses are more permissive (you can keep your changes private) but some licenses - require you to publish the changes (share-alike). - - -### If your work is not derivative work - -If you have started "from scratch", and not used any existing code, or -incorporated existing code into your code, then you may consider your code to -be not derivative work. - -Before you may choose a license, clarify the following points with, for -example, your supervisor, collaborators, or principal investigator: -- Does your work contract, grant, or collaboration agreement dictate a - specific license? -- Is there an intent to commercialize the code? -- When there is unknown or mixed ownership: If there are multiple persons or - organizations as owners of the code, all must agree to the license. - -**Do not invent your own license**. Choose one of the standard licenses, otherwise -compatibility is not clear: - - [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) - - [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) - -Practical steps: -- Create a `LICENSES/` folder ([example](https://github.com/bast/runtest/tree/main/LICENSES)). -- Put the unmodified license text - (i.e., the license text template without any copyright notices) in plain - text format into the folder ([example](https://github.com/bast/runtest/tree/main/LICENSES)). Here are - the two above licenses in plain text: - [EUPL](https://joinup.ec.europa.eu/sites/default/files/custom-page/attachment/2020-03/EUPL-1.2%20EN.txt) - and [MIT](https://en.wikipedia.org/wiki/MIT_License#License_terms) (but the - latter contains a copyright notice which we rather want to have on top of - files). -- Add copyright and license information to each file following - which uses a standard format with - so-called [SPDX identifiers](https://spdx.org/licenses/). Example below - ([example](https://github.com/bast/runtest/blob/3b210d2e9bdbdc1903a1dab9da32e161d390092d/runtest/tuple_comparison.py#L1-L3)): - ```python - # SPDX-FileCopyrightText: 2023 Jane Doe - # - # SPDX-License-Identifier: EUPL-1.2 - ``` - The [REUSE](https://reuse.software/) initiative was started by the [Free - Software Foundation Europe](https://fsfe.org/) to make licensing of software - projects easier. It is OK if you prefer to not follow this strict format but - the advantage of following it is that the - [reuse-tool](https://github.com/fsfe/reuse-tool) makes it then easy to verify - and update license headers if you have many files from different sources. -- For really small projects with one or two files the above may seem excessive - and some projects choose to not have copyright information on top of their - files and they only have one `LICENSE` file and that is - OK for really small projects. - - - -```{admonition} Licensing code produced by generative AI systems - -With generative AI tools for coding such as GitHub copilot, Cursor, or even basic chat implementations (ChatGPT, Claude, Grok, ...) the responsibility fully lays on the person who is going to use (and publish) the generated code. You can never blame the autopilot or the company who invented it, only the driver (you!). - -There are various risks in using generative AI code (this is not a taxonomy). A few examples: - -- Risks for the derivative work: you think your code is doing what you asked, but you did not review it and your results are false -- Risks for the system in use: your generated code has software security issues, e.g. an import is a *typosquat* of an actual library (e.g. "microsoft" is spelled "rnicrosoft" and depending on the font you might totally miss it...) -- Risks related to licenses/IPR: you have generated code that is actually verbatim copy of fully copyrighted code, or code that requires a strict copyleft license. Plagiarism (ethics) also applies. - -If we focus on the last one, a recent paper ([ref](https://arxiv.org/html/2408.02487v1)) estimates that around 2% of AI generated code is "strikingly similar to existing open-source implementations". Generative AI tools are typically not able to provide an exact reference of where certain bits of generated code were copied from, so it is the responsibility of the researcher to verify that the produced code is citing and referencing the license of other published pieces of software. Possibly, future AI systems for code generation can be trained on code that share the same set of licenses (e.g. based only on MIT) to mitigate these risks. +* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. -``` +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: ---- +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | +:::{solution} +**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. -## Great resources - -- [Research institution policies to support research software (compiled by the Research Software Alliance)](https://www.researchsoft.org/software-policies/) -- Guide from the Aalto University in Finland: ["Opening your Software at Aalto University"](https://www.aalto.fi/en/open-science-and-research/opening-your-software-at-aalto-university) -- [Draft: Research software licensing guide](https://research-software.uit.no/blog/2023-software-licensing-guide/) -- [Joinup Licensing Assistant - Find and compare software licenses](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-find-and-compare-software-licenses) -- [Joinup Licensing Assistant - Compatibility Checker](https://joinup.ec.europa.eu/collection/eupl/solution/joinup-licensing-assistant/jla-compatibility-checker) -- [Social coding lesson material](https://coderefinery.github.io/social-coding/) by [CodeRefinery](https://coderefinery.org/) -- [Citation File Format (CFF)](https://citation-file-format.github.io/) -- [License Selector](https://ufal.github.io/public-license-selector/) -- [GitHub licensing guide](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/licensing-a-repository) -- [Choosing an open-source licence](https://www.software.ac.uk/resources/guides/choosing-open-source-licence) -- [Understanding Open Source and Free Software Licensing](http://www.oreilly.com/openbook/osfreesoft/) -- [Software Licenses in Plain English](https://tldrlegal.com) -- [Don's Bibliography of Ethical Source Reading and Resources](https://github.com/DEGoodmanWilson/Ethical-Resources) -- [Mikko Vรคlimรคki: The Rise of Open Source Licensing](http://lib.tkk.fi/Diss/2005/isbn9529187793/isbn9529187793.pdf) -- [Lawrence Rosen: Open Source Licensing](http://www.rosenlaw.com/oslbook.htm) -- [Aalto IPR Cheatsheet](https://users.aalto.fi/~darstr1/cheatsheets/ipr-cheatsheet.pdf) -- [Contributor License Agreements](https://jacobian.org/2009/sep/17/contributor-license-agreements/) -- [4OSS recommendations](https://softdev4research.github.io/recommendations/) -- [4OSS lesson](https://softdev4research.github.io/4OSS-lesson/) -- [Intellectual Property Rights (IPR), Licensing And Patents](http://oss-watch.ac.uk/resources/ipr) -- [Dispelling Open Source Confusion: An Introduction to Licenses](http://depth-first.com/articles/2006/12/29/dispelling-open-source-confusion-an-introduction-to-licenses/) -- (can send automatic pull request to your GitHub repo) -- -- -- Nadia Asparouhova (formerly Nadia Eghbal): "Working in Public: The Making and Maintenance of Open Source Software" (Stripe Press) -- [Open Source Guides](https://opensource.guide/) -- [The Architecture of Open Source Applications](http://aosabook.org) -- Christopher M. Kelty: ["Two Bits: The Cultural Significance of Free Software"](https://twobits.net/) (Duke University Press, 2008) -- [Open Source (Almost) Everything](http://tom.preston-werner.com/2011/11/22/open-source-everything.html) -- [99 ways to ruin an open source project](http://opensoul.org/99ways/) -- [Open Source Casebook](https://google.github.io/opencasebook/) - -```{keypoints} -- **You cannot ignore licensing**: default is "no one can make copies or - derivative works". -``` +* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. +* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` +* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. +* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. +::: +:::: + + +::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) +You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). + +* **Licensing Goal**: You want to publish your repository and need to select a license that complies with the inbound linking requirements of the GPL library. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Linking your code (statically or dynamically) with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. The strong copyleft obligation extends across the linking boundary. + +* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. You cannot license the overall project under a Permissive license (like MIT). +* **Selected Category**: **Copyleft / Reciprocal** (required by the linked GPL library). +* **JLA Expected Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` +* **Why**: The linked library's reciprocal license mandates that any distributed program depending on it must also provide source code access under compatible copyleft terms (`Copyleft/Share a.` and `Disclose source`). +* **User Obligation**: Users who distribute binaries or modified packages of your project must provide the full source code under the GPL-compatible copyleft license. +* **Mixing & Redistribution**: Anyone using or building upon your work must maintain the GPL-compatible copyleft license. If you want to avoid copyleft restrictions for your codebase, you must replace the GPL library dependency with a permissively licensed alternative (e.g., an MIT or BSD library). +::: +:::: + +::::{exercise} Scenario 6: Generating or assisting code using AI tools +You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. + +* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). + +* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. +* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). +* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. +* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). +* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. +* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. +::: +:::: + +::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) +You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` file) to make your research reproducible. The recipe contains text commands that pull a base image, install system packages (`apt-get`), clone code from GitHub, and download data. + +* **Licensing Goal**: You want **maximum adoption** for your build recipe and zero restrictions on who can use or modify your setup instructions. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images, packages, or repositories in build commands does not transfer third-party copyright onto your text file. + +* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions you write and can choose any license for your recipe file. +* **If Generated by AI**: Using AI tools (Copilot, ChatGPT) to generate or refactor a `Dockerfile` follows standard AI code rules. As long as you review, adapt, and configure the recipe for your project, you hold the copyright and retain total freedom over its license. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: The recipe file itself is source code. Referencing third-party packages in `RUN` or `FROM` steps is legally equivalent to writing an `import` statement or listing dependencies in `requirements.txt`. +* **User Obligation**: Users who download your recipe file must preserve your copyright notice. +* **Mixing & Redistribution**: Anyone can freely share or modify your `Dockerfile` or `.def` file under your chosen permissive license, regardless of whether the tools installed by the recipe are Permissive, Copyleft, or Proprietary. +::: +:::: + +::::{exercise} Scenario 8: Distributing a Built Container Image (Docker Hub or Apptainer .sif) +You build a complete container runtime image (as an Apptainer `.sif` file or an image pushed to Docker Hub/GitHub Container Registry). The compiled image contains a base Linux OS, installed system libraries, runtime dependencies, and your application code. + +* **Licensing Goal**: Fulfill legal obligations imposed by distributing a bundled, compiled binary filesystem image containing third-party works. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Unlike a text recipe file, a compiled container image (`.sif` or registry image) is a **bundle of third-party software works**. You do not hold exclusive copyright over the entire image filesystem. + +* **Outcome**: **Mandatory Compliance (Restricted Choice).** You cannot assign a single permissive license to the distributed image. Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. +* **Selected Category**: **Copyleft / Reciprocal** (if your application links against or incorporates Copyleft components inside the container). +* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` +* **Why (Linking vs. Aggregation)**: If your application links against or embeds a Strong Copyleft library (`GPL-3.0`) installed in the container, distributing that image triggers copyleft disclosure obligations for your compiled application. However, if GPL components in the image are merely independent system utilities or standalone tools, GPL's "mere aggregation" provisions applyโ€”the GPL license governs those specific tools, but does not extend to your independent application binaries. +* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including providing source access for any GPL components or linked works contained in the layers. +* **Mixing & Redistribution**: Downstream users who pull your image must abide by individual component licenses. To keep your application source code unencumbered, ensure your app links only against permissively licensed libraries inside the container layers. +::: +:::: + +::::{exercise} Scenario 9: Including AI prompt templates in LLM applications +You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). + +* **Licensing Goal**: You want **maximum adoption** for your application and want to ensure your prompt templates are legally covered under the same open-source license as your Python code. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Copyrightability depends on creative complexity. Simple, functional prompts lack the minimal threshold of creative human expression and carry no copyright. However, complex, highly structured prompt templates are legally classified as literary text assets and are fully protected by copyright. + +* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are treated like source code assets. Applying your overall repository license automatically covers these prompt files. +* **Simple vs. Engineered Prompts**: Short commands (e.g., *"Fix this Dockerfile"*) are uncopyrightable instructions. Complex system prompts, XML-formatted templates, or multi-step reasoning frameworks meet the threshold of creative human authorship. +* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Why**: Permissive open-source licenses cover software text assets, allowing downstream developers to incorporate, modify, and execute your prompt templates in their own AI pipelines. +* **User Obligation**: Standard attribution obligations apply. Downstream users who copy your prompt files must preserve your copyright notice and file headers (e.g., `# SPDX-License-Identifier: MIT`). +* **Mixing & Redistribution**: Downstream users can freely adapt your prompt templates or integrate them into closed commercial LLM applications, provided they maintain your original copyright attribution in the template files. +::: +:::: From b5b9b8990d653dcd5cb7941304b845da585f8ac7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 11 Sep 2026 19:22:13 +0200 Subject: [PATCH 35/99] Use to address @samumantha's suggestions --- content/index.rst | 4 ++-- content/software-licensing.md | 4 ++++ 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/content/index.rst b/content/index.rst index 4dd6ec5..cb019e3 100644 --- a/content/index.rst +++ b/content/index.rst @@ -40,7 +40,7 @@ navigating and deciding on licenses. :delim: ; 20 min ; :doc:`social-coding` - 90 min ; :doc:`software-licensing-eu` + 90 min ; :doc:`software-licensing` 20 min ; :doc:`software-citation` 10 min ; :doc:`sharing-data` @@ -51,7 +51,7 @@ navigating and deciding on licenses. :hidden: social-coding - software-licensing-eu + software-licensing software-citation sharing-data diff --git a/content/software-licensing.md b/content/software-licensing.md index 0572a31..1f9da59 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -56,6 +56,9 @@ Software development is an inherently cosmopolitan business. Research software e However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating in the EU or collaborating globally. +:::{dropdown} Deep Dive: Comparative Legal Mechanisms (US vs. EU vs. Asia) +:color: info + * **Code Adaptation / Refactoring** * **US Concept:** **Derivative Work** (broadly interpreted judicial doctrine). * **EU Concept:** **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). @@ -80,6 +83,7 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista * **Civil Law Alignment:** Legal frameworks in China, Japan, and South Korea mirror EU civil law rather than US common law, strictly protecting moral rights and requiring formal contract grants. * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. +::: ## Classification of licenses From f4e2fad16a1533b54b400b711507b0d7fbb458d2 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 11 Sep 2026 20:39:50 +0200 Subject: [PATCH 36/99] Change mermaid direction --- content/software-licensing.md | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 1f9da59..c9d0b85 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -88,7 +88,7 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista ## Classification of licenses ```{mermaid} - flowchart TB + flowchart LR subgraph box[ ] A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] @@ -108,8 +108,7 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista D --> D2["Sell copies as-is?
No!"] D --> D3["Embed in closed product & sell?
No!"] D --> D4["Can I change code?
No (Closed source)"] - subgraph osi["Open Source Initiative (OSI)"] - osi_H["๐Ÿ‘‰ Some exceptions exist"] + subgraph osi["OSI compatible"] B["Permissive
(MIT, BSD, Apache-2.0)"] C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] end @@ -119,13 +118,13 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; - classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; + classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; classDef box fill:#ffffff; class B1,B2,B3,B4,C1,C2 permissive; class C3,C4,D1,D2,D3,D4 proprietary; class box box; class A,B,C,D mains; - class osi_H,osi osiBox; + class osi osiBox; ``` ### Best Practice: In-File Identification using SPDX From 2a6fdb1be20359f9d43cf181353c0d58082a161d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 12:37:54 +0200 Subject: [PATCH 37/99] Add motivation --- content/software-licensing.md | 40 ++++++++++++++++++++++++++++++++++- 1 file changed, 39 insertions(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index c9d0b85..ed7fb50 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -17,7 +17,7 @@ This lesson is designed as practical educational material for researchers and re * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. * This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. -If you need formal guidance reference below and legal experts at your host institute could be of help: +If you need formal guidance references below and legal experts, especially if you have legal services at your host institute, could be of help: * [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) * [Compendium of U.S. Copyright Office Practices (3rd Ed.) โ€“ Chapter 700, Section 721: Computer Programs](https://www.copyright.gov/comp3/) @@ -27,6 +27,44 @@ If you need formal guidance reference below and legal experts at your host insti * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` +## Motivation + +```{mermaid} +flowchart TB + + subgraph box["CI/CD License Compliance Debugging Pipeline"] + A["Build Trigger: Push to my-analysis-tool"] --> B["Run Compliance Scanner"] + B --> C{"Check Inbound vs.
Outbound Terms"} + + C -->|"Your Target License: MIT (Permissive)
Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] + + D --> E{"Select Patch Option"} + + E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] + E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] + E -->|"Option C: Rewrite 15-line algorithm from scratch"| H["โœ… BUILD PASS
New code expression frees your target license"] + P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] + CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)
'Must share changes under same terms'"] + end + + P -.->|"Applies to Your Target License"| C + CL -.->|"Applies to Pasted Snippet"| C + + classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; + + class P,G,H pass; + class CL copyleft; + class D,F fail; + class A,B,C,E neutral; + class box box_fill; + +``` + + ## Introduction In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: From 90bc43cd7e063a5e22299bf38c12766d35d70ec1 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 17:19:55 +0200 Subject: [PATCH 38/99] Update motivation to mention unlicensed --- content/software-licensing.md | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index ed7fb50..99becdd 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -30,6 +30,7 @@ If you need formal guidance references below and legal experts, especially if yo ## Motivation ```{mermaid} + flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] @@ -42,28 +43,31 @@ flowchart TB E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] - E -->|"Option C: Rewrite 15-line algorithm from scratch"| H["โœ… BUILD PASS
New code expression frees your target license"] - P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] + E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] + E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'
Nobody can legally run, modify, or reuse your tool"] + + P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)
'Must share changes under same terms'"] end - P -.->|"Applies to Your Target License"| C - CL -.->|"Applies to Pasted Snippet"| C + P -.->|"I want to use"| C + CL -.->|"Pasted code snippet uses"| C classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; class P,G,H pass; class CL copyleft; class D,F fail; + class I warning; class A,B,C,E neutral; - class box box_fill; - -``` + class box box_fill; +``` ## Introduction From 670bbdbc891d362f0ff06c54ab8096ef6f915659 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 18:42:18 +0200 Subject: [PATCH 39/99] Update introduciton with a mermaid to show the options --- content/software-licensing.md | 35 +++++++++++++++++++++++++++++------ 1 file changed, 29 insertions(+), 6 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 99becdd..a90e6d8 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -30,7 +30,7 @@ If you need formal guidance references below and legal experts, especially if yo ## Motivation ```{mermaid} - +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] @@ -69,14 +69,37 @@ flowchart TB ``` -## Introduction +## Introduction: What is a Software License? + +In Option D of our debugging pipeline, deleting the `LICENSE` file tricked the automated scanner into passing, but created a major distribution trap. Under copyright law worldwide, software without a license automatically defaults to **"All Rights Reserved"**โ€”meaning nobody else has the legal right to run, modify, or cite your code. -In the European Union, software protection is governed by copyright law, which makes a sharp distinction between what is protected and what is not: +A **software license** is an explicit permission grant that overrides this statutory default, defining exactly how downstream researchers can reuse your work. - * Protected: The specific source code text, expression, binaries, and preparatory design work. - * Not protected: Underlying mathematical algorithms, ideas, programming logic, and interface principles. +```{mermaid} +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +flowchart TD + A["Your Research Codebase
(Source code, container definition files, prompt templates)"] -->|"Option D: No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Nobody can legally run, modify, or share"] + + A -->|"Attach Software License
(Explicit Permission Grant)"| C{"Select License Flavor"} + + C -->|"Permissive
(MIT, Apache-2.0, 0BSD)"| D["Maximum Reuse Freedom
โœ… Anyone can run, modify, embed in commercial tools, or re-license"] + C -->|"Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)"| E["Reciprocal Protection
โœ… Free to run & modify, but distributed changes must stay open source"] + C -->|"Proprietary / Closed Source
(Commercial EULA)"| F["Closed Source / Restricted
๐Ÿšซ Flavour not discussed in this lesson"] + + classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef openState fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleftState fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef closedState fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#6c757d; + classDef codeState fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + + class B defaultState; + class D openState; + class E copyleftState; + class F closedState; + class A,C codeState; + +``` -Because copyright only protects the expression and not the underlying ideas, developers use licenses to define how that expression can be legally reused. ### Scope of this Lesson: What Counts as "Software"? From 209e78607e4dc756e98ea5ea187c4da9720f7dcd Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 19:23:31 +0200 Subject: [PATCH 40/99] expand what can be licensed --- content/software-licensing.md | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index a90e6d8..9b9bee3 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -101,11 +101,22 @@ flowchart TD ``` +### Copyright Foundation: Expression vs. Ideas + +To understand why licenses are required, you must understand how copyright law treats software. Under EU statutory law (Directive 2009/24/EC) and international treaties, software is protected under copyright as a **literary work**. + +However, copyright law draws a sharp, fundamental distinction between what is protected and what is free for anyone to use: + +* **Protected (Code Expression)**: The specific source code text, variable names, binaries, container build recipes, prompt engineering text, and preparatory design documents. +* **Not Protected (Underlying Ideas)**: Mathematical algorithms, scientific models, programming logic, data structures, and interface principles. + +Because copyright restricts only the *creative human expression* and not the underlying *ideas or algorithms*, developers use open-source licenses to define the exact terms under which that expression can be legally shared and modified. + ### Scope of this Lesson: What Counts as "Software"? -Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is commonly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. Under EU statutory law (Directive 2009/24/EC), computer programsโ€”including their preparatory design materialโ€”are protected under copyright as literary works. +Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is broadly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. -Because copyright protection hinges on functional execution combined with creative human expression, this lesson covers the full spectrum of modern research software assets: +Because modern research software extends beyond simple Python scripts, this lesson applies copyright and licensing principles across six core research software assets: * **Source Code**: Original algorithms written from scratch or implemented from scientific papers. * **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. @@ -114,7 +125,6 @@ Because copyright protection hinges on functional execution combined with creati * **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. - ## Global Context: Software Engineering Across Legal Borders Software development is an inherently cosmopolitan business. Research software engineers routinely collaborate across continents, fetch dependencies from global registries, and commit code to international repositories. From a753a17bab88eefa5b98d0ee2df83cf4abebff85 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 22:42:28 +0200 Subject: [PATCH 41/99] emphasize examples --- content/software-licensing.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 9b9bee3..c055b92 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -69,9 +69,10 @@ flowchart TB ``` + ## Introduction: What is a Software License? -In Option D of our debugging pipeline, deleting the `LICENSE` file tricked the automated scanner into passing, but created a major distribution trap. Under copyright law worldwide, software without a license automatically defaults to **"All Rights Reserved"**โ€”meaning nobody else has the legal right to run, modify, or cite your code. +In {bdg-warning}`Option D` of our debugging pipeline, deleting the `LICENSE` file tricked the automated scanner into passing, but created a major distribution trap. Under copyright law worldwide, software without a license automatically defaults to **"All Rights Reserved"**: meaning nobody else has the legal right to run, modify, or cite your code. A **software license** is an explicit permission grant that overrides this statutory default, defining exactly how downstream researchers can reuse your work. @@ -120,7 +121,7 @@ Because modern research software extends beyond simple Python scripts, this less * **Source Code**: Original algorithms written from scratch or implemented from scientific papers. * **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. -* **Container Recipes**: Infrastructure as Code text files (`Dockerfile`, Apptainer `.def`). +* **Infrastructure as Code**: Ansible playbooks,Terraform configurations,container Recipes (`Dockerfile`, Apptainer `.def`). * **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). * **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. From 89a496051a6401df28255663c2d0cb84c65f554d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 22:47:51 +0200 Subject: [PATCH 42/99] Move best practices to the end --- content/software-licensing.md | 39 +++++++++++++++++++---------------- 1 file changed, 21 insertions(+), 18 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index c055b92..582344f 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -203,24 +203,6 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista class osi osiBox; ``` -### Best Practice: In-File Identification using SPDX - -Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. - -Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: - - In a container recipe - -```dockerfile -# SPDX-License-Identifier: MIT -FROM ubuntu:24.04 -``` - - In a python script -```python -# SPDX-License-Identifier: 0BSD -import numpy as np -``` - ---- ## How to select a license @@ -459,3 +441,24 @@ You develop a research software pipeline that uses Large Language Models (LLMs) * **Mixing & Redistribution**: Downstream users can freely adapt your prompt templates or integrate them into closed commercial LLM applications, provided they maintain your original copyright attribution in the template files. ::: :::: + +### Best Practice: + +#### In-File Identification using SPDX + +Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. + +Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: + - In a container recipe + +```dockerfile +# SPDX-License-Identifier: MIT +FROM ubuntu:24.04 +``` + - In a python script +```python +# SPDX-License-Identifier: 0BSD +import numpy as np +``` + +#### How to include a license file From 8b76c6244f2a27e4c6d084d43490240824808000 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 23:07:19 +0200 Subject: [PATCH 43/99] Group excersises to groups --- content/software-licensing.md | 86 ++++++++++++++++++++++------------- 1 file changed, 55 insertions(+), 31 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 582344f..e5b06f3 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -204,13 +204,21 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista ``` -## How to select a license -Lets go through some examples on how to use the European Commission's Joinup Licensing Assistant (JLA) to select licenses. The JLA groups license clauses into four categories that map to the visual diagram above: - * ๐ŸŸข Can (Rights): What you are allowed to do (e.g., Run, Modify). Matches the "Yes!" bubbles in the diagram. - * โšช Must (Obligations): What you are required to do (e.g., Include Copyright for Permissive, or Share Alike for Copyleft). Maps to "Must changes stay open?". - * ๐Ÿ”ต Compatible: What context the code is used in (e.g., For software). - * ๐ŸŸก Support: External verification (e.g., OSI approved). Maps to the blue dashed box. +## Selecting Compliant Licenses + +When applying the European Commission's Joinup Licensing Assistant (JLA), license selection depends on your specific RSE workflow. The JLA groups license criteria into four categories: + +* ๐ŸŸข **Can (Rights)**: Permissions granted (Run, Modify, Distribute). +* โšช **Must (Obligations)**: Mandatory requirements (Include Copyright, Share Alike/Copyleft, Disclose Source). +* ๐Ÿ”ต **Compatible**: Application domain (Software, Data, Documentation). +* ๐ŸŸก **Support**: Verification status (OSI Approved). + +--- + +### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms + +When writing original code or implementing published mathematical logic, you control 100% of your copyright. ::::{exercise} Scenario 1: Own algorithm with external dependencies You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). @@ -262,6 +270,12 @@ You read a published scientific paper or technical specification, understand the ::: :::: +--- + +### Module 2: The Dependency Minefield โ€“ Inbound Code & Linking + +Embedding third-party source code snippets or linking against strong copyleft C/Fortran libraries introduces compliance boundaries that restrict your repository choices. + ::::{exercise} Scenario 3: Directly embedding third-party Permissive source code You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. @@ -287,7 +301,6 @@ You find a useful helper module online licensed under a **Permissive license** ( ::: :::: - ::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. @@ -313,7 +326,6 @@ You find a useful utility function or module online licensed under a **Copyleft ::: :::: - ::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). @@ -339,31 +351,11 @@ You write your own original code from scratch, but your program includes or link ::: :::: -::::{exercise} Scenario 6: Generating or assisting code using AI tools -You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. - -* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. +--- -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): +### Module 3: Reproducible Infrastructure โ€“ Build Recipes vs. Binary Bundles -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | - -:::{solution} -**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). - -* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. -* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). -* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. -* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). -* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. -* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. -::: -:::: +A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). ::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` file) to make your research reproducible. The recipe contains text commands that pull a base image, install system packages (`apt-get`), clone code from GitHub, and download data. @@ -416,6 +408,38 @@ You build a complete container runtime image (as an Apptainer `.sif` file or an ::: :::: +--- + +### Module 4: Modern AI Workflows โ€“ Assisted Code & Prompt Engineering + +AI tools introduce distinct licensing considerations depending on whether you are integrating AI-generated code snippets or authoring complex system prompt templates. + +::::{exercise} Scenario 6: Generating or assisting code using AI tools +You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. + +* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. + +[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): + +| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | +| :--- | :--- | :--- | :--- | +| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | +| โ˜‘ Modify/merge | | | | +| โ˜‘ Distribute | | | | + +:::{solution} +**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). + +* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. +* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). +* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. +* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). +* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). +* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. +* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. +::: +:::: + ::::{exercise} Scenario 9: Including AI prompt templates in LLM applications You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). From 6df2989cc111171883a0bf6be4a6fd319a0d4e31 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 14 Sep 2026 23:35:09 +0200 Subject: [PATCH 44/99] Move the JLA tables out excercises --- content/software-licensing.md | 244 +++++++++++----------------------- 1 file changed, 81 insertions(+), 163 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index e5b06f3..481083b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -204,15 +204,23 @@ However, modern developers face a subtle trap: **AI legal bias**. Coding assista ``` - ## Selecting Compliant Licenses -When applying the European Commission's Joinup Licensing Assistant (JLA), license selection depends on your specific RSE workflow. The JLA groups license criteria into four categories: +When using the European Commission's [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses), license selection depends on your RSE workflow. The JLA groups criteria into four categories: **๐ŸŸข Can** (Permissions), **โšช Must** (Obligations), **๐Ÿ”ต Compatible** (Domain), and **๐ŸŸก Support** (OSI Approval). + +### JLA Decision Matrix at a Glance -* ๐ŸŸข **Can (Rights)**: Permissions granted (Run, Modify, Distribute). -* โšช **Must (Obligations)**: Mandatory requirements (Include Copyright, Share Alike/Copyleft, Disclose Source). -* ๐Ÿ”ต **Compatible**: Application domain (Software, Data, Documentation). -* ๐ŸŸก **Support**: Verification status (OSI Approved). +| Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | +| :--- | :--- | :--- | :--- | +| **1. Own Code** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| **2. Math Implementation** | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| **3. Embed Permissive** | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | +| **4. Embed Copyleft** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | +| **5. Link GPL Library** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | +| **6. AI-Assisted Code** | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | +| **7. Container Recipe** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | +| **8. Built Image** | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | +| **9. Prompt Template** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | --- @@ -221,52 +229,34 @@ When applying the European Commission's Joinup Licensing Assistant (JLA), licens When writing original code or implementing published mathematical logic, you control 100% of your copyright. ::::{exercise} Scenario 1: Own algorithm with external dependencies -You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`, or dynamic linking flags). +You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). * **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | +* **JLA Filter Focus**: Select ๐ŸŸข `Commercial use`, `Modify`, `Distribute` + โšช `Incl. Copyright` + ๐ŸŸก `OSI approved`. :::{solution} **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. * **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. * **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: The filters select licenses granting maximum reuse while requiring only basic copyright attribution (`Incl. Copyright`). -* **User Obligation**: Downstream users must comply with individual external package licenses when fetching, compiling, or running them. -* **Mixing & Redistribution**: Anyone can freely mix, embed, or redistribute your source code. If a user compiles and distributes a combined **binary** that dynamically links to a copyleft shared library (e.g., GPL `.so`), their *distributed compiled binary* must comply with copyleft obligations, but your upstream source repository remains unaffected under your chosen permissive license. +* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **User Obligation**: Downstream users must comply with individual external package licenses when fetching or running dependencies. ::: :::: ::::{exercise} Scenario 2: Implementing an algorithm from a paper -You read a published scientific paper or technical specification, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. - -* **Licensing Goal**: You want **reciprocal protection** anyone can use your implementation, but any downstream modifications distributed by others must remain open source. +You read a published scientific paper, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: You want **reciprocal protection**โ€”anyone can use your code, but downstream modifications distributed by others must remain open source. +* **JLA Filter Focus**: Add โšช **Must** toggles: `Copyleft/Share a.` + `Disclose source`. :::{solution} -**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new, independent copyright. +**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new copyright. -* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation and can choose any open-source license. +* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation. * **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -* **Why**: Adding **`Copyleft/Share a.`** and **`Disclose source`** under the **Must** column isolates reciprocal terms while leaving all other baseline criteria identical. -* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under the same copyleft terms. -* **Mixing & Redistribution**: Anyone can use and modify your code. However, if a third party integrates your copyleft implementation into their software and distributes the combined product, their whole application must be released under a compatible open-source copyleft license. +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` +* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under matching copyleft terms. ::: :::: @@ -274,80 +264,51 @@ You read a published scientific paper or technical specification, understand the ### Module 2: The Dependency Minefield โ€“ Inbound Code & Linking -Embedding third-party source code snippets or linking against strong copyleft C/Fortran libraries introduces compliance boundaries that restrict your repository choices. +Embedding third-party source code snippets or linking against strong copyleft libraries introduces legal boundaries that restrict your repository choices. ::::{exercise} Scenario 3: Directly embedding third-party Permissive source code -You find a useful helper module online licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause). You copy and paste this code directly into your repository to build upon it. - -* **Licensing Goal**: You want to know if including permissive third-party code limits your overall repository license choices (e.g., if you prefer a Copyleft license like EUPL-1.2 or GPL-3.0). +You copy and paste a helper module licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause) directly into your repository. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example selecting Copyleft): - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Know if including permissive third-party code limits your overall repository license choices. +* **JLA Filter Focus**: Baseline ๐ŸŸข `Commercial use` + โšช `Incl. Copyright` (Permissive code leaves all target options open). :::{solution} -**Legal Reality**: Permissive licenses (MIT, BSD) grant broad rights to combine, modify, and re-license derivative works under different terms, provided you preserve the original author's copyright notice and license text in the copied files. - -* **Outcome**: **Full Flexibility.** Unlike inbound Copyleft (Scenario 4), embedding Permissive code does not force a specific license on your project. You can license your combined repository as Permissive *or* Copyleft. -* **Selected Category**: **Copyleft** (or Permissive, depending on your intent). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` (or `MIT`, `Apache-2.0` if Permissive goal). -* **Why**: Permissive inbound code is compatible with almost all OSI-approved software licenses. -* **User Obligation**: You must retain the original copyright notice and MIT/BSD license text within the specific files or NOTICE file where the copied code resides. -* **Mixing & Redistribution**: Downstream users follow your repository's overall license terms, but the original permissive author's attribution notice must remain intact inside the codebase. +**Legal Reality**: Permissive licenses grant broad rights to combine, modify, and re-license derivative works, provided you preserve the original author's copyright notice. + +* **Outcome**: **Full Flexibility.** Embedding Permissive code does not force a specific license on your project. You can choose Permissive *or* Copyleft. +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `MIT`, `Apache-2.0` +* **User Obligation**: Retain the original copyright notice and MIT/BSD license text within the specific files where the copied code resides. ::: :::: ::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code -You find a useful utility function or module online licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2). You copy and paste this source code directly into your repository files and extend it to fit your project. +You copy and paste a utility function licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2) directly into your repository files. * **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | +* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` is **mandated** by inbound code. :::{solution} -**Legal Reality**: Unlike referencing external dependencies or writing code from scratch, pasting third-party source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the entire codebase. - -* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (e.g., MIT) or keep the repository proprietary. You must choose a copyleft license compatible with the inbound code. -* **Selected Category**: **Copyleft / Reciprocal** (mandated by the inbound license's copyleft clause). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why**: Inbound copyleft terms mandate that any derivative work distributed as a whole must inherit reciprocal sharing obligations (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Anyone distributing your project must provide access to the full source code (including your modifications) under the matching copyleft terms. -* **Mixing & Redistribution**: Downstream users receive full copyleft freedoms. You cannot re-license your combined repository under a permissive license later unless you completely strip out or rewrite the third-party copyleft code from scratch. +**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the overall codebase. + +* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. +* **Selected Category**: **Copyleft / Reciprocal** +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0` +* **User Obligation**: Anyone distributing your project must provide access to the full source code under matching copyleft terms. ::: :::: ::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) -You write your own original code from scratch, but your program includes or links against a third-party scientific library licensed under a **Strong Copyleft license** (such as GPL-3.0). +You write your code from scratch, but your program links (statically or dynamically) against a scientific library licensed under **GPL-3.0**. -* **Licensing Goal**: You want to publish your repository and need to select a license that complies with the inbound linking requirements of the GPL library. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Select a license compliant with the inbound linking requirements of the GPL library. +* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` + `Disclose source` (Required across linking boundaries). :::{solution} -**Legal Reality**: Linking your code (statically or dynamically) with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. The strong copyleft obligation extends across the linking boundary. - -* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. You cannot license the overall project under a Permissive license (like MIT). -* **Selected Category**: **Copyleft / Reciprocal** (required by the linked GPL library). -* **JLA Expected Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` -* **Why**: The linked library's reciprocal license mandates that any distributed program depending on it must also provide source code access under compatible copyleft terms (`Copyleft/Share a.` and `Disclose source`). -* **User Obligation**: Users who distribute binaries or modified packages of your project must provide the full source code under the GPL-compatible copyleft license. -* **Mixing & Redistribution**: Anyone using or building upon your work must maintain the GPL-compatible copyleft license. If you want to avoid copyleft restrictions for your codebase, you must replace the GPL library dependency with a permissively licensed alternative (e.g., an MIT or BSD library). +**Legal Reality**: Linking your code with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. + +* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. +* **JLA Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` +* **User Obligation**: Anyone distributing compiled binaries must provide the full application source code under GPL-compatible copyleft terms. ::: :::: @@ -358,53 +319,32 @@ You write your own original code from scratch, but your program includes or link A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). ::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) -You write or generate a container build recipe (`Dockerfile` or Apptainer `.def` file) to make your research reproducible. The recipe contains text commands that pull a base image, install system packages (`apt-get`), clone code from GitHub, and download data. - -* **Licensing Goal**: You want **maximum adoption** for your build recipe and zero restrictions on who can use or modify your setup instructions. +You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Maximum adoption for your build instructions with zero restrictions. +* **JLA Filter Focus**: Treat as original source code ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. :::{solution} -**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images, packages, or repositories in build commands does not transfer third-party copyright onto your text file. +**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images or packages in commands does not transfer third-party copyright onto your text file. -* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions you write and can choose any license for your recipe file. -* **If Generated by AI**: Using AI tools (Copilot, ChatGPT) to generate or refactor a `Dockerfile` follows standard AI code rules. As long as you review, adapt, and configure the recipe for your project, you hold the copyright and retain total freedom over its license. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: The recipe file itself is source code. Referencing third-party packages in `RUN` or `FROM` steps is legally equivalent to writing an `import` statement or listing dependencies in `requirements.txt`. -* **User Obligation**: Users who download your recipe file must preserve your copyright notice. -* **Mixing & Redistribution**: Anyone can freely share or modify your `Dockerfile` or `.def` file under your chosen permissive license, regardless of whether the tools installed by the recipe are Permissive, Copyleft, or Proprietary. +* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions and can choose any license for your recipe file. +* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **User Obligation**: Users downloading your recipe file must preserve your copyright notice. ::: :::: ::::{exercise} Scenario 8: Distributing a Built Container Image (Docker Hub or Apptainer .sif) -You build a complete container runtime image (as an Apptainer `.sif` file or an image pushed to Docker Hub/GitHub Container Registry). The compiled image contains a base Linux OS, installed system libraries, runtime dependencies, and your application code. - -* **Licensing Goal**: Fulfill legal obligations imposed by distributing a bundled, compiled binary filesystem image containing third-party works. +You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Copyleft/Share a. | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | โ˜‘ Disclose source | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Comply with legal obligations when distributing a bundled binary filesystem image. +* **JLA Filter Focus**: N/A (Cannot apply a single JLA license filter to a multi-work binary bundle). :::{solution} -**Legal Reality**: Unlike a text recipe file, a compiled container image (`.sif` or registry image) is a **bundle of third-party software works**. You do not hold exclusive copyright over the entire image filesystem. - -* **Outcome**: **Mandatory Compliance (Restricted Choice).** You cannot assign a single permissive license to the distributed image. Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Selected Category**: **Copyleft / Reciprocal** (if your application links against or incorporates Copyleft components inside the container). -* **JLA Expected Matches**: `EUPL-1.2`, `GPL-3.0` -* **Why (Linking vs. Aggregation)**: If your application links against or embeds a Strong Copyleft library (`GPL-3.0`) installed in the container, distributing that image triggers copyleft disclosure obligations for your compiled application. However, if GPL components in the image are merely independent system utilities or standalone tools, GPL's "mere aggregation" provisions applyโ€”the GPL license governs those specific tools, but does not extend to your independent application binaries. -* **User Obligation**: Anyone distributing the built image file must ensure compliance with all third-party licenses inside the container, including providing source access for any GPL components or linked works contained in the layers. -* **Mixing & Redistribution**: Downstream users who pull your image must abide by individual component licenses. To keep your application source code unencumbered, ensure your app links only against permissively licensed libraries inside the container layers. +**Legal Reality**: Unlike a text recipe file, a compiled container image is a **bundle of separate third-party software works**. You do not hold exclusive copyright over the entire image filesystem. + +* **Outcome**: **Mandatory Multi-License Compliance.** Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. +* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, "mere aggregation" applies. +* **User Obligation**: Ensure compliance with all third-party licenses bundled inside the container layers. ::: :::: @@ -412,57 +352,35 @@ You build a complete container runtime image (as an Apptainer `.sif` file or an ### Module 4: Modern AI Workflows โ€“ Assisted Code & Prompt Engineering -AI tools introduce distinct licensing considerations depending on whether you are integrating AI-generated code snippets or authoring complex system prompt templates. +AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. ::::{exercise} Scenario 6: Generating or assisting code using AI tools -You write software using AI coding assistants (e.g., GitHub Copilot, ChatGPT) to generate functions, boilerplate, or refactor algorithms. Your repository consists of a mix of human-authored code and AI-generated outputs. - -* **Licensing Goal**: You want **maximum adoption** (or any open-source model) and need to know if using AI tools restricts your choice of open-source license. +You write software using AI coding assistants (ChatGPT, Copilot) to generate functions, boilerplate, or refactor algorithms. -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide (example using Permissive selection): - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Determine if using AI coding tools restricts your open-source license choices. +* **JLA Filter Focus**: Driven by human author intent (e.g., ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`). :::{solution} -**Legal Reality**: Under EU copyright law and international consensus, **pure AI-generated outputs lacking human authorship are generally ineligible for copyright protection**. However, when you assemble, refine, and integrate AI code into an overarching software project through creative human effort, you hold copyright over the resulting human-authored work (provided the AI tool did not reproduce substantial copyrighted third-party snippets verbatim). - -* **How Much AI Assistance Is Allowed**: There is no fixed percentage threshold. If a legal dispute arises, courts evaluate **Human Authorship and Creative Control**. Using AI as a boilerplate code generator, advanced autocomplete, or research assistant where you actively guide, review, modify, and structure the code preserves your copyright ownership. Conversely, simply pressing a button to generate an entire project without human creative intervention yields uncopyrightable output. -* **How to Check for Copyrighted Material**: Combine manual codebase searches (e.g., GitHub Code Search), built-in AI tool filters (such as *Block suggestions matching public code* in GitHub Copilot), and automated open-source license scanners (like FOSSology or Snyk). -* **Outcome**: **Fully Permissible.** The use of AI tools does not force a specific open-source license onto your repository. You retain the choice between Permissive or Copyleft based on your strategic goals. -* **Selected Category**: **Permissive** (or Copyleft, determined by author intent rather than the AI tool). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` (or `EUPL-1.2`, `GPL-3.0` if your intent is Copyleft). -* **User Obligation**: Standard obligations apply based on the license you choose to attach to your human-authored codebase. -* **Mixing & Redistribution**: Anyone can use, modify, or redistribute your repository under your chosen license. Downstream users are bound by your overall repository license terms, while the standalone, raw unedited AI snippets themselves remain ineligible for copyright protection. +**Legal Reality**: Pure AI outputs lacking human authorship are ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. + +* **Outcome**: **Fully Permissible.** Using AI tools does not force a specific open-source license onto your repository. +* **JLA Matches**: `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` (Author choice). +* **User Obligation**: Standard obligations apply based on the license you choose for your human-authored codebase. ::: :::: ::::{exercise} Scenario 9: Including AI prompt templates in LLM applications -You develop a research software pipeline that uses Large Language Models (LLMs) for automated data extraction. Your repository contains Python scripts alongside a `prompts/` directory containing both short functional prompts (e.g., *"Extract keywords from this paper"*) and complex, 500-word structured prompt templates (e.g., system prompts, JSON schemas, and chain-of-thought frameworks). +Your repository contains Python scripts alongside complex, 500-word structured prompt templates (system prompts, XML schemas, reasoning frameworks). -* **Licensing Goal**: You want **maximum adoption** for your application and want to ensure your prompt templates are legally covered under the same open-source license as your Python code. - -[Licensing Assistant](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) selection guide: - -| ๐ŸŸข **Can** | โšช **Must** | ๐Ÿ”ต **Compatible** | ๐ŸŸก **Support** | -| :--- | :--- | :--- | :--- | -| โ˜‘ Commercial use | โ˜‘ Incl. Copyright | โ˜‘ For software | โ˜‘ OSI approved | -| โ˜‘ Modify/merge | | | | -| โ˜‘ Distribute | | | | +* **Licensing Goal**: Ensure prompt templates are legally covered under the same open-source license as your code. +* **JLA Filter Focus**: Treat engineered prompts as code assets: ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. :::{solution} -**Legal Reality**: Copyrightability depends on creative complexity. Simple, functional prompts lack the minimal threshold of creative human expression and carry no copyright. However, complex, highly structured prompt templates are legally classified as literary text assets and are fully protected by copyright. +**Legal Reality**: Short functional prompts carry no copyright. However, complex, highly structured prompt templates meet the threshold of creative human expression and are legally protected as literary text assets. -* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are treated like source code assets. Applying your overall repository license automatically covers these prompt files. -* **Simple vs. Engineered Prompts**: Short commands (e.g., *"Fix this Dockerfile"*) are uncopyrightable instructions. Complex system prompts, XML-formatted templates, or multi-step reasoning frameworks meet the threshold of creative human authorship. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Expected Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Why**: Permissive open-source licenses cover software text assets, allowing downstream developers to incorporate, modify, and execute your prompt templates in their own AI pipelines. -* **User Obligation**: Standard attribution obligations apply. Downstream users who copy your prompt files must preserve your copyright notice and file headers (e.g., `# SPDX-License-Identifier: MIT`). -* **Mixing & Redistribution**: Downstream users can freely adapt your prompt templates or integrate them into closed commercial LLM applications, provided they maintain your original copyright attribution in the template files. +* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are covered under your overall repository license. +* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **User Obligation**: Downstream users who copy your prompt files must preserve your copyright notice and file headers (`# SPDX-License-Identifier: MIT`). ::: :::: From 75601de09506093110a6465705b205e812b28ac0 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Tue, 15 Sep 2026 00:17:36 +0200 Subject: [PATCH 45/99] intergrate the global perspective to excersises --- content/software-licensing.md | 51 ++++++++++++++++++++++++++++------- 1 file changed, 42 insertions(+), 9 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 481083b..3df3047 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -126,11 +126,11 @@ Because modern research software extends beyond simple Python scripts, this less * **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. -## Global Context: Software Engineering Across Legal Borders +## Global Context & AI Legal Bias -Software development is an inherently cosmopolitan business. Research software engineers routinely collaborate across continents, fetch dependencies from global registries, and commit code to international repositories. +Software development is inherently cosmopolitan: research software engineers routinely collaborate across legal borders, fetch dependencies from global registries, and commit code to international repositories. -However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating in the EU or collaborating globally. +However, modern developers face a subtle trap: AI legal bias. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to US common law concepts ("Fair Use", "Work Made for Hire", "Derivative Works"). Relying blindly on AI advice can create legal blind spots when operating under EU statutory frameworks or collaborating globally. :::{dropdown} Deep Dive: Comparative Legal Mechanisms (US vs. EU vs. Asia) :color: info @@ -224,6 +224,34 @@ When using the European Commission's [Joinup Licensing Assistant (JLA)](https:// --- +## Global Context: Software Engineering Across Legal Borders + +Software development is inherently cosmopolitan: research software engineers routinely collaborate across legal borders, fetch dependencies from global registries, and commit code to international repositories. + +However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating under EU statutory frameworks or collaborating globally. + +--- + +## Selecting Compliant Licenses + +When using the European Commission's [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses), license selection depends on your RSE workflow. The JLA groups criteria into four categories: **๐ŸŸข Can** (Permissions), **โšช Must** (Obligations), **๐Ÿ”ต Compatible** (Domain), and **๐ŸŸก Support** (OSI Approval). + +### JLA Decision Matrix at a Glance + +| Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | +| :--- | :--- | :--- | :--- | +| **1. Own Code** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| **2. Math Implementation** | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| **3. Embed Permissive** | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | +| **4. Embed Copyleft** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | +| **5. Link GPL Library** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | +| **6. Container Recipe** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | +| **7. Built Image** | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | +| **8. AI-Assisted Code** | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | +| **9. Prompt Template** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | + +--- + ### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms When writing original code or implementing published mathematical logic, you control 100% of your copyright. @@ -241,6 +269,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your * **Selected Category**: **Permissive** (driven by your goal of maximum adoption). * **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **User Obligation**: Downstream users must comply with individual external package licenses when fetching or running dependencies. +* **Public Domain vs. Permissive Licenses**: Civil law jurisdictions (EU, China, Japan, South Korea) do not recognize total waivers of moral rights (e.g., your right to attribution as an author). Avoid informal "Public Domain" claims; always use standard permissive open-source licenses (`MIT`, `0BSD`, `Apache-2.0`) to grant legal permissions safely worldwide. ::: :::: @@ -288,8 +317,9 @@ You copy and paste a utility function licensed under a **Copyleft / Reciprocal l * **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` is **mandated** by inbound code. :::{solution} -**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined (derivative) work. You do not hold exclusive copyright over the overall codebase. +**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined work. You do not hold exclusive copyright over the overall codebase. +* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *"Derivative Works"*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. * **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. * **Selected Category**: **Copyleft / Reciprocal** * **JLA Matches**: `EUPL-1.2`, `GPL-3.0` @@ -318,7 +348,7 @@ You write your code from scratch, but your program links (statically or dynamica A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). -::::{exercise} Scenario 7: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) +::::{exercise} Scenario 6: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. * **Licensing Goal**: Maximum adoption for your build instructions with zero restrictions. @@ -333,7 +363,7 @@ You write a container build recipe (`Dockerfile` or Apptainer `.def` file) conta ::: :::: -::::{exercise} Scenario 8: Distributing a Built Container Image (Docker Hub or Apptainer .sif) +::::{exercise} Scenario 7: Distributing a Built Container Image (Docker Hub or Apptainer .sif) You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. * **Licensing Goal**: Comply with legal obligations when distributing a bundled binary filesystem image. @@ -354,15 +384,16 @@ You build and publish a complete container runtime image (`.sif` or Docker Hub i AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. -::::{exercise} Scenario 6: Generating or assisting code using AI tools -You write software using AI coding assistants (ChatGPT, Copilot) to generate functions, boilerplate, or refactor algorithms. +::::{exercise} Scenario 8: Generating or assisting code using AI tools +You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to generate functions, boilerplate, or refactor algorithms. * **Licensing Goal**: Determine if using AI coding tools restricts your open-source license choices. * **JLA Filter Focus**: Driven by human author intent (e.g., ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`). :::{solution} -**Legal Reality**: Pure AI outputs lacking human authorship are ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. +**Legal Reality**: Pure AI outputs lacking human authorship are generally ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. +* **Global & Asian AI Tools (e.g., DeepSeek, Qwen)**: Code generated using open-weight models follows standard copyright rules (human creative oversight determines code ownership). However, distinguish between **generated code** and **model weights**: always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the LLM itself. When collaborating internationally or using Asian open-source software, you may also encounter **MulanPSL-2.0** (an OSI-approved Chinese permissive license compatible with MIT/Apache-2.0). * **Outcome**: **Fully Permissible.** Using AI tools does not force a specific open-source license onto your repository. * **JLA Matches**: `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` (Author choice). * **User Obligation**: Standard obligations apply based on the license you choose for your human-authored codebase. @@ -384,6 +415,8 @@ Your repository contains Python scripts alongside complex, 500-word structured p ::: :::: + + ### Best Practice: #### In-File Identification using SPDX From 0f6e471d22763d49db07f1b5eb1a1c3302f02c3d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Tue, 15 Sep 2026 16:42:38 +0200 Subject: [PATCH 46/99] Reorganizing, this version may be broken, saving before changing --- content/software-licensing.md | 169 +++++++++++++++++----------------- 1 file changed, 83 insertions(+), 86 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 3df3047..cc25657 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -27,65 +27,40 @@ If you need formal guidance references below and legal experts, especially if yo * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` -## Motivation - -```{mermaid} -%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% -flowchart TB - - subgraph box["CI/CD License Compliance Debugging Pipeline"] - A["Build Trigger: Push to my-analysis-tool"] --> B["Run Compliance Scanner"] - B --> C{"Check Inbound vs.
Outbound Terms"} - - C -->|"Your Target License: MIT (Permissive)
Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] - - D --> E{"Select Patch Option"} - - E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] - E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] - E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] - E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'
Nobody can legally run, modify, or reuse your tool"] - - P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] - CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)
'Must share changes under same terms'"] - end - - P -.->|"I want to use"| C - CL -.->|"Pasted code snippet uses"| C - - classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; - classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; - - class P,G,H pass; - class CL copyleft; - class D,F fail; - class I warning; - class A,B,C,E neutral; - class box box_fill; +## Introduction: What is a Software License? -``` +Under copyright law worldwide, software without an explicit license automatically +defaults to "All Rights Reserved": meaning nobody else has the legal right to run, +modify, embed, or cite your code. A software license is a legal permission grant +created by the author that overrides this statutory default, defining how +downstream researchers can reuse your work. +* Open-source licenses fall into two main families: -## Introduction: What is a Software License? + * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** "Do whatever you want, just keep credit." Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. -In {bdg-warning}`Option D` of our debugging pipeline, deleting the `LICENSE` file tricked the automated scanner into passing, but created a major distribution trap. Under copyright law worldwide, software without a license automatically defaults to **"All Rights Reserved"**: meaning nobody else has the legal right to run, modify, or cite your code. + * **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** "Share alike." Grants full freedom to run and modify, but mandates that any distributed derivative work must also be released under the same open-source copyleft terms. -A **software license** is an explicit permission grant that overrides this statutory default, defining exactly how downstream researchers can reuse your work. +The diagram below unifies these license choices and their downstream rights: ```{mermaid} -%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +%%{init: {'themeVariables': { 'edgeLabelBackground': '#ffffff' }}}%% flowchart TD - A["Your Research Codebase
(Source code, container definition files, prompt templates)"] -->|"Option D: No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Nobody can legally run, modify, or share"] + A["Your Research Codebase
(Source code, container recipes, prompt templates)"] -->|"No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Cannot run, modify, or share"] - A -->|"Attach Software License
(Explicit Permission Grant)"| C{"Select License Flavor"} + A -->|"Attach Open-Source License
(Explicit Permission Grant)"| C{"Select License Flavor"} - C -->|"Permissive
(MIT, Apache-2.0, 0BSD)"| D["Maximum Reuse Freedom
โœ… Anyone can run, modify, embed in commercial tools, or re-license"] - C -->|"Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)"| E["Reciprocal Protection
โœ… Free to run & modify, but distributed changes must stay open source"] - C -->|"Proprietary / Closed Source
(Commercial EULA)"| F["Closed Source / Restricted
๐Ÿšซ Flavour not discussed in this lesson"] + C -->|"Permissive
(MIT, Apache-2.0, 0BSD)"| D["Permissive License"] + C -->|"Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)"| E["Copyleft License"] + C -->|"Proprietary / Closed Source"| F["Closed Source / Restricted
๐Ÿšซ Flavour not discussed in this lesson"] + + D --> D1["Run & Modify? Yes!"] + D --> D2["Embed in closed product? Yes!"] + D --> D3["Must changes stay open? No (Optional)"] + + E --> E1["Run & Modify? Yes!"] + E --> E2["Embed in closed product? No!"] + E --> E3["Must changes stay open? Yes! (Mandatory)"] classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef openState fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; @@ -93,31 +68,40 @@ flowchart TD classDef closedState fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#6c757d; classDef codeState fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - class B defaultState; - class D openState; - class E copyleftState; + class B,E2 defaultState; + class D,D1,D2,D3,E1 openState; + class E,E3 copyleftState; class F closedState; class A,C codeState; ``` - ### Copyright Foundation: Expression vs. Ideas -To understand why licenses are required, you must understand how copyright law treats software. Under EU statutory law (Directive 2009/24/EC) and international treaties, software is protected under copyright as a **literary work**. +To understand why licenses are required, you must understand how copyright law treats software. +Under EU statutory law (Directive 2009/24/EC) and international treaties, software is protected +under copyright as a **literary work**. -However, copyright law draws a sharp, fundamental distinction between what is protected and what is free for anyone to use: +However, copyright law draws a sharp, fundamental distinction between what is protected and what +is free for anyone to use: -* **Protected (Code Expression)**: The specific source code text, variable names, binaries, container build recipes, prompt engineering text, and preparatory design documents. -* **Not Protected (Underlying Ideas)**: Mathematical algorithms, scientific models, programming logic, data structures, and interface principles. +* **Protected (Code Expression)**: The specific source code text, variable names, binaries, + container build recipes, prompt engineering text, and preparatory design documents. +* **Not Protected (Underlying Ideas)**: Mathematical algorithms, scientific models, + programming logic, data structures, and interface principles. -Because copyright restricts only the *creative human expression* and not the underlying *ideas or algorithms*, developers use open-source licenses to define the exact terms under which that expression can be legally shared and modified. +Because copyright restricts only the *creative human expression* and not the underlying +*ideas or algorithms*, developers use open-source licenses to define the exact terms under +which that expression can be legally shared and modified. ### Scope of this Lesson: What Counts as "Software"? -Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is broadly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. +Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), +software is broadly defined as a set of instructions to be used directly or indirectly in +a computer to bring about a certain result. -Because modern research software extends beyond simple Python scripts, this lesson applies copyright and licensing principles across six core research software assets: +Because modern research software extends beyond simple Python scripts, this lesson applies +copyright and licensing principles across six core research software assets: * **Source Code**: Original algorithms written from scratch or implemented from scientific papers. * **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. @@ -126,40 +110,53 @@ Because modern research software extends beyond simple Python scripts, this less * **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. -## Global Context & AI Legal Bias -Software development is inherently cosmopolitan: research software engineers routinely collaborate across legal borders, fetch dependencies from global registries, and commit code to international repositories. +Motivation: Debugging a License Compliance Failure -However, modern developers face a subtle trap: AI legal bias. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to US common law concepts ("Fair Use", "Work Made for Hire", "Derivative Works"). Relying blindly on AI advice can create legal blind spots when operating under EU statutory frameworks or collaborating globally. +With the understanding of the difference between Permissive (MIT) and Copyleft (GPL-3.0) licenses, +examine what happens when they collide inside an automated CI/CD pipeline: -:::{dropdown} Deep Dive: Comparative Legal Mechanisms (US vs. EU vs. Asia) -:color: info -* **Code Adaptation / Refactoring** - * **US Concept:** **Derivative Work** (broadly interpreted judicial doctrine). - * **EU Concept:** **Adaptation**, translation, arrangement, or alteration (Directive 2009/24/EC Art. 4(1)(b)). - * **Practical Impact:** EU law avoids the vague term "derivative work." Any code modification is classified as a specific statutory act of adaptation or translation. +```{mermaid} +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +flowchart TB -* **User Rights & Interoperability** (Run, debug, reverse engineer) - * **US Concept:** **Fair Use** (flexible balancing test evaluated case-by-case in court). - * **EU Concept:** **Statutory Exceptions** (Directive 2009/24/EC Articles 5 & 6). - * **Practical Impact:** EU law splits user rights into **non-waivable statutory rights** (backup copies under Art. 5(2), studying/testing under Art. 5(3), and decompilation for interoperability under Art. 6, which cannot be overridden by contract under Art. 8) and **contract-overridable default rules** (error correction under Art. 5(1), which applies unless an employment or vendor contract specifies otherwise). + subgraph box["CI/CD License Compliance Debugging Pipeline"] + A["Build Trigger: Push to my-analysis-tool"] --> B["Run Compliance Scanner"] + B --> C{"Check Inbound vs.
Outbound Terms"} + + C -->|"Your Target License: MIT (Permissive)
Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] + + D --> E{"Select Patch Option"} + + E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] + E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] + E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] + E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'
Nobody can legally run, modify, or reuse your tool"] -* **Code Ownership** (Employee authorship) - * **US Concept:** **Work Made for Hire** (the employer is legally recognized as the primary author). - * **EU Concept:** **Employer Economic Rights** (Directive 2009/24/EC Art. 2(3)). - * **Practical Impact:** The individual developer remains the legal author, but all economic exploitation rights automatically transfer to the employer for code created during employment duties. + P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] + CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)
'Must share changes under same terms'"] + end -* **Waiving Rights & Public Domain** (Giving up control) - * **US Concept:** **Public Domain Dedication** (authors can fully surrender both economic and moral rights). - * **EU & Asian Civil Law Concept:** **Economic Rights Transfer / Non-Waivable Moral Rights**. - * **Practical Impact:** Civil law traditions (EU, China, Japan, South Korea) do not allow complete waivers of moral rights (e.g., the author's right to attribution). Always use permissive open-source licenses (MIT, 0BSD) rather than informal public domain claims. + P -.->|"I want to use"| C + CL -.->|"Pasted code snippet uses"| C + + classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c0000; + classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; + + class P,G,H pass; + class CL copyleft; + class D,F fail; + class I warning; + class A,B,C,E neutral; + class box box_fill; + +``` -* **Collaborating with Asian Ecosystems & Chinese AI Tools** - * **Civil Law Alignment:** Legal frameworks in China, Japan, and South Korea mirror EU civil law rather than US common law, strictly protecting moral rights and requiring formal contract grants. - * **OSI-Approved Chinese Licenses:** Chinese open-source projects frequently use **MulanPSL-2.0** (Mulan Permissive Software License), an OSI-approved bilingual license designed to align with Chinese contract law while maintaining global compatibility with MIT/Apache-2.0. - * **Using Chinese AI Models (e.g., DeepSeek, Qwen):** While code generated using Chinese LLMs follows standard copyright rules (human creative oversight determines ownership), always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the model itself, as some open-weight licenses restrict specific commercial downstream uses. -::: ## Classification of licenses From 23a51c0c496623b53280966463770375f0d4e35b Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 22:36:01 +0200 Subject: [PATCH 47/99] Update introduction mermaid to intergrate the license clasification --- content/software-licensing.md | 42 ++++++++++++++++++----------------- 1 file changed, 22 insertions(+), 20 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index cc25657..867869c 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -44,12 +44,13 @@ downstream researchers can reuse your work. The diagram below unifies these license choices and their downstream rights: ```{mermaid} -%%{init: {'themeVariables': { 'edgeLabelBackground': '#ffffff' }}}%% -flowchart TD +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% + +flowchart TB A["Your Research Codebase
(Source code, container recipes, prompt templates)"] -->|"No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Cannot run, modify, or share"] - + A -->|"Attach Open-Source License
(Explicit Permission Grant)"| C{"Select License Flavor"} - + C -->|"Permissive
(MIT, Apache-2.0, 0BSD)"| D["Permissive License"] C -->|"Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)"| E["Copyleft License"] C -->|"Proprietary / Closed Source"| F["Closed Source / Restricted
๐Ÿšซ Flavour not discussed in this lesson"] @@ -61,19 +62,20 @@ flowchart TD E --> E1["Run & Modify? Yes!"] E --> E2["Embed in closed product? No!"] E --> E3["Must changes stay open? Yes! (Mandatory)"] - + classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef white fill:#f8f9fa,stroke:#adb + classDef dashed fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; + classDef dashed_red fill:#ffe3e3,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef openState fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef copyleftState fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef closedState fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#6c757d; - classDef codeState fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - - class B,E2 defaultState; - class D,D1,D2,D3,E1 openState; - class E,E3 copyleftState; - class F closedState; - class A,C codeState; - + + class D1,D2,D3,E1,E3 green; + class E2 red; + class D,E yellow; + class F dashed; + class B dashed_red; + class A,C white; ``` ### Copyright Foundation: Expression vs. Ideas @@ -186,15 +188,15 @@ flowchart TB C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] end end - classDef permissive fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef proprietary fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; classDef box fill:#ffffff; - class B1,B2,B3,B4,C1,C2 permissive; - class C3,C4,D1,D2,D3,D4 proprietary; + class B1,B2,B3,C1,C2,C4 green; + class C3,D1,D2,D3,D4 red; class box box; class A,B,C,D mains; class osi osiBox; From ae4e8871b050b14b8ddaa0fd43df06247585b4c0 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 22:50:08 +0200 Subject: [PATCH 48/99] Update motivation --- content/software-licensing.md | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 867869c..0661fd4 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -96,7 +96,7 @@ Because copyright restricts only the *creative human expression* and not the und *ideas or algorithms*, developers use open-source licenses to define the exact terms under which that expression can be legally shared and modified. -### Scope of this Lesson: What Counts as "Software"? +### Scope of this Lesson: What Counts as *Software*? Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), software is broadly defined as a set of instructions to be used directly or indirectly in @@ -113,18 +113,18 @@ copyright and licensing principles across six core research software assets: * **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. -Motivation: Debugging a License Compliance Failure +## Motivation: Debugging a License Compliance Failure With the understanding of the difference between Permissive (MIT) and Copyleft (GPL-3.0) licenses, examine what happens when they collide inside an automated CI/CD pipeline: - ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] - A["Build Trigger: Push to my-analysis-tool"] --> B["Run Compliance Scanner"] + A[Update
Paste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] + A2["Build Trigger: Push to my-code-base"] --> B["Run Compliance Scanner"] B --> C{"Check Inbound vs.
Outbound Terms"} C -->|"Your Target License: MIT (Permissive)
Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] @@ -156,7 +156,6 @@ flowchart TB class I warning; class A,B,C,E neutral; class box box_fill; - ``` From 16990fc0876b0ec67017f3fa4d8e02c836068dd7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 23:06:00 +0200 Subject: [PATCH 49/99] Scenario 1 rework --- content/software-licensing.md | 271 ++++------------------------------ 1 file changed, 30 insertions(+), 241 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 0661fd4..4637af9 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -158,82 +158,25 @@ flowchart TB class box box_fill; ``` - -## Classification of licenses - -```{mermaid} - flowchart LR - subgraph box[ ] - A["Copyright Law Foundation
(EU Directive 2009/24/EC)"] --> B["Permissive
(MIT, BSD, Apache-2.0)"] - A --> C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] - A --> D["All Rights Reserved / Proprietary"] - - B --> B1["Run & Modify?
Yes!"] - B --> B2["Sell copies as-is?
Yes!"] - B --> B3["Embed in closed product & sell?
Yes!"] - B --> B4["Must changes stay open?
No (Optional)"] - - C --> C1["Run & Modify?
Yes!"] - C --> C2["Sell copies as-is?
Yes!"] - C --> C3["Embed in closed product & sell?
No!"] - C --> C4["Must changes stay open?
Yes! (Mandatory)"] - - D --> D1["Run & Modify?
No! (Zero permission)"] - D --> D2["Sell copies as-is?
No!"] - D --> D3["Embed in closed product & sell?
No!"] - D --> D4["Can I change code?
No (Closed source)"] - subgraph osi["OSI compatible"] - B["Permissive
(MIT, BSD, Apache-2.0)"] - C["Copyleft / Reciprocal
(EUPL, GPL, LGPL)"] - end - end - classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef header fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - classDef mains fill:#fafadc,stroke:#495057,stroke-width:2px,color:#212529; - classDef osiBox fill:#f8f9fa,stroke:#0275d8,stroke-width:2px,stroke-dasharray: 5 5,color:#0275d8; - classDef box fill:#ffffff; - class B1,B2,B3,C1,C2,C4 green; - class C3,D1,D2,D3,D4 red; - class box box; - class A,B,C,D mains; - class osi osiBox; - -``` - -## Selecting Compliant Licenses - -When using the European Commission's [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses), license selection depends on your RSE workflow. The JLA groups criteria into four categories: **๐ŸŸข Can** (Permissions), **โšช Must** (Obligations), **๐Ÿ”ต Compatible** (Domain), and **๐ŸŸก Support** (OSI Approval). - -### JLA Decision Matrix at a Glance - -| Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | -| :--- | :--- | :--- | :--- | -| **1. Own Code** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| **2. Math Implementation** | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | -| **3. Embed Permissive** | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | -| **4. Embed Copyleft** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | -| **5. Link GPL Library** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | -| **6. AI-Assisted Code** | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | -| **7. Container Recipe** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | -| **8. Built Image** | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | -| **9. Prompt Template** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | - ---- - -## Global Context: Software Engineering Across Legal Borders - -Software development is inherently cosmopolitan: research software engineers routinely collaborate across legal borders, fetch dependencies from global registries, and commit code to international repositories. - -However, modern developers face a subtle trap: **AI legal bias**. Coding assistants (ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric web data and legal texts. Consequently, when asked about software ownership or licensing, AI outputs almost universally default to **US common law concepts** (*"Fair Use"*, *"Work Made for Hire"*, *"Derivative Works"*). Relying blindly on AI advice can create legal blind spots when operating under EU statutory frameworks or collaborating globally. - ---- - -## Selecting Compliant Licenses - -When using the European Commission's [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses), license selection depends on your RSE workflow. The JLA groups criteria into four categories: **๐ŸŸข Can** (Permissions), **โšช Must** (Obligations), **๐Ÿ”ต Compatible** (Domain), and **๐ŸŸก Support** (OSI Approval). - +Global Context & AI Legal Bias + +Software development is inherently cosmopolitan: research software engineers +routinely collaborate across legal borders, fetch dependencies from global +registries, and commit code to international repositories. + +However, modern developers face a subtle trap: AI legal bias. Coding assistants +(ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric +web data and legal texts. Consequently, when asked about software ownership +or licensing, AI outputs almost universally default to US common law concepts +("Fair Use", "Work Made for Hire", "Derivative Works"). Relying blindly on +AI advice can create legal blind spots when operating under EU statutory +frameworks or collaborating globally.Selecting Compliant Licenses + +When using the European Commission's Joinup Licensing Assistant (JLA), +license selection depends on your RSE workflow. The JLA groups +criteria into four categories: +๐ŸŸข Can (Permissions), โšช Must (Obligations), ๐Ÿ”ต Compatible (Domain), +and ๐ŸŸก Support (OSI Approval). ### JLA Decision Matrix at a Glance | Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | @@ -248,8 +191,6 @@ When using the European Commission's [Joinup Licensing Assistant (JLA)](https:// | **8. AI-Assisted Code** | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | | **9. Prompt Template** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | ---- - ### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms When writing original code or implementing published mathematical logic, you control 100% of your copyright. @@ -267,171 +208,19 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your * **Selected Category**: **Permissive** (driven by your goal of maximum adoption). * **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **User Obligation**: Downstream users must comply with individual external package licenses when fetching or running dependencies. -* **Public Domain vs. Permissive Licenses**: Civil law jurisdictions (EU, China, Japan, South Korea) do not recognize total waivers of moral rights (e.g., your right to attribution as an author). Avoid informal "Public Domain" claims; always use standard permissive open-source licenses (`MIT`, `0BSD`, `Apache-2.0`) to grant legal permissions safely worldwide. -::: -:::: - -::::{exercise} Scenario 2: Implementing an algorithm from a paper -You read a published scientific paper, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. - -* **Licensing Goal**: You want **reciprocal protection**โ€”anyone can use your code, but downstream modifications distributed by others must remain open source. -* **JLA Filter Focus**: Add โšช **Must** toggles: `Copyleft/Share a.` + `Disclose source`. - -:::{solution} -**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new copyright. - -* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation. -* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under matching copyleft terms. -::: -:::: - ---- - -### Module 2: The Dependency Minefield โ€“ Inbound Code & Linking - -Embedding third-party source code snippets or linking against strong copyleft libraries introduces legal boundaries that restrict your repository choices. - -::::{exercise} Scenario 3: Directly embedding third-party Permissive source code -You copy and paste a helper module licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause) directly into your repository. - -* **Licensing Goal**: Know if including permissive third-party code limits your overall repository license choices. -* **JLA Filter Focus**: Baseline ๐ŸŸข `Commercial use` + โšช `Incl. Copyright` (Permissive code leaves all target options open). - -:::{solution} -**Legal Reality**: Permissive licenses grant broad rights to combine, modify, and re-license derivative works, provided you preserve the original author's copyright notice. - -* **Outcome**: **Full Flexibility.** Embedding Permissive code does not force a specific license on your project. You can choose Permissive *or* Copyleft. -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `MIT`, `Apache-2.0` -* **User Obligation**: Retain the original copyright notice and MIT/BSD license text within the specific files where the copied code resides. -::: -:::: - -::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code -You copy and paste a utility function licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2) directly into your repository files. - -* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. -* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` is **mandated** by inbound code. - -:::{solution} -**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined work. You do not hold exclusive copyright over the overall codebase. - -* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *"Derivative Works"*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. -* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. -* **Selected Category**: **Copyleft / Reciprocal** -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0` -* **User Obligation**: Anyone distributing your project must provide access to the full source code under matching copyleft terms. -::: -:::: - -::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) -You write your code from scratch, but your program links (statically or dynamically) against a scientific library licensed under **GPL-3.0**. +* **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: -* **Licensing Goal**: Select a license compliant with the inbound linking requirements of the GPL library. -* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` + `Disclose source` (Required across linking boundaries). - -:::{solution} -**Legal Reality**: Linking your code with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. - -* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. -* **JLA Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` -* **User Obligation**: Anyone distributing compiled binaries must provide the full application source code under GPL-compatible copyleft terms. -::: -:::: - ---- - -### Module 3: Reproducible Infrastructure โ€“ Build Recipes vs. Binary Bundles - -A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). - -::::{exercise} Scenario 6: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) -You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. - -* **Licensing Goal**: Maximum adoption for your build instructions with zero restrictions. -* **JLA Filter Focus**: Treat as original source code ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. - -:::{solution} -**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images or packages in commands does not transfer third-party copyright onto your text file. - -* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions and can choose any license for your recipe file. -* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **User Obligation**: Users downloading your recipe file must preserve your copyright notice. -::: -:::: - -::::{exercise} Scenario 7: Distributing a Built Container Image (Docker Hub or Apptainer .sif) -You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. - -* **Licensing Goal**: Comply with legal obligations when distributing a bundled binary filesystem image. -* **JLA Filter Focus**: N/A (Cannot apply a single JLA license filter to a multi-work binary bundle). - -:::{solution} -**Legal Reality**: Unlike a text recipe file, a compiled container image is a **bundle of separate third-party software works**. You do not hold exclusive copyright over the entire image filesystem. - -* **Outcome**: **Mandatory Multi-License Compliance.** Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, "mere aggregation" applies. -* **User Obligation**: Ensure compliance with all third-party licenses bundled inside the container layers. -::: -:::: - ---- - -### Module 4: Modern AI Workflows โ€“ Assisted Code & Prompt Engineering - -AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. - -::::{exercise} Scenario 8: Generating or assisting code using AI tools -You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to generate functions, boilerplate, or refactor algorithms. - -* **Licensing Goal**: Determine if using AI coding tools restricts your open-source license choices. -* **JLA Filter Focus**: Driven by human author intent (e.g., ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`). - -:::{solution} -**Legal Reality**: Pure AI outputs lacking human authorship are generally ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. - -* **Global & Asian AI Tools (e.g., DeepSeek, Qwen)**: Code generated using open-weight models follows standard copyright rules (human creative oversight determines code ownership). However, distinguish between **generated code** and **model weights**: always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the LLM itself. When collaborating internationally or using Asian open-source software, you may also encounter **MulanPSL-2.0** (an OSI-approved Chinese permissive license compatible with MIT/Apache-2.0). -* **Outcome**: **Fully Permissible.** Using AI tools does not force a specific open-source license onto your repository. -* **JLA Matches**: `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` (Author choice). -* **User Obligation**: Standard obligations apply based on the license you choose for your human-authored codebase. -::: -:::: - -::::{exercise} Scenario 9: Including AI prompt templates in LLM applications -Your repository contains Python scripts alongside complex, 500-word structured prompt templates (system prompts, XML schemas, reasoning frameworks). - -* **Licensing Goal**: Ensure prompt templates are legally covered under the same open-source license as your code. -* **JLA Filter Focus**: Treat engineered prompts as code assets: ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. - -:::{solution} -**Legal Reality**: Short functional prompts carry no copyright. However, complex, highly structured prompt templates meet the threshold of creative human expression and are legally protected as literary text assets. - -* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are covered under your overall repository license. -* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **User Obligation**: Downstream users who copy your prompt files must preserve your copyright notice and file headers (`# SPDX-License-Identifier: MIT`). -::: -:::: - - - -### Best Practice: - -#### In-File Identification using SPDX - -Once you select a license, apply it to individual source files and build recipes using **SPDX identifiers** (Software Package Data Exchange). Managed by the Linux Foundation, an SPDX identifier is a standardized, machine-readable short tag (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `0BSD`) recognized by automated compliance scanners, package managers, and CI/CD build pipelines. - -Instead of pasting long legal texts at the top of every file, add a single-line comment at the very first line of your script or recipe: - - In a container recipe - -```dockerfile -# SPDX-License-Identifier: MIT -FROM ubuntu:24.04 -``` - - In a python script ```python -# SPDX-License-Identifier: 0BSD +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name + import numpy as np ``` +Public Domain vs. Permissive Licenses: Civil law jurisdictions (EU, China, Japan, +South Korea) do not recognize total waivers of moral rights (e.g., your right +to attribution as an author). Avoid informal *Public Domain* claims; +always use standard permissive open-source licenses (MIT, 0BSD, Apache-2.0) to +grant legal permissions safely worldwide. +::: +:::: -#### How to include a license file From f41c93437c65a06d4d78cdcb4b31eb540592e42f Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 23:07:08 +0200 Subject: [PATCH 50/99] Scenario 2 rework --- content/software-licensing.md | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 4637af9..fc11b19 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -216,7 +216,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your import numpy as np ``` -Public Domain vs. Permissive Licenses: Civil law jurisdictions (EU, China, Japan, +* Public Domain vs. Permissive Licenses: Civil law jurisdictions (EU, China, Japan, South Korea) do not recognize total waivers of moral rights (e.g., your right to attribution as an author). Avoid informal *Public Domain* claims; always use standard permissive open-source licenses (MIT, 0BSD, Apache-2.0) to @@ -224,3 +224,19 @@ grant legal permissions safely worldwide. ::: :::: +::::{exercise} Scenario 2: Implementing an algorithm from a paper +You read a published scientific paper, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. + +* **Licensing Goal**: You want **reciprocal protection**โ€”anyone can use your code, but downstream modifications distributed by others must remain open source. +* **JLA Filter Focus**: Add โšช **Must** toggles: `Copyleft/Share a.` + `Disclose source`. + +:::{solution} +**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new copyright. + +* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation. +* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` +* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under matching copyleft terms. +::: +:::: + From b51e30dce0587a909c1e0180e35391a92b9c1fa1 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 23:17:35 +0200 Subject: [PATCH 51/99] Scenario 3 -9 rework to include SPDX --- content/software-licensing.md | 189 ++++++++++++++++++++++++++++++++++ 1 file changed, 189 insertions(+) diff --git a/content/software-licensing.md b/content/software-licensing.md index fc11b19..c10bffa 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -240,3 +240,192 @@ You read a published scientific paper, understand the underlying mathematical al ::: :::: +### Module 2: The Dependency Minefield โ€“ Inbound Code & Linking + +Embedding third-party source code snippets or linking against strong copyleft libraries introduces legal boundaries that restrict your repository choices. + +::::{exercise} Scenario 3: Directly embedding third-party Permissive source code +You copy and paste a helper module licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause) directly into your repository. + +* **Licensing Goal**: Know if including permissive third-party code limits your overall repository license choices. +* **JLA Filter Focus**: Baseline ๐ŸŸข `Commercial use` + โšช `Incl. Copyright` (Permissive code leaves all target options open). + +:::{solution} +**Legal Reality**: Permissive licenses grant broad rights to combine, modify, and re-license derivative works, provided you preserve the original author's copyright notice. + +* **Outcome**: **Full Flexibility.** Embedding Permissive code does not force a specific license on your project. You can choose Permissive *or* Copyleft. +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `MIT`, `Apache-2.0` +* **User Obligation**: Retain the original copyright notice and MIT/BSD license text within the specific files where the copied code resides. +::: +:::: + +::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code +You copy and paste a utility function licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2) directly into your repository files. + +* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. +* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` is **mandated** by inbound code. + +:::{solution} +**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined work. You do not hold exclusive copyright over the overall codebase. + +* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *"Derivative Works"*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. +* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. +* **Selected Category**: **Copyleft / Reciprocal** +* **JLA Matches**: `EUPL-1.2`, `GPL-3.0` +* **User Obligation**: Anyone distributing your project must provide access to the full source code under matching copyleft terms. +::: +:::: + +::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) +You write your code from scratch, but your program links (statically or dynamically) against a scientific library licensed under **GPL-3.0**. + +* **Licensing Goal**: Select a license compliant with the inbound linking requirements of the GPL library. +* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` + `Disclose source` (Required across linking boundaries). + +:::{solution} +**Legal Reality**: Linking your code with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. + +* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. +* **JLA Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` +* **User Obligation**: Anyone distributing compiled binaries must provide the full application source code under GPL-compatible copyleft terms. +::: +:::: + +--- + +### Module 3: Reproducible Infrastructure โ€“ Build Recipes vs. Binary Bundles + +A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). + +::::{exercise} Scenario 6: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) +You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. + +* **Licensing Goal**: Maximum adoption for your build instructions with zero restrictions. +* **JLA Filter Focus**: Treat as original source code ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. + +:::{solution} +**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images or packages in commands does not transfer third-party copyright onto your text file. + +* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions and can choose any license for your recipe file. +* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **In-File Identification (SPDX)**: Add an SPDX header comment to the first line of your Dockerfile: + +```dockerfile +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Research Group + +FROM ubuntu:24.04 +RUN apt-get update && apt-get install -y python3 +``` + +* **User Obligation**: Users downloading your recipe file must preserve your copyright notice. +::: +:::: + +::::{exercise} Scenario 7: Distributing a Built Container Image (Docker Hub or Apptainer .sif) +You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. + +* **Licensing Goal**: Comply with legal obligations when distributing a bundled binary filesystem image. +* **JLA Filter Focus**: N/A (Cannot apply a single JLA license filter to a multi-work binary bundle). + +:::{solution} +**Legal Reality**: Unlike a text recipe file, a compiled container image is a **bundle of separate third-party software works**. You do not hold exclusive copyright over the entire image filesystem. + +* **Outcome**: **Mandatory Multi-License Compliance.** Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. +* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, "mere aggregation" applies. +* **User Obligation**: Ensure compliance with all third-party licenses bundled inside the container layers. +::: +:::: + +--- + +### Module 4: Modern AI Workflows โ€“ Assisted Code & Prompt Engineering + +AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. + +::::{exercise} Scenario 8: Generating or assisting code using AI tools +You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to generate functions, boilerplate, or refactor algorithms. + +* **Licensing Goal**: Determine if using AI coding tools restricts your open-source license choices. +* **JLA Filter Focus**: Driven by human author intent (e.g., ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`). + +:::{solution} +**Legal Reality**: Pure AI outputs lacking human authorship are generally ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. + +* **Global & Asian AI Tools (e.g., DeepSeek, Qwen)**: Code generated using open-weight models follows standard copyright rules (human creative oversight determines code ownership). However, distinguish between **generated code** and **model weights**: always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the LLM itself. When collaborating internationally or using Asian open-source software, you may also encounter **MulanPSL-2.0** (an OSI-approved Chinese permissive license compatible with MIT/Apache-2.0). +* **Outcome**: **Fully Permissible.** Using AI tools does not force a specific open-source license onto your repository. +* **JLA Matches**: `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` (Author choice). +* **User Obligation**: Standard obligations apply based on the license you choose for your human-authored codebase. +::: +:::: + +::::{exercise} Scenario 9: Including AI prompt templates in LLM applications +Your repository contains Python scripts alongside complex, 500-word structured prompt templates (system prompts, XML schemas, reasoning frameworks). + +* **Licensing Goal**: Ensure prompt templates are legally covered under the same open-source license as your code. +* **JLA Filter Focus**: Treat engineered prompts as code assets: ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. + +:::{solution} +**Legal Reality**: Short functional prompts carry no copyright. However, complex, highly structured prompt templates meet the threshold of creative human expression and are legally protected as literary text assets. + +* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are covered under your overall repository license. +* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **In-File Identification (SPDX)**: Place SPDX comments at the top of structured prompt files: + +```yaml +# SPDX-License-Identifier: MIT +# System Prompt: Structured Research Summarizer Framework +``` + +* **User Obligation**: Downstream users who copy your prompt files must preserve your copyright notice and file headers (`# SPDX-License-Identifier: MIT`). +::: +:::: + +## Best Practices: Attaching a License to Your Repository + +Once you have selected a license using the JLA, you must officially attach it to your repository so automated scanners, package registries, and downstream researchers can verify your terms. + +--- + +### 1. Adding the Root `LICENSE` File + +Always place the full text of your chosen license in a plain-text file named `LICENSE` or `LICENSE.txt` at the root of your repository. + +* **Exact Legal Text**: Copy the standard text directly from [spdx.org/licenses](https://spdx.org/licenses/) or [choosealicense.com](https://choosealicense.com/). +* **Copyright Header**: Ensure you fill in the copyright year and copyright holder line at the top of the license text: + ```text + Copyright (c) 2026 [Author Name or Institution Name] + ``` +* **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Custom license edits create "non-standard" legal texts that compliance scanners cannot parse, defaulting your repository back to restricted status. + +--- + +### 2. Documenting License Status in `README.md` + +Add a dedicated **License** section near the bottom of your repository's `README.md` file, along with a machine-readable badge: + +```markdown +## License + +This project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details. + +[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT) +``` + +--- + +### 3. Automated Compliance with the REUSE Standard + +For multi-asset research repositories containing code, data, container build recipes, and prompt templates, follow the [FSFE REUSE Initiative](https://reuse.software/) standard: + +1. **Include License Texts**: Place full license files inside a `LICENSES/` directory (e.g., `LICENSES/MIT.txt`, `LICENSES/GPL-3.0-or-later.txt`). +2. **Add In-File SPDX Headers**: Label every source file, build script, and prompt file with SPDX tags. +3. **Verify Compliance**: Run the automated REUSE linter in your CI/CD pipeline: + +```bash +# Install and run REUSE compliance check +pip install reuse +reuse lint +``` + +When `reuse lint` passes, downstream researchers can automatically verify the legal status of every single asset in your codebase. From d057871150ac5b570ef67936cda9da89aeb6ccd3 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 16 Sep 2026 23:27:12 +0200 Subject: [PATCH 52/99] impliment scenario navigation --- content/software-licensing.md | 48 +++++++++++++++++++++++++++-------- 1 file changed, 38 insertions(+), 10 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index c10bffa..d5d0a22 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -177,24 +177,45 @@ license selection depends on your RSE workflow. The JLA groups criteria into four categories: ๐ŸŸข Can (Permissions), โšช Must (Obligations), ๐Ÿ”ต Compatible (Domain), and ๐ŸŸก Support (OSI Approval). + ### JLA Decision Matrix at a Glance | Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | | :--- | :--- | :--- | :--- | -| **1. Own Code** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| **2. Math Implementation** | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | -| **3. Embed Permissive** | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | -| **4. Embed Copyleft** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | -| **5. Link GPL Library** | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | -| **6. Container Recipe** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | -| **7. Built Image** | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | -| **8. AI-Assisted Code** | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | -| **9. Prompt Template** | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | +| [**1. Own Code**](#scenario-1) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| [**2. Math Implementation**](#scenario-2) | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| [**3. Embed Permissive**](#scenario-3) | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | +| [**4. Embed Copyleft**](#scenario-4) | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | +| [**5. Link GPL Library**](#scenario-5) | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | +| [**6. Container Recipe**](#scenario-6) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | +| [**7. Built Image**](#scenario-7) | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | +| [**8. AI-Assisted Code**](#scenario-8) | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | +| [**9. Prompt Template**](#scenario-9) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | + + +### Standardizing In-File Declarations: SPDX Identifiers + +Selecting a license is only half the battle; automated scanners and CI/CD pipelines need a machine-readable way to verify license compliance per file without parsing long legal texts. + +Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exchange) provide standardized short tags (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `EUPL-1.2`) placed at the very top line of every source file: + +```python +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name +``` + +```dockerfile +# SPDX-License-Identifier: Apache-2.0 +FROM ubuntu:24.04 +``` + +Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. ### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms When writing original code or implementing published mathematical logic, you control 100% of your copyright. +(scenario-1)= ::::{exercise} Scenario 1: Own algorithm with external dependencies You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). @@ -224,6 +245,7 @@ grant legal permissions safely worldwide. ::: :::: +(scenario-2)= ::::{exercise} Scenario 2: Implementing an algorithm from a paper You read a published scientific paper, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. @@ -244,6 +266,7 @@ You read a published scientific paper, understand the underlying mathematical al Embedding third-party source code snippets or linking against strong copyleft libraries introduces legal boundaries that restrict your repository choices. +(scenario-3)= ::::{exercise} Scenario 3: Directly embedding third-party Permissive source code You copy and paste a helper module licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause) directly into your repository. @@ -259,6 +282,7 @@ You copy and paste a helper module licensed under a **Permissive license** (e.g. ::: :::: +(scenario-4)= ::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code You copy and paste a utility function licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2) directly into your repository files. @@ -276,6 +300,7 @@ You copy and paste a utility function licensed under a **Copyleft / Reciprocal l ::: :::: +(scenario-5)= ::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) You write your code from scratch, but your program links (statically or dynamically) against a scientific library licensed under **GPL-3.0**. @@ -297,6 +322,7 @@ You write your code from scratch, but your program links (statically or dynamica A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). +(scenario-6)= ::::{exercise} Scenario 6: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. @@ -322,6 +348,7 @@ RUN apt-get update && apt-get install -y python3 ::: :::: +(scenario-7)= ::::{exercise} Scenario 7: Distributing a Built Container Image (Docker Hub or Apptainer .sif) You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. @@ -343,6 +370,7 @@ You build and publish a complete container runtime image (`.sif` or Docker Hub i AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. +(scenario-8)= ::::{exercise} Scenario 8: Generating or assisting code using AI tools You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to generate functions, boilerplate, or refactor algorithms. @@ -359,6 +387,7 @@ You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to ge ::: :::: +(scenario-9)= ::::{exercise} Scenario 9: Including AI prompt templates in LLM applications Your repository contains Python scripts alongside complex, 500-word structured prompt templates (system prompts, XML schemas, reasoning frameworks). @@ -385,7 +414,6 @@ Your repository contains Python scripts alongside complex, 500-word structured p Once you have selected a license using the JLA, you must officially attach it to your repository so automated scanners, package registries, and downstream researchers can verify your terms. ---- ### 1. Adding the Root `LICENSE` File From 01665a453e5747305c5b3523af465c099562a77d Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 17 Sep 2026 15:14:06 +0200 Subject: [PATCH 53/99] Remove global context section and focus on legal bias --- content/software-licensing.md | 42 +++++++++++++++++++---------------- 1 file changed, 23 insertions(+), 19 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index d5d0a22..98aced1 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -30,16 +30,16 @@ If you need formal guidance references below and legal experts, especially if yo ## Introduction: What is a Software License? Under copyright law worldwide, software without an explicit license automatically -defaults to "All Rights Reserved": meaning nobody else has the legal right to run, +defaults to *All Rights Reserved*: meaning nobody else has the legal right to run, modify, embed, or cite your code. A software license is a legal permission grant created by the author that overrides this statutory default, defining how downstream researchers can reuse your work. * Open-source licenses fall into two main families: - * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** "Do whatever you want, just keep credit." Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. + * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit.* Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. - * **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** "Share alike." Grants full freedom to run and modify, but mandates that any distributed derivative work must also be released under the same open-source copyleft terms. + * **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom to run and modify, but mandates that any distributed derivative work must also be released under the same open-source copyleft terms. The diagram below unifies these license choices and their downstream rights: @@ -158,19 +158,25 @@ flowchart TB class box box_fill; ``` -Global Context & AI Legal Bias +## Limitations of AI-Assisted Licensing Advice -Software development is inherently cosmopolitan: research software engineers -routinely collaborate across legal borders, fetch dependencies from global -registries, and commit code to international repositories. +Modern software developers and RSEs routinely rely on AI coding assistants +(ChatGPT, Claude, GitHub Copilot) to generate boilerplate, refactor functions, +and answer project setup questions. However, using these tools for legal or +licensing guidance introduces a subtle risk: **AI legal bias**. -However, modern developers face a subtle trap: AI legal bias. Coding assistants -(ChatGPT, Claude, GitHub Copilot) are overwhelmingly trained on US-centric -web data and legal texts. Consequently, when asked about software ownership -or licensing, AI outputs almost universally default to US common law concepts -("Fair Use", "Work Made for Hire", "Derivative Works"). Relying blindly on -AI advice can create legal blind spots when operating under EU statutory -frameworks or collaborating globally.Selecting Compliant Licenses +Because AI models are overwhelmingly trained on US-centric web data and legal +forum posts, their outputs default almost universally to **US common law concepts** +such as *Fair Use*, *Work Made for Hire*, and *Derivative Works*. + +In contrast, developers operating under EU statutory frameworks +(such as Directive 2009/24/EC) face a different legal reality regarding statutory +exceptions, author ownership, and code adaptations. Relying blindly on AI legal +advice creates significant compliance blind spots, which is why this lesson equips +you with a direct, EU-aligned framework for software licensing. + + +### JLA Decision Matrix at a Glance When using the European Commission's Joinup Licensing Assistant (JLA), license selection depends on your RSE workflow. The JLA groups @@ -178,8 +184,6 @@ criteria into four categories: ๐ŸŸข Can (Permissions), โšช Must (Obligations), ๐Ÿ”ต Compatible (Domain), and ๐ŸŸก Support (OSI Approval). -### JLA Decision Matrix at a Glance - | Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | | :--- | :--- | :--- | :--- | | [**1. Own Code**](#scenario-1) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | @@ -292,7 +296,7 @@ You copy and paste a utility function licensed under a **Copyleft / Reciprocal l :::{solution} **Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined work. You do not hold exclusive copyright over the overall codebase. -* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *"Derivative Works"*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. +* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *Derivative Works*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. * **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. * **Selected Category**: **Copyleft / Reciprocal** * **JLA Matches**: `EUPL-1.2`, `GPL-3.0` @@ -359,7 +363,7 @@ You build and publish a complete container runtime image (`.sif` or Docker Hub i **Legal Reality**: Unlike a text recipe file, a compiled container image is a **bundle of separate third-party software works**. You do not hold exclusive copyright over the entire image filesystem. * **Outcome**: **Mandatory Multi-License Compliance.** Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, "mere aggregation" applies. +* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, *mere aggregation* applies. * **User Obligation**: Ensure compliance with all third-party licenses bundled inside the container layers. ::: :::: @@ -424,7 +428,7 @@ Always place the full text of your chosen license in a plain-text file named `LI ```text Copyright (c) 2026 [Author Name or Institution Name] ``` -* **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Custom license edits create "non-standard" legal texts that compliance scanners cannot parse, defaulting your repository back to restricted status. +* **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Custom license edits create *non-standard* legal texts that compliance scanners cannot parse, defaulting your repository back to restricted status. --- From c53627d5bf6beea218526df115c9f923530a223b Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Thu, 17 Sep 2026 15:32:36 +0200 Subject: [PATCH 54/99] Include concluding summary to link back to CI CD example --- content/software-licensing.md | 73 ++++++++++++++++++++++++++++------- 1 file changed, 58 insertions(+), 15 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 98aced1..21ab20c 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -47,13 +47,13 @@ The diagram below unifies these license choices and their downstream rights: %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB - A["Your Research Codebase
(Source code, container recipes, prompt templates)"] -->|"No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Cannot run, modify, or share"] + A["Your Research Codebase(Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] - A -->|"Attach Open-Source License
(Explicit Permission Grant)"| C{"Select License Flavor"} + A -->|"Attach Open-Source License(Explicit Permission Grant)"| C{"Select License Flavor"} - C -->|"Permissive
(MIT, Apache-2.0, 0BSD)"| D["Permissive License"] - C -->|"Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)"| E["Copyleft License"] - C -->|"Proprietary / Closed Source"| F["Closed Source / Restricted
๐Ÿšซ Flavour not discussed in this lesson"] + C -->|"Permissive(MIT, Apache-2.0, 0BSD)"| D["Permissive License"] + C -->|"Copyleft / Reciprocal(GPL-3.0, EUPL-1.2)"| E["Copyleft License"] + C -->|"Proprietary / Closed Source"| F["Closed Source / Restricted๐Ÿšซ Flavour not discussed in this lesson"] D --> D1["Run & Modify? Yes!"] D --> D2["Embed in closed product? Yes!"] @@ -123,21 +123,21 @@ examine what happens when they collide inside an automated CI/CD pipeline: flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] - A[Update
Paste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] + A[UpdatePaste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] A2["Build Trigger: Push to my-code-base"] --> B["Run Compliance Scanner"] - B --> C{"Check Inbound vs.
Outbound Terms"} + B --> C{"Check Inbound vs.Outbound Terms"} - C -->|"Your Target License: MIT (Permissive)
Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] + C -->|"Your Target License: MIT (Permissive)Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILUREPasted copyleft snippet restricts MIT release"] D --> E{"Select Patch Option"} - E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] - E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] - E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] - E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'
Nobody can legally run, modify, or reuse your tool"] + E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAILComments do not override copyleft terms"] + E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASSYour license matches the pasted copyleft snippet"] + E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASSNew code expression frees your target license"] + E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)No license = Default 'All Rights Reserved'Nobody can legally run, modify, or reuse your tool"] - P["Permissive
(MIT, Apache-2.0, 0BSD)
'Do whatever you want, just keep credit'"] - CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)
'Must share changes under same terms'"] + P["Permissive(MIT, Apache-2.0, 0BSD)'Do whatever you want, just keep credit'"] + CL["Copyleft / Reciprocal(GPL-3.0, EUPL-1.2)'Must share changes under same terms'"] end P -.->|"I want to use"| C @@ -460,4 +460,47 @@ pip install reuse reuse lint ``` -When `reuse lint` passes, downstream researchers can automatically verify the legal status of every single asset in your codebase. +When `reuse lint` passes, downstream researchers can automatically verify the +legal status of every single asset in your codebase. + +## Summary: Resolving the Compliance Pipeline + +At the start of this lesson, our project hit a **โŒ BUILD FAILURE** because a pasted copyleft snippet conflicted with our target `MIT` license. + +By applying the legal concepts and technical tools covered in this module, we can trace how our learned skills directly resolve the original pipeline crash: + +```{mermaid} +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +flowchart TB + + subgraph box["Resolved CI/CD License Compliance Pipeline"] + A["Build Trigger: Push code with inbound dependency/snippet"] --> B["Run Compliance Scanner"] + B --> C{"Check Inbound vs Outbound Terms"} + + C -->|"Apply JLA Decision Matrix &Copyright Principles"| E{"Select Compliant Strategy"} + + E -->|"Strategy 1: Align Project License(Module 2)Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASSProject license matches inbound copyleft terms"] + + E -->|"Strategy 2: Clean Implementation(Module 1)Rewrite code expression from scratch"| H["โœ… BUILD PASSFresh expression frees original MIT license"] + + G --> V["Standardize & Verify Repository1. Tag files with SPDX Identifiers (# SPDX-License-Identifier)2. Add root LICENSE file & README badge3. Execute REUSE Linter (reuse lint)"] + H --> V + + V --> SUCCESS["๐ŸŽ‰ COMPLIANT OPEN-SOURCE RELEASELegally safe, reproducible & ready for research reuse"] + end + + classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; + + class G,H,V,SUCCESS pass; + class A,B,C,E neutral; + class box box_fill; +``` + +### What Resolved the Issue: + +1. **Applied Copyright Expression vs. Idea (Option C)**: You learned that copyright protects code *expression*, not underlying algorithms. Rewriting the logic creates a fresh copyright, freeing you to maintain an `MIT` permissive license. +2. **Applied the JLA Decision Matrix (Option B)**: You learned how to navigate inbound copyleft obligations. Re-licensing the repository to `GPL-3.0` or `EUPL-1.2` satisfies reciprocal terms while keeping your work open source. +3. **Bypassed Legal Traps (Options A & D)**: You recognized that code comments cannot waive statutory licenses and that deleting a license triggers the default *"All Rights Reserved"* trap. +4. **Standardized Distribution**: You embedded **SPDX headers** across code, recipes, and prompts, verifying full repository compliance via `reuse lint`. From 3bf66a8cc7b4760da4f464a9b9b9845b956ceb9b Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 12:49:18 +0200 Subject: [PATCH 55/99] bridge the intro to explain why permissive and copyleft is defined --- content/software-licensing.md | 42 +++++++++++++++++++---------------- 1 file changed, 23 insertions(+), 19 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 21ab20c..809f5b4 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -35,6 +35,10 @@ modify, embed, or cite your code. A software license is a legal permission grant created by the author that overrides this statutory default, defining how downstream researchers can reuse your work. +In this lesson, we focus on open-source licenses to define both how we grant +permissions for software we develop (outbound licensing) and how we safely +comply with terms attached to code written by others (inbound reuse). + * Open-source licenses fall into two main families: * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit.* Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. @@ -176,6 +180,25 @@ advice creates significant compliance blind spots, which is why this lesson equi you with a direct, EU-aligned framework for software licensing. + +### Standardizing In-File Declarations: SPDX Identifiers + +Selecting a license is only half the battle; automated scanners and CI/CD pipelines need a machine-readable way to verify license compliance per file without parsing long legal texts. + +Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exchange) provide standardized short tags (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `EUPL-1.2`) placed at the very top line of every source file: + +```python +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name +``` + +```dockerfile +# SPDX-License-Identifier: Apache-2.0 +FROM ubuntu:24.04 +``` + +Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. + ### JLA Decision Matrix at a Glance When using the European Commission's Joinup Licensing Assistant (JLA), @@ -196,25 +219,6 @@ and ๐ŸŸก Support (OSI Approval). | [**8. AI-Assisted Code**](#scenario-8) | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | | [**9. Prompt Template**](#scenario-9) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | - -### Standardizing In-File Declarations: SPDX Identifiers - -Selecting a license is only half the battle; automated scanners and CI/CD pipelines need a machine-readable way to verify license compliance per file without parsing long legal texts. - -Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exchange) provide standardized short tags (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `EUPL-1.2`) placed at the very top line of every source file: - -```python -# SPDX-License-Identifier: MIT -# Copyright (c) 2026 Author Name -``` - -```dockerfile -# SPDX-License-Identifier: Apache-2.0 -FROM ubuntu:24.04 -``` - -Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. - ### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms When writing original code or implementing published mathematical logic, you control 100% of your copyright. From ed018fd5016806abcd9978e98cb6d48ebe5ac321 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 12:55:14 +0200 Subject: [PATCH 56/99] Introduce the slang word viral --- content/software-licensing.md | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 809f5b4..4fd0c7b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -41,11 +41,16 @@ comply with terms attached to code written by others (inbound reuse). * Open-source licenses fall into two main families: - * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit.* Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. - - * **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom to run and modify, but mandates that any distributed derivative work must also be released under the same open-source copyleft terms. - -The diagram below unifies these license choices and their downstream rights: + * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep crediti*. + Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code + in open or closed projects. + + * **Copyleft/Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom + to run and modify, but mandates that any distributed derivative or combined work must + also be released under matching copyleft terms. Often informally referred to as *viral* + or *infectious* because its open-source requirements propagate across code boundaries + (such as embedding snippets or static linking) into downstream projects. The diagram + below unifies these license choices and their downstream rights: ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% From a84433468462e687d8f8b84a0b09f4bdd91773f4 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 13:03:08 +0200 Subject: [PATCH 57/99] Include a heading for license types diagramm --- content/software-licensing.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 4fd0c7b..9f4918a 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -56,6 +56,8 @@ comply with terms attached to code written by others (inbound reuse). %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB + + subgraph box["How License Selection Governs Code Reuse"] A["Your Research Codebase(Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] A -->|"Attach Open-Source License(Explicit Permission Grant)"| C{"Select License Flavor"} @@ -71,13 +73,15 @@ flowchart TB E --> E1["Run & Modify? Yes!"] E --> E2["Embed in closed product? No!"] E --> E3["Must changes stay open? Yes! (Mandatory)"] - classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + end + classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; classDef white fill:#f8f9fa,stroke:#adb classDef dashed fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; classDef dashed_red fill:#ffe3e3,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; - classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; class D1,D2,D3,E1,E3 green; class E2 red; @@ -85,6 +89,7 @@ flowchart TB class F dashed; class B dashed_red; class A,C white; + class box box_fill; ``` ### Copyright Foundation: Expression vs. Ideas From 2c278563c71724d6a5c2725e62a5e1c52668b646 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 13:29:39 +0200 Subject: [PATCH 58/99] Update license hirarchi to show goals --- content/software-licensing.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 9f4918a..cc4fb32 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -58,13 +58,13 @@ comply with terms attached to code written by others (inbound reuse). flowchart TB subgraph box["How License Selection Governs Code Reuse"] - A["Your Research Codebase(Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] + A["Your Research Codebase (Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] - A -->|"Attach Open-Source License(Explicit Permission Grant)"| C{"Select License Flavor"} + A -->|"Attach License(Explicit Permission Grant)"| C{"Select License"} - C -->|"Permissive(MIT, Apache-2.0, 0BSD)"| D["Permissive License"] - C -->|"Copyleft / Reciprocal(GPL-3.0, EUPL-1.2)"| E["Copyleft License"] - C -->|"Proprietary / Closed Source"| F["Closed Source / Restricted๐Ÿšซ Flavour not discussed in this lesson"] + C -->|"Goal: Maximum adoption & unrestricted reuse"| D["Permissive License"] + C -->|"Goal: Ensure changes stay open-source (Reciprocity)"| E["Copyleft License"] + C -->|"Goal: Proprietary control & restricted access"| F["Closed Source / Restricted๐Ÿšซ Flavour not discussed in this lesson"] D --> D1["Run & Modify? Yes!"] D --> D2["Embed in closed product? Yes!"] From 50a09b2dfb48d4c2b02e3d7dacbcfe9a6d736c41 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 19:05:41 +0200 Subject: [PATCH 59/99] minor edits to male concepts clearer --- content/software-licensing.md | 51 ++++++++++++++++++----------------- 1 file changed, 26 insertions(+), 25 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index cc4fb32..3f30dbe 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -107,20 +107,20 @@ is free for anyone to use: programming logic, data structures, and interface principles. Because copyright restricts only the *creative human expression* and not the underlying -*ideas or algorithms*, developers use open-source licenses to define the exact terms under +*ideas or algorithms*, developers could use open-source licenses to define the exact terms under which that expression can be legally shared and modified. ### Scope of this Lesson: What Counts as *Software*? -Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO model provisions), -software is broadly defined as a set of instructions to be used directly or indirectly in +Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO-World Intellectual Property Organization +model provisions), software is broadly defined as a set of instructions to be used directly or indirectly in a computer to bring about a certain result. Because modern research software extends beyond simple Python scripts, this lesson applies copyright and licensing principles across six core research software assets: * **Source Code**: Original algorithms written from scratch or implemented from scientific papers. -* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and dynamically/statically linked libraries. +* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and linked libraries (dynamically/statically). * **Infrastructure as Code**: Ansible playbooks,Terraform configurations,container Recipes (`Dockerfile`, Apptainer `.def`). * **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). * **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. @@ -129,7 +129,7 @@ copyright and licensing principles across six core research software assets: ## Motivation: Debugging a License Compliance Failure -With the understanding of the difference between Permissive (MIT) and Copyleft (GPL-3.0) licenses, +With the understanding of the difference between Permissive and Copyleft licenses, examine what happens when they collide inside an automated CI/CD pipeline: ```{mermaid} @@ -137,21 +137,21 @@ examine what happens when they collide inside an automated CI/CD pipeline: flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] - A[UpdatePaste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] + A[Paste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] A2["Build Trigger: Push to my-code-base"] --> B["Run Compliance Scanner"] B --> C{"Check Inbound vs.Outbound Terms"} - C -->|"Your Target License: MIT (Permissive)Pasted Snippet: GPL-3.0 (Copyleft)"| D["โŒ BUILD FAILUREPasted copyleft snippet restricts MIT release"] + C -->|"Target License:Permissive but pasted snippet:Copyleft"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] D --> E{"Select Patch Option"} - E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAILComments do not override copyleft terms"] - E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASSYour license matches the pasted copyleft snippet"] - E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASSNew code expression frees your target license"] - E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)No license = Default 'All Rights Reserved'Nobody can legally run, modify, or reuse your tool"] + E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] + E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] + E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] + E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'Nobody can legally run, modify, or reuse your tool"] - P["Permissive(MIT, Apache-2.0, 0BSD)'Do whatever you want, just keep credit'"] - CL["Copyleft / Reciprocal(GPL-3.0, EUPL-1.2)'Must share changes under same terms'"] + P["Permissive
(MIT, Apache-2.0, 0BSD)'Do whatever you want, just keep credit'"] + CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)'Must share changes under same terms'"] end P -.->|"I want to use"| C @@ -176,18 +176,19 @@ flowchart TB Modern software developers and RSEs routinely rely on AI coding assistants (ChatGPT, Claude, GitHub Copilot) to generate boilerplate, refactor functions, -and answer project setup questions. However, using these tools for legal or -licensing guidance introduces a subtle risk: **AI legal bias**. - -Because AI models are overwhelmingly trained on US-centric web data and legal -forum posts, their outputs default almost universally to **US common law concepts** -such as *Fair Use*, *Work Made for Hire*, and *Derivative Works*. - -In contrast, developers operating under EU statutory frameworks -(such as Directive 2009/24/EC) face a different legal reality regarding statutory -exceptions, author ownership, and code adaptations. Relying blindly on AI legal -advice creates significant compliance blind spots, which is why this lesson equips -you with a direct, EU-aligned framework for software licensing. +and answer project setup questions. + +However, using these tools for legal or licensing guidance introduces a subtle +risk of **AI legal bias** as AI models are overwhelmingly trained on US-centric +web data and legal forum posts, their outputs default almost universally +to **US common law concepts** such as *Fair Use*, *Work Made for Hire*, and +*Derivative Works*. + +In contrast, developers operating under EU statutory frameworks (such as Directive 2009/24/EC) +face a different legal reality related to exceptions, author ownership, and code adaptations. +Relying blindly on AI legal advice creates significant compliance blind spots, +which is why this lesson was developed by the CodeRefinery team with a direct, EU-aligned +framework for software licensing. From 98f878f0d926f0a8af55fc18aea449a1672f9526 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 19:37:32 +0200 Subject: [PATCH 60/99] Emphasize legal trap when deleting a license --- content/software-licensing.md | 12 +++--------- 1 file changed, 3 insertions(+), 9 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 3f30dbe..620aa2b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -148,7 +148,7 @@ flowchart TB E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] - E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (TRAP!)
No license = Default 'All Rights Reserved'Nobody can legally run, modify, or reuse your tool"] + E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (LEGAL TRAP!)
Infringes third-party copyright & locks own code to All Rights Reserved"] P["Permissive
(MIT, Apache-2.0, 0BSD)'Do whatever you want, just keep credit'"] CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)'Must share changes under same terms'"] @@ -187,8 +187,7 @@ to **US common law concepts** such as *Fair Use*, *Work Made for Hire*, and In contrast, developers operating under EU statutory frameworks (such as Directive 2009/24/EC) face a different legal reality related to exceptions, author ownership, and code adaptations. Relying blindly on AI legal advice creates significant compliance blind spots, -which is why this lesson was developed by the CodeRefinery team with a direct, EU-aligned -framework for software licensing. +which is why this lesson equips you with a direct, EU-aligned framework for software licensing. @@ -203,14 +202,9 @@ Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exc # Copyright (c) 2026 Author Name ``` -```dockerfile -# SPDX-License-Identifier: Apache-2.0 -FROM ubuntu:24.04 -``` - Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. -### JLA Decision Matrix at a Glance +### License Decision Matrix at a Glance When using the European Commission's Joinup Licensing Assistant (JLA), license selection depends on your RSE workflow. The JLA groups From 6249d81a07bf064111e569ee781eacbc2e18717a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 20:18:32 +0200 Subject: [PATCH 61/99] simplify descision matrix --- content/software-licensing.md | 45 ++++++++++++++++++++--------------- 1 file changed, 26 insertions(+), 19 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 620aa2b..09f5319 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -204,25 +204,32 @@ Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exc Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. -### License Decision Matrix at a Glance - -When using the European Commission's Joinup Licensing Assistant (JLA), -license selection depends on your RSE workflow. The JLA groups -criteria into four categories: -๐ŸŸข Can (Permissions), โšช Must (Obligations), ๐Ÿ”ต Compatible (Domain), -and ๐ŸŸก Support (OSI Approval). - -| Scenario Module | Key JLA Toggle (โšช Must) | Resulting Category | Target Licenses | -| :--- | :--- | :--- | :--- | -| [**1. Own Code**](#scenario-1) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| [**2. Math Implementation**](#scenario-2) | `Copyleft/Share a.` + `Disclose Source` | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | -| [**3. Embed Permissive**](#scenario-3) | `Incl. Copyright` | ๐ŸŸข Flexible (Any) | `MIT` or `EUPL-1.2` / `GPL-3.0` | -| [**4. Embed Copyleft**](#scenario-4) | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `EUPL-1.2`, `GPL-3.0` | -| [**5. Link GPL Library**](#scenario-5) | `Copyleft/Share a.` *(Mandatory)* | ๐ŸŸก Copyleft | `GPL-3.0`, `EUPL-1.2` | -| [**6. Container Recipe**](#scenario-6) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | -| [**7. Built Image**](#scenario-7) | Overlapping Component Terms | โš ๏ธ Multi-License | Governed by individual image layers | -| [**8. AI-Assisted Code**](#scenario-8) | `Incl. Copyright` | ๐ŸŸข Author Choice | `MIT`, `Apache-2.0` (or Copyleft) | -| [**9. Prompt Template**](#scenario-9) | `Incl. Copyright` | ๐ŸŸข Permissive | `MIT`, `Apache-2.0` | + +### License Selection Decision Matrix & Scenario Index + +To help you navigate open-source compliance, the matrix below serves as an upfront +quick-reference summary and interactive index for the core licensing scenarios +encountered in research software engineering. + +Our decision framework is grounded in the European Commission's **Joinup Licensing Assistant (JLA)**, +which evaluates software assets across six criteria categories: **Can** (Permissions), +**Must** (Obligations), **Cannot** (Restrictions), **Compatible** (Interoperability), +**Law** (Jurisdiction), and **Support** (Governance). + +Use this index to preview the demonstrated path for each scenario, or click any module link to jump +directly to its detailed exercise, legal analysis, and JLA selection instructions. + +| Scenario Module | Demonstrated Path / Focus | Compliant Target Licenses | +| :--- | :--- | :--- | +| [**1. Own Code**](#scenario-1) | ๐ŸŸข Permissive *(Default Choice)* | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| [**2. Math Implementation**](#scenario-2) | ๐ŸŸก Copyleft / Reciprocal | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| [**3. Embed Permissive**](#scenario-3) | ๐ŸŸข Permissive Focus *(Copyleft Flexible)* | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | +| [**4. Embed Copyleft**](#scenario-4) | ๐ŸŸก Mandatory Copyleft | `EUPL-1.2`, `GPL-3.0` | +| [**5. Link GPL Library**](#scenario-5) | ๐ŸŸก Mandatory Copyleft | `GPL-3.0`, `EUPL-1.2` | +| [**6. Container Recipe**](#scenario-6) | ๐ŸŸข Permissive Focus | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| [**7. Built Image**](#scenario-7) | โš ๏ธ Multi-License Bundle | Governed by individual layer/binary terms | +| [**8. AI-Assisted Code**](#scenario-8) | ๐ŸŸข Permissive Focus *(Author Choice)* | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | +| [**9. Prompt Chaining Architecture**](#scenario-9) | ๐ŸŸข Permissive Focus | `MIT`, `Apache-2.0` | ### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms From 3a3cc0ccfe304133d9ddd3258291ba42e71fadff Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 21:36:49 +0200 Subject: [PATCH 62/99] Update the scenarios with more JLS assitance --- content/software-licensing.md | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 09f5319..1571bf8 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -236,19 +236,28 @@ directly to its detailed exercise, legal analysis, and JLA selection instruction When writing original code or implementing published mathematical logic, you control 100% of your copyright. (scenario-1)= -::::{exercise} Scenario 1: Own algorithm with external dependencies +::::{exercise} Scenario 1: Authoring original code and algorithms You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). * **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. -* **JLA Filter Focus**: Select ๐ŸŸข `Commercial use`, `Modify`, `Distribute` + โšช `Incl. Copyright` + ๐ŸŸก `OSI approved`. +* **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. +* **JLA Selection Strategy**: To ensure downstream users must acknowledge your original authorship while granting them maximum flexibility to incorporate your code into both open and proprietary software, you require citation credit (`Incl. Copyright`) without imposing share-alike conditions (leaving `Copyleft/Share a.` unselected). :::{solution} -**Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` + +* **Permissive vs. Public Domain (EU Civil Law Nuance)**: Public domain dedications (e.g., `CC0`, `Unlicense`) attempt to give away all rights. However, under EU civil law, authors cannot legally give up their moral rights (*droit moral*). Selecting an explicit permissive license like `MIT` or `Apache-2.0` grants broad permissions globally, remains legally valid under European copyright law, and guarantees academic citation credit. + +* **Downstream Obligations**: Anyone who reuses, modifies, or integrates your code into their work must preserve your copyright notice and license text. They are not required to share their modifications or open-source their downstream projects. + +* **Allowed Inbound Snippets**: If you want to include small third-party code snippets in your files, you can freely embed code licensed under **permissive terms** (e.g., MIT, BSD, Apache-2.0, 0BSD) or public domain waivers (CC0) without affecting your permissive license. However, embedding copyleft snippets (e.g., GPL, EUPL) will trigger reciprocal obligations, forcing your entire repository to be re-licensed under those copyleft terms. -* **Outcome**: **Fully Permissible.** You own the code and can choose any open-source license. -* **Selected Category**: **Permissive** (driven by your goal of maximum adoption). -* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **User Obligation**: Downstream users must comply with individual external package licenses when fetching or running dependencies. * **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: ```python @@ -257,11 +266,6 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your import numpy as np ``` -* Public Domain vs. Permissive Licenses: Civil law jurisdictions (EU, China, Japan, -South Korea) do not recognize total waivers of moral rights (e.g., your right -to attribution as an author). Avoid informal *Public Domain* claims; -always use standard permissive open-source licenses (MIT, 0BSD, Apache-2.0) to -grant legal permissions safely worldwide. ::: :::: From 2c4a0d0478f5ff9416a310fe571de270f4b03545 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 21:49:38 +0200 Subject: [PATCH 63/99] Update the scenarios 2 and 3 --- content/software-licensing.md | 178 +++++++++------------------------- 1 file changed, 45 insertions(+), 133 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 1571bf8..a19bd0b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -270,167 +270,79 @@ import numpy as np :::: (scenario-2)= -::::{exercise} Scenario 2: Implementing an algorithm from a paper -You read a published scientific paper, understand the underlying mathematical algorithm, and write your own original software implementation from scratch. +::::{exercise} Scenario 2: Implementing mathematical models with copyleft obligations +You developed a custom mathematical solver implementing algorithms from academic literature. You want to ensure that any downstream improvements, extensions, or modifications made by others remain open-source and are shared back with the scientific community. -* **Licensing Goal**: You want **reciprocal protection**โ€”anyone can use your code, but downstream modifications distributed by others must remain open source. -* **JLA Filter Focus**: Add โšช **Must** toggles: `Copyleft/Share a.` + `Disclose source`. +* **Licensing Goal**: You want to enforce **reciprocity** (share-alike), preventing third parties from incorporating your algorithm into proprietary, closed-source software without sharing their modifications. +* **Legal Reality**: Mathematical concepts and formulas themselves are not copyrightable, but your specific code implementation is fully protected by copyright. Applying a copyleft license legally binds anyone who distributes modified versions of your implementation to release their source code under matching reciprocal terms. +* **JLA Selection Strategy**: To enforce reciprocal sharing, you must mandate that downstream distributors disclose their modified source code (`Disclose source`) and license their derivative works under matching terms (`Copyleft/Share a.`). :::{solution} -**Legal Reality**: Under EU Directive 2009/24/EC Art. 1(2), copyright protects specific source code *expression*, not underlying mathematical algorithms or scientific principles. Writing a fresh implementation creates a brand-new copyright. - -* **Outcome**: **Fully Permissible.** You own 100% of the copyright for your software implementation. -* **Selected Category**: **Copyleft / Reciprocal** (driven by your goal of community protection). -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -* **User Obligation**: Users who redistribute your software or their modified versions must provide source code access under matching copyleft terms. -::: -:::: - -### Module 2: The Dependency Minefield โ€“ Inbound Code & Linking - -Embedding third-party source code snippets or linking against strong copyleft libraries introduces legal boundaries that restrict your repository choices. - -(scenario-3)= -::::{exercise} Scenario 3: Directly embedding third-party Permissive source code -You copy and paste a helper module licensed under a **Permissive license** (e.g., MIT or BSD-3-Clause) directly into your repository. - -* **Licensing Goal**: Know if including permissive third-party code limits your overall repository license choices. -* **JLA Filter Focus**: Baseline ๐ŸŸข `Commercial use` + โšช `Incl. Copyright` (Permissive code leaves all target options open). - -:::{solution} -**Legal Reality**: Permissive licenses grant broad rights to combine, modify, and re-license derivative works, provided you preserve the original author's copyright notice. - -* **Outcome**: **Full Flexibility.** Embedding Permissive code does not force a specific license on your project. You can choose Permissive *or* Copyleft. -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `MIT`, `Apache-2.0` -* **User Obligation**: Retain the original copyright notice and MIT/BSD license text within the specific files where the copied code resides. -::: -:::: - -(scenario-4)= -::::{exercise} Scenario 4: Directly embedding third-party Copyleft source code -You copy and paste a utility function licensed under a **Copyleft / Reciprocal license** (e.g., GPL-3.0 or EUPL-1.2) directly into your repository files. - -* **Licensing Goal**: Fulfill legal obligations imposed by incorporating inbound copyleft code into your codebase. -* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` is **mandated** by inbound code. - -:::{solution} -**Legal Reality**: Pasting third-party copyleft source code directly into your repository creates a single combined work. You do not hold exclusive copyright over the overall codebase. - -* **EU vs. US Legal Concepts (Adaptation vs. Derivative Work)**: Coding AI tools often refer to this under the US common-law doctrine of *Derivative Works*. In the EU (Directive 2009/24/EC Art. 4(1)(b)), modifying or refactoring code is classified as a statutory act of **Adaptation, Translation, or Alteration**. Regardless of terminology, modifying copyleft code triggers mandatory reciprocal sharing obligations. -* **Outcome**: **Restricted Choice (Mandatory Copyleft).** You cannot choose a permissive license (MIT) or keep the repository proprietary. -* **Selected Category**: **Copyleft / Reciprocal** -* **JLA Matches**: `EUPL-1.2`, `GPL-3.0` -* **User Obligation**: Anyone distributing your project must provide access to the full source code under matching copyleft terms. -::: -:::: - -(scenario-5)= -::::{exercise} Scenario 5: Linking against a Strong Copyleft library (e.g., GSL or FFTW) -You write your code from scratch, but your program links (statically or dynamically) against a scientific library licensed under **GPL-3.0**. - -* **Licensing Goal**: Select a license compliant with the inbound linking requirements of the GPL library. -* **JLA Filter Focus**: โšช **Must** clause `Copyleft/Share a.` + `Disclose source` (Required across linking boundaries). - -:::{solution} -**Legal Reality**: Linking your code with a Strong Copyleft library like GPL creates a combined software work upon compilation and distribution. - -* **Outcome**: **Mandatory Copyleft.** To distribute the compiled application or repository, your code must be licensed under a GPL-compatible copyleft license. -* **JLA Matches**: `GPL-3.0`, `AGPL-3.0`, `EUPL-1.2` -* **User Obligation**: Anyone distributing compiled binaries must provide the full application source code under GPL-compatible copyleft terms. -::: -:::: - ---- +**What to select in the JLA interface:** -### Module 3: Reproducible Infrastructure โ€“ Build Recipes vs. Binary Bundles +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` +3. **Support Column**: Select `OSI approved` -A major trap for RSEs is confusing **Infrastructure as Code text files** (recipes) with **compiled binary filesystems** (container images). +* **JLA Filter Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` -(scenario-6)= -::::{exercise} Scenario 6: Distributing a Container Build Recipe (Dockerfile or Apptainer .def) -You write a container build recipe (`Dockerfile` or Apptainer `.def` file) containing text commands that pull base images and install packages. +* **Copyleft Mechanics (EUPL vs. GPL Nuance)**: `GPL-3.0` is the standard global copyleft license, but `EUPL-1.2` is specifically tailored for European institutions. EUPL-1.2 is officially published in 23 EU language versions (each with equal legal validity), includes built-in compatibility clauses with GPL, and explicitly defaults to EU Member State jurisdiction and courts. -* **Licensing Goal**: Maximum adoption for your build instructions with zero restrictions. -* **JLA Filter Focus**: Treat as original source code ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. +* **Downstream Obligations**: Anyone who distributes your code or a modified version of it must provide complete access to the corresponding source code under the same copyleft license and preserve your original copyright notices. -:::{solution} -**Legal Reality**: A container recipe is a text file containing build instructions (Infrastructure as Code). Referencing external base images or packages in commands does not transfer third-party copyright onto your text file. +* **Allowed Inbound Snippets**: You can freely embed code snippets licensed under **permissive terms** (e.g., MIT, Apache-2.0, BSD) or public domain waivers (CC0). You may also embed snippets from compatible copyleft code (e.g., EUPL, GPL). However, you cannot embed closed-source or proprietary code snippets. -* **Outcome**: **Fully Permissible.** You own the copyright to the build instructions and can choose any license for your recipe file. -* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **In-File Identification (SPDX)**: Add an SPDX header comment to the first line of your Dockerfile: +* **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: -```dockerfile -# SPDX-License-Identifier: MIT -# Copyright (c) 2026 Research Group +```python +# SPDX-License-Identifier: EUPL-1.2 +# Copyright (c) 2026 Author Name -FROM ubuntu:24.04 -RUN apt-get update && apt-get install -y python3 +import numpy as np ``` - -* **User Obligation**: Users downloading your recipe file must preserve your copyright notice. ::: :::: -(scenario-7)= -::::{exercise} Scenario 7: Distributing a Built Container Image (Docker Hub or Apptainer .sif) -You build and publish a complete container runtime image (`.sif` or Docker Hub image) bundling a base Linux OS, system libraries, dependencies, and your application code. +(scenario-3)= +::::{exercise} Scenario 3: Embedding permissively licensed third-party code +You are building an RSE tool and copied a helper function or utility snippet from a third-party project licensed under a permissive license (e.g., MIT or Apache-2.0) directly into one of your source files. -* **Licensing Goal**: Comply with legal obligations when distributing a bundled binary filesystem image. -* **JLA Filter Focus**: N/A (Cannot apply a single JLA license filter to a multi-work binary bundle). +* **Licensing Goal**: You want to maintain a **permissive default** for your project while properly acknowledging and legally respecting the embedded third-party code. +* **Legal Reality**: Permissive licenses explicitly grant you permission to copy, modify, and embed their code into your repository. However, embedding permissive code does not make the original third-party copyright disappear, you must preserve the original copyright attribution and license terms for that specific snippet. +* **JLA Selection Strategy**: Because inbound permissive code gives you maximum licensing flexibility, your overall repository can remain permissively licensed. To reflect this, select citation obligations (`Incl. Copyright`) without imposing reciprocal sharing constraints (leaving `Copyleft/Share a.` unselected). :::{solution} -**Legal Reality**: Unlike a text recipe file, a compiled container image is a **bundle of separate third-party software works**. You do not hold exclusive copyright over the entire image filesystem. - -* **Outcome**: **Mandatory Multi-License Compliance.** Distribution is governed by the overlapping terms of all installed base layers, packages, and linked binaries inside. -* **Key Rule**: If your application links against a GPL library inside the container, image distribution triggers GPL source disclosure obligations for your app. If GPL tools in the container are standalone system utilities, *mere aggregation* applies. -* **User Obligation**: Ensure compliance with all third-party licenses bundled inside the container layers. -::: -:::: - ---- - -### Module 4: Modern AI Workflows โ€“ Assisted Code & Prompt Engineering +**What to select in the JLA interface:** -AI tools introduce distinct licensing considerations depending on whether you integrate AI-generated code snippets or author complex system prompt templates. +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` +3. **Support Column**: Select `OSI approved` -(scenario-8)= -::::{exercise} Scenario 8: Generating or assisting code using AI tools -You write software using AI coding assistants (ChatGPT, Copilot, DeepSeek) to generate functions, boilerplate, or refactor algorithms. +* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Licensing Goal**: Determine if using AI coding tools restricts your open-source license choices. -* **JLA Filter Focus**: Driven by human author intent (e.g., ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`). +* **Notice Preservation Nuance**: Permissive licenses are flexible, but they are not license-free. If you copy code from an Apache-2.0 or BSD-3-Clause project into your MIT-licensed repository, you must retain the original author's copyright statement and license identifier directly above the embedded code block. -:::{solution} -**Legal Reality**: Pure AI outputs lacking human authorship are generally ineligible for copyright. However, when you guide, refine, and integrate AI code into a project through creative human effort, you hold copyright over the resulting human-authored work. +* **Downstream Obligations**: Downstream users receive your project under your primary permissive license (e.g., MIT), but they must preserve both your overall copyright notice and the specific third-party notices attached to embedded snippets. -* **Global & Asian AI Tools (e.g., DeepSeek, Qwen)**: Code generated using open-weight models follows standard copyright rules (human creative oversight determines code ownership). However, distinguish between **generated code** and **model weights**: always review the **Model Weights License** (e.g., OpenRAIL or specific commercial restrictions) attached to the LLM itself. When collaborating internationally or using Asian open-source software, you may also encounter **MulanPSL-2.0** (an OSI-approved Chinese permissive license compatible with MIT/Apache-2.0). -* **Outcome**: **Fully Permissible.** Using AI tools does not force a specific open-source license onto your repository. -* **JLA Matches**: `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` (Author choice). -* **User Obligation**: Standard obligations apply based on the license you choose for your human-authored codebase. -::: -:::: +* **Allowed Inbound Snippets**: In addition to the embedded permissive snippet, you can freely embed other permissively licensed code (MIT, BSD, Apache-2.0) or public domain waivers (CC0). You cannot embed copyleft code (e.g., GPL, EUPL) without upgrading your entire repository's license to match that copyleft license. -(scenario-9)= -::::{exercise} Scenario 9: Including AI prompt templates in LLM applications -Your repository contains Python scripts alongside complex, 500-word structured prompt templates (system prompts, XML schemas, reasoning frameworks). +* **In-File Identification (SPDX)**: Mark both your overall file license and the specific embedded snippet using SPDX comments: -* **Licensing Goal**: Ensure prompt templates are legally covered under the same open-source license as your code. -* **JLA Filter Focus**: Treat engineered prompts as code assets: ๐ŸŸข `Commercial use` + โšช `Incl. Copyright`. - -:::{solution} -**Legal Reality**: Short functional prompts carry no copyright. However, complex, highly structured prompt templates meet the threshold of creative human expression and are legally protected as literary text assets. +```python +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name -* **Outcome**: **Fully Coverable.** Engineered prompt templates checked into your repository are covered under your overall repository license. -* **JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **In-File Identification (SPDX)**: Place SPDX comments at the top of structured prompt files: +# --- Embedded Third-Party Snippet --- +# SPDX-License-Identifier: Apache-2.0 +# Copyright (c) 2024 External Contributor +def fast_matrix_solver(matrix): + # Embedded algorithm implementation + return np.linalg.solve(matrix, np.eye(len(matrix))) +# --- End Embedded Snippet --- -```yaml -# SPDX-License-Identifier: MIT -# System Prompt: Structured Research Summarizer Framework +def main(): + pass ``` - -* **User Obligation**: Downstream users who copy your prompt files must preserve your copyright notice and file headers (`# SPDX-License-Identifier: MIT`). ::: :::: From f98fc72fba0e07afa16f1226ca508149eec29bb2 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 22:35:09 +0200 Subject: [PATCH 64/99] Update the scenarios 5,6 and 7 --- content/software-licensing.md | 177 +++++++++++++++++++++++++++++++++- 1 file changed, 175 insertions(+), 2 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index a19bd0b..38f8b87 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -303,6 +303,11 @@ import numpy as np ::: :::: +## Module 2: The Dependency Minefield โ€“ Inbound Code & Linking + +Embedding third-party source code snippets or linking against strong copyleft libraries +introduces legal boundaries that restrict your repository choices. + (scenario-3)= ::::{exercise} Scenario 3: Embedding permissively licensed third-party code You are building an RSE tool and copied a helper function or utility snippet from a third-party project licensed under a permissive license (e.g., MIT or Apache-2.0) directly into one of your source files. @@ -346,6 +351,176 @@ def main(): ::: :::: +(scenario-4)= +::::{exercise} Scenario 4: Embedding copyleft third-party code +You are building an software tool and copied a non-trivial code snippet from a third-party project licensed under a copyleft license (e.g., GPL-3.0 or EUPL-1.2) directly into one of your source files. + +* **Licensing Goal**: Comply with legal requirements imposed by the inbound copyleft code while ensuring your overall repository remains legally compliant. +* **Legal Reality**: Copyleft licenses require that any work containing copyleft code must be shared under a compatible copyleft license as a whole. Embedding copyleft code directly into your repository creates a single combined work, making copyleft licensing mandatory for your entire project. +* **JLA Selection Strategy**: Because the inbound copyleft code forces your repository to adopt reciprocal sharing terms, you must configure JLA to require source code disclosure (`Disclose source`) and reciprocal licensing (`Copyleft/Share a.`). + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `GPL-3.0`, `EUPL-1.2` + +* **Copyleft Scope & EUPL Compatibility (Legal Nuance)**: Directly copying copyleft code into your source files extends the copyleft obligation to your entire codebase. If the embedded snippet is `EUPL-1.2`, its built-in compatibility provisions allow you to license your combined project under `GPL-3.0` if your project ecosystem requires it, resolving license conflicts without violating EUPL terms. + +* **Downstream Obligations**: Anyone who receives, modifies, or distributes your repository must receive full access to the source code under the same copyleft license terms (`GPL-3.0` or `EUPL-1.2`) and preserve all copyright notices. + +* **Allowed Inbound Snippets**: Because your overall repository is now governed by a copyleft license, you can safely embed code from **permissive sources** (MIT, BSD, Apache-2.0, CC0) as well as **compatible copyleft sources**. You cannot embed proprietary, closed-source code or snippets from incompatible copyleft licenses. + +* **In-File Identification (SPDX)**: Mark your overall file license and clearly cite the embedded copyleft snippet using SPDX comments: + +```python +# SPDX-License-Identifier: GPL-3.0-or-later +# Copyright (c) 2026 Author Name + +# --- Embedded Copyleft Snippet --- +# SPDX-License-Identifier: GPL-3.0-or-later +# Copyright (c) 2023 External Researcher +def optimized_fft_filter(data_signal): + # Embedded copyleft algorithm implementation + return np.fft.fft(data_signal) +# --- End Embedded Snippet --- + +def main(): + pass +``` +::: +:::: + +## Module 3: Dependency Linking & Packaging + +When software incorporates external dependencies, whether by dynamic linking, static compiling, or bundling binaries into container images licensing obligations expand beyond your own written source code. This module covers how dependency boundaries, build automation scripts, and packaged container artifacts affect legal compliance under the Joinup Licensing Assistant (JLA) framework. + +--- + +(scenario-5)= +::::{exercise} Scenario 5: Linking against a GPL-licensed library +You are developing an software application that imports or links against an external software library licensed under GPL-3.0 (e.g., importing a GPL Python package or linking a C/C++ static/shared library). + +* **Licensing Goal**: Ensure legal compliance while using copyleft libraries as core dependencies in your software project. +* **Legal Reality**: Under mainstream copyright interpretation and the text of GPL-3.0, linking your code directly against a GPL library (whether statically or dynamically) creates a combined work. Consequently, the copyleft obligations of the external library extend to your entire repository. +* **JLA Selection Strategy**: Because linking to a GPL library requires your distributed project to be released under matching reciprocal terms, you must configure JLA to mandate source code disclosure (`Disclose source`) and reciprocal licensing (`Copyleft/Share a.`). + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `GPL-3.0`, `EUPL-1.2` + +* **Linking Boundaries & License Selection (Legal Nuance)**: + * **Why GPL forces copyleft**: Linking against a standard `GPL-3.0` library extends copyleft to your entire project. Your repository must adopt a compatible copyleft license (`GPL-3.0` or `EUPL-1.2`, which explicitly lists GPL-3.0 in its compatibility appendix). + * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library were licensed under `LGPL` (which has an explicit linking exemption) or `EUPL-1.2` (where linking across APIs under EU software law does not create a derivative work), copyleft would **not** extend to your application. In those cases, your own project could stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). Standard `GPL` is the key exception that forces your overall application to become copyleft. +* **Downstream Obligations**: Downstream users who receive or run your application must receive full access to your source code under `GPL-3.0` (or `EUPL-1.2`), along with all upstream copyright notices and build scripts required to recompile the project. + +* **Allowed Inbound Code & Dependencies**: Your project can import or include other **permissively licensed** packages (MIT, BSD, Apache-2.0) and public domain waivers (CC0). However, all code linked together in the final executable or runtime environment must satisfy GPL compatibility. + +* **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your main scripts: + +```python +# SPDX-License-Identifier: GPL-3.0-or-later +# Copyright (c) 2026 Author Name + +import gpl_licensed_solver # External GPL dependency forces GPL/EUPL compliance + +def solve_system(data): + return gpl_licensed_solver.compute(data) +``` +::: +:::: + +--- + +(scenario-6)= +::::{exercise} Scenario 6: Authoring container recipes and environment specifications +You are creating a `Dockerfile`, Conda `environment.yml`, or build recipe to automate the setup of your research environment. The recipe itself contains setup instructions, shell commands, and package lists. + +* **Licensing Goal**: You want **maximum adoption** and reuse of your build automation script so other researchers can freely adapt and build upon your workflow. +* **Legal Reality**: Build recipes and configuration scripts are plain-text source code separate from the software binaries they download at execution time. You hold copyright over the unique build instructions you write in the Dockerfile. +* **JLA Selection Strategy**: To allow anyone to reuse or adapt your container recipe without restrictions, you require citation credit (`Incl. Copyright`) while leaving reciprocal requirements (`Copyleft/Share a.`) unselected. + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` + +* **Recipe vs. Image Nuance**: The license applied to a `Dockerfile` covers only the recipe instructions, not the software packages installed inside the container when `docker build` runs. A permissively licensed Dockerfile can install both permissive and copyleft packages without legal conflict. + +* **Downstream Obligations**: Anyone who reuses or adapts your build recipe must preserve your original copyright notice in the header of the recipe file. + +* **Allowed Inbound Snippets**: You can freely include build commands and code snippets from permissively licensed build scripts or public domain code. + +* **In-File Identification (SPDX)**: Place SPDX identifier comments at the top of your Dockerfile or recipe file: + +```dockerfile +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name + +FROM ubuntu:24.04 +RUN apt-get update && apt-get install -y python3 python3-pip +COPY solver.py /app/solver.py +``` +::: +:::: + +--- + +(scenario-7)= +::::{exercise} Scenario 7: Distributing pre-built container images +You compiled and published a pre-built container image (e.g., pushing a compiled Docker image to Docker Hub, GitHub Container Registry, or an institutional registry) containing an OS layer, runtime binaries, dependencies, and your application code. + +* **Licensing Goal**: Safely distribute compiled container images without violating the license terms of any software layer or binary included inside the image. +* **Legal Reality**: A compiled container image is a **multi-license aggregate bundle**. Distributing pre-built binaries triggers source-code distribution obligations for any copyleft software (e.g., Linux base packages, coreutils, GPL libraries) pre-installed inside the image layers. +* **JLA Selection Strategy**: Because a container image combines multiple distinct software components, JLA is used to evaluate constituent component obligations. When distributing compiled binaries containing copyleft layers, source disclosure requirements (`Disclose source`) must be fulfilled for those specific layers. + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute` and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` and `Disclose source` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `Multi-License Bundle` (Governed by constituent package terms) + +* **Multi-License Aggregation Nuance**: Applying a permissive license (like MIT) to your application code inside the container does not override or erase the GPL/LGPL obligations of base system packages installed in `/usr/lib` or `/usr/bin`. Distributing the built image binary makes you a distributor of all installed packages. + +* **Downstream Obligations**: You must ensure that downstream users can obtain the source code for copyleft components shipped inside the image, typically by publishing the `Dockerfile` and build steps used to generate the image from public upstream sources. + +* **Allowed Inbound Packages**: Before publishing an image binary, run automated compliance scanning tools (e.g., Syft, Trivy) to generate a Software Bill of Materials (SBOM) and verify that no non-redistributable or proprietary software is packaged inside. + +* **In-File Identification (Metadata Annotations)**: Document the multi-license nature of the aggregate bundle using standard OCI (Open Container Initiative) image labels inside your Dockerfile: + +```dockerfile +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name + +FROM ubuntu:24.04 +LABEL org.opencontainers.image.authors="author@institute.eu" +# OCI Standard Image Annotations for Docker Hub Compliance +LABEL org.opencontainers.image.title="My Research Pipeline" +LABEL org.opencontainers.image.licenses="MIT AND GPL-3.0-or-later" +LABEL org.opencontainers.image.vendor="My Institute Name" +LABEL org.opencontainers.image.description="Includes Ubuntu 24.04 base layers (GPL/LGPL) and custom solver (MIT)" + +COPY solver.py /app/solver.py +``` +::: +:::: + + ## Best Practices: Attaching a License to Your Repository Once you have selected a license using the JLA, you must officially attach it to your repository so automated scanners, package registries, and downstream researchers can verify your terms. @@ -362,7 +537,6 @@ Always place the full text of your chosen license in a plain-text file named `LI ``` * **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Custom license edits create *non-standard* legal texts that compliance scanners cannot parse, defaulting your repository back to restricted status. ---- ### 2. Documenting License Status in `README.md` @@ -376,7 +550,6 @@ This project is licensed under the MIT License - see the [LICENSE](LICENSE) file [![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT) ``` ---- ### 3. Automated Compliance with the REUSE Standard From 2304e7136c5817485beabf8b03dc9149b94e32c3 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 22:42:18 +0200 Subject: [PATCH 65/99] Update the scenarios 8 and 9, on AI activity --- content/software-licensing.md | 85 +++++++++++++++++++++++++++++++++++ 1 file changed, 85 insertions(+) diff --git a/content/software-licensing.md b/content/software-licensing.md index 38f8b87..411ac6b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -520,6 +520,91 @@ COPY solver.py /app/solver.py ::: :::: +## Module 4: Emerging Workflows & AI + +AI-assisted development tools and machine learning models introduce unique legal challenges regarding copyright ownership, training data memorization, and behavioral restrictions. This module addresses how to license projects built with AI code generation tools and how to package research software that bundles AI models, weights, and datasets alongside source code. + +--- + +(scenario-8)= +::::{exercise} Scenario 8: AI-assisted code generation +You used AI tools (e.g., GitHub Copilot, ChatGPT, Claude) to write functions, unit tests, or documentation for your research software repository. + +* **Licensing Goal**: Retain clear ownership and apply a **permissive license** (`MIT` or `Apache-2.0`) to your repository without incurring hidden copyright infringement or copyleft obligations from code embedded during model training. +* **Legal Reality**: Unmodified AI-generated outputs lack human authorship and are generally not eligible for copyright protection under current EU and international legal standards. However, if an LLM reproduces a substantial copyrighted code snippet verbatim from its training data (memorization), that output snippet retains its original copyright and license obligations. +* **JLA Selection Strategy**: To ensure maximum adoption and academic reuse for your overall codebase, require citation credit (`Incl. Copyright`) while avoiding share-alike constraints (leaving `Copyleft/Share a.` unselected), supported by automated compliance checks. + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` + +* **AI Code Generation & Verification Nuance**: Because non-human AI output cannot hold copyright, your copyright applies to the overall project structure, human-written logic, and creative choices. To protect your repository against accidental copyright infringement or copyleft contamination from AI memorization, turn on public code matching filters in your AI tools and run automated code-similarity scanners before releasing your repository. + +* **Downstream Obligations**: Downstream users must preserve your copyright notice for the repository. They are free to reuse, modify, and integrate your code into commercial or open-source projects. + +* **Allowed Inbound Snippets**: You can include permissively licensed code, public domain code (CC0), and AI-generated snippets that have been verified against verbatim training data duplication. + +* **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: + +```python +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name + +def filter_sensor_data(raw_readings: list[float]) -> list[float]: + """Cleans raw sensor data (written with AI assistance and human review).""" + return [reading for reading in raw_readings if reading > 0.0] +``` +::: +:::: + +--- + +(scenario-9)= +::::{exercise} Scenario 9: Packaging AI workflows, datasets, and model weights +You are developing research software that includes source code alongside trained machine learning model weights (`.pt`, `.safetensors`) and benchmark datasets. + +* **Licensing Goal**: Apply a clear **dual-licensing strategy** that makes both the software source code and the non-code assets (data, weights) open and reusable under appropriate legal frameworks. +* **Legal Reality**: Standard open-source software licenses (MIT, GPL) are written specifically for source code and are legally ill-suited for datasets or neural network parameters. Under EU legal frameworks, datasets and model weights are governed by database rights (*sui generis* database protection) rather than traditional code copyright. +* **JLA Selection Strategy**: Use JLA to select an OSI-approved open-source license for the executable code component (`Incl. Copyright` selected), while using Creative Commons licenses (e.g., `CC-BY-4.0` or `CC0`) for the dataset and weight files. + +:::{solution} +**What to select in the JLA interface:** + +1. **Can Column**: Select `Distribute`, `Modify/merge`, and `Commercial use` +2. **Must Column**: Select `Incl. Copyright` +3. **Support Column**: Select `OSI approved` + +* **JLA Filter Matches**: `MIT`, `Apache-2.0` (for the code component) + +* **Code vs. Data/Weights & OpenRAIL Nuance**: Never apply software licenses like GPL or MIT to raw datasets or model weights. Use **CC-BY-4.0** or **CC0** for non-code assets. Additionally, behavioral licenses (such as OpenRAIL) impose usage restrictions (e.g., prohibiting specific harmful uses), which means they do **not** qualify as OSI-approved open-source software and cannot be filtered via standard JLA open-source queries. + +* **Downstream Obligations**: Downstream users must cite your repository for the code (under your chosen software license) and give credit for the model weights and data under the corresponding Creative Commons license. + +* **Allowed Inbound Assets**: You may combine permissively licensed python code with CC-BY-4.0 datasets or open-weight models, provided the attribution files clearly separate code licenses from data/weight licenses. + +* **In-File Identification (SPDX / Dual-Licensing Structure)**: Document the dual-licensing scheme in your root repository structure and script headers: + +```python +# SPDX-License-Identifier: MIT +# Copyright (c) 2026 Author Name +# +# Note: Source code is licensed under MIT. +# Model weights in /models/ and datasets in /data/ are licensed under CC-BY-4.0. + +import torch + +def load_pipeline(): + model = torch.load("models/climate_weights.safetensors") + return model +``` +::: +:::: + ## Best Practices: Attaching a License to Your Repository From 73c9c54eed8fceb57752bf5a73be013ea06ce648 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 22:58:47 +0200 Subject: [PATCH 66/99] update summary --- content/software-licensing.md | 43 +++++++++++++++++++---------------- 1 file changed, 23 insertions(+), 20 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 411ac6b..d42f11e 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -655,42 +655,45 @@ legal status of every single asset in your codebase. ## Summary: Resolving the Compliance Pipeline -At the start of this lesson, our project hit a **โŒ BUILD FAILURE** because a pasted copyleft snippet conflicted with our target `MIT` license. +When developing research software, license compliance is not an afterthought to debug at the end of a project, it is a proactive design choice. By using the **Joinup Licensing Assistant (JLA)** framework to align your repository license with your inbound dependencies from day one, your CI/CD pipeline passes cleanly on the first run. -By applying the legal concepts and technical tools covered in this module, we can trace how our learned skills directly resolve the original pipeline crash: +The diagram below illustrates how selecting a compatible license upfront ensures your code passes automated compliance checks and results in a legally sound release: ```{mermaid} + %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB - subgraph box["Resolved CI/CD License Compliance Pipeline"] - A["Build Trigger: Push code with inbound dependency/snippet"] --> B["Run Compliance Scanner"] - B --> C{"Check Inbound vs Outbound Terms"} - - C -->|"Apply JLA Decision Matrix &Copyright Principles"| E{"Select Compliant Strategy"} + subgraph local["1. Local Authoring & Standardization"] + A["Inbound Reuse Trigger:
User copies copyleft snippet (Scenario 4)
or links GPL library (Scenario 5)"] --> B["JLA Selection Strategy:
Select compatible copyleft license
(GPL-3.0 / EUPL-1.2)"] - E -->|"Strategy 1: Align Project License(Module 2)Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASSProject license matches inbound copyleft terms"] + B --> C["Standardize Local Codebase:
1. Add SPDX Headers to all files (Scenarios 1-9)
2. Add root LICENSE file & README badge"] + end + + subgraph cicd["2. Automated CI/CD & Verification"] + C -->|"Git Push to Repository"| D["Build Trigger: Run Compliance Scanner
(Executes reuse lint in CI/CD)"] - E -->|"Strategy 2: Clean Implementation(Module 1)Rewrite code expression from scratch"| H["โœ… BUILD PASSFresh expression frees original MIT license"] + D --> E{"Verify Inbound vs.
Outbound Terms
"} - G --> V["Standardize & Verify Repository1. Tag files with SPDX Identifiers (# SPDX-License-Identifier)2. Add root LICENSE file & README badge3. Execute REUSE Linter (reuse lint)"] - H --> V + E -->|"SPDX Headers & License Match Confirmed!"| F["โœ… BUILD PASSES
Compliance verified automatically"] - V --> SUCCESS["๐ŸŽ‰ COMPLIANT OPEN-SOURCE RELEASELegally safe, reproducible & ready for research reuse"] + F --> SUCCESS["๐ŸŽ‰ COMPLIANT OPEN-SOURCE RELEASE
Legally sound, reproducible & ready for scientific reuse"] end classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; - class G,H,V,SUCCESS pass; - class A,B,C,E neutral; - class box box_fill; + class F,SUCCESS pass; + class A,B,C,D,E neutral; + class local,cicd box_fill; ``` -### What Resolved the Issue: -1. **Applied Copyright Expression vs. Idea (Option C)**: You learned that copyright protects code *expression*, not underlying algorithms. Rewriting the logic creates a fresh copyright, freeing you to maintain an `MIT` permissive license. -2. **Applied the JLA Decision Matrix (Option B)**: You learned how to navigate inbound copyleft obligations. Re-licensing the repository to `GPL-3.0` or `EUPL-1.2` satisfies reciprocal terms while keeping your work open source. -3. **Bypassed Legal Traps (Options A & D)**: You recognized that code comments cannot waive statutory licenses and that deleting a license triggers the default *"All Rights Reserved"* trap. -4. **Standardized Distribution**: You embedded **SPDX headers** across code, recipes, and prompts, verifying full repository compliance via `reuse lint`. +### Scenario Mapping Across the Pipeline + +* **Handling Inbound Copyleft ([Scenario 4](#scenario-4) & [Scenario 5](#scenario-5))**: When you copy non-trivial copyleft code snippets (e.g., CC BY-SA from Stack Overflow or GPL snippets) or link directly against a GPL library, your overall project becomes a combined work. Selecting a compatible copyleft license upfront (`GPL-3.0` or `EUPL-1.2`) satisfies the reciprocal sharing terms and allows the pipeline scanner to pass without conflict. +* **Maintaining Permissive Defaults ([Scenario 1](#scenario-1) & [Scenario 3](#scenario-3))**: If you write original code or embed only permissively licensed snippets (MIT, Apache-2.0, BSD), selecting a permissive license (`MIT` or `Apache-2.0`) grants downstream users maximum adoption freedom while preserving your citation credit. +* **Packaging and Build Automation ([Scenario 6](#scenario-6) & [Scenario 7](#scenario-7))**: Keep plain-text build recipes (Dockerfiles) permissively licensed for maximum reuse, while annotating compiled container image binaries as multi-license aggregate bundles to satisfy embedded base-layer obligations. +* **AI Assets and Dual-Licensing ([Scenario 8](#scenario-8) & [Scenario 9](#scenario-9))**: Run code-similarity scanners to catch LLM training memorization before releasing AI-assisted code, and apply dual-licensing to separate executable software code (`MIT`) from non-code datasets and model weights (`CC-BY-4.0`). +* **Standardized Distribution**: By adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template, running `reuse lint` in your pipeline confirms 100% legal clarity for the entire scientific community. From 43f6a559e2d43f55049fceaf55888a985c43e8e7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Fri, 18 Sep 2026 23:42:32 +0200 Subject: [PATCH 67/99] Remove EUPL , LGPL level claim --- content/software-licensing.md | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index d42f11e..0b1d6c1 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -398,8 +398,6 @@ def main(): When software incorporates external dependencies, whether by dynamic linking, static compiling, or bundling binaries into container images licensing obligations expand beyond your own written source code. This module covers how dependency boundaries, build automation scripts, and packaged container artifacts affect legal compliance under the Joinup Licensing Assistant (JLA) framework. ---- - (scenario-5)= ::::{exercise} Scenario 5: Linking against a GPL-licensed library You are developing an software application that imports or links against an external software library licensed under GPL-3.0 (e.g., importing a GPL Python package or linking a C/C++ static/shared library). @@ -419,7 +417,8 @@ You are developing an software application that imports or links against an exte * **Linking Boundaries & License Selection (Legal Nuance)**: * **Why GPL forces copyleft**: Linking against a standard `GPL-3.0` library extends copyleft to your entire project. Your repository must adopt a compatible copyleft license (`GPL-3.0` or `EUPL-1.2`, which explicitly lists GPL-3.0 in its compatibility appendix). - * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library were licensed under `LGPL` (which has an explicit linking exemption) or `EUPL-1.2` (where linking across APIs under EU software law does not create a derivative work), copyleft would **not** extend to your application. In those cases, your own project could stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). Standard `GPL` is the key exception that forces your overall application to become copyleft. + * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library is licensed under `LGPL` (which includes an explicit linking exception) or `EUPL-1.2` (where European Commission guidance takes the position that dynamically linking an EUPL work through its API does not by itself create a derivative work), copyleft does not extend to your application. In these dynamic linking scenarios, your own project can stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). However, note that this EUPL stance reflects Commission guidance rather than settled CJEU case law, and static linking or direct code incorporation continues to trigger EUPL copyleft obligations. + * **Downstream Obligations**: Downstream users who receive or run your application must receive full access to your source code under `GPL-3.0` (or `EUPL-1.2`), along with all upstream copyright notices and build scripts required to recompile the project. * **Allowed Inbound Code & Dependencies**: Your project can import or include other **permissively licensed** packages (MIT, BSD, Apache-2.0) and public domain waivers (CC0). However, all code linked together in the final executable or runtime environment must satisfy GPL compatibility. @@ -438,7 +437,6 @@ def solve_system(data): ::: :::: ---- (scenario-6)= ::::{exercise} Scenario 6: Authoring container recipes and environment specifications From 05a775e12034d2c314ccb6ec9f44786e4bf18bc2 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 12:10:12 +0200 Subject: [PATCH 68/99] Change mermaid orientation to check rendering --- content/software-licensing.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 0b1d6c1..66925e9 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -55,7 +55,7 @@ comply with terms attached to code written by others (inbound reuse). ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% -flowchart TB +flowchart LR subgraph box["How License Selection Governs Code Reuse"] A["Your Research Codebase (Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] From 54fa163bc19b94b5e9bb6ee704877b3ffdde692e Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 21:49:02 +0200 Subject: [PATCH 69/99] Include JLA link right before scenario intro --- content/software-licensing.md | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 66925e9..8f7b8c6 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -211,10 +211,16 @@ To help you navigate open-source compliance, the matrix below serves as an upfro quick-reference summary and interactive index for the core licensing scenarios encountered in research software engineering. -Our decision framework is grounded in the European Commission's **Joinup Licensing Assistant (JLA)**, -which evaluates software assets across six criteria categories: **Can** (Permissions), -**Must** (Obligations), **Cannot** (Restrictions), **Compatible** (Interoperability), -**Law** (Jurisdiction), and **Support** (Governance). + +* [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) + * Our decision framework is grounded in the European Commission's **JLA**, which evaluates software + assets across six criteria categories: + * Can (Permissions) + * Must (Obligations) + * Cannot (Restrictions) + * Compatible** (Interoperability) + * Law (Jurisdiction) + * Support(Governance) Use this index to preview the demonstrated path for each scenario, or click any module link to jump directly to its detailed exercise, legal analysis, and JLA selection instructions. @@ -222,7 +228,7 @@ directly to its detailed exercise, legal analysis, and JLA selection instruction | Scenario Module | Demonstrated Path / Focus | Compliant Target Licenses | | :--- | :--- | :--- | | [**1. Own Code**](#scenario-1) | ๐ŸŸข Permissive *(Default Choice)* | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| [**2. Math Implementation**](#scenario-2) | ๐ŸŸก Copyleft / Reciprocal | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| [**2. Implement an algorithm**](#scenario-2) | ๐ŸŸก Copyleft / Reciprocal | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | | [**3. Embed Permissive**](#scenario-3) | ๐ŸŸข Permissive Focus *(Copyleft Flexible)* | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | | [**4. Embed Copyleft**](#scenario-4) | ๐ŸŸก Mandatory Copyleft | `EUPL-1.2`, `GPL-3.0` | | [**5. Link GPL Library**](#scenario-5) | ๐ŸŸก Mandatory Copyleft | `GPL-3.0`, `EUPL-1.2` | From 7a044b7190d16bf7ca7f25480881a86d233a8f14 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 21:51:11 +0200 Subject: [PATCH 70/99] Update content/software-licensing-old.md Co-authored-by: Richard Darst --- content/software-licensing-old.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing-old.md b/content/software-licensing-old.md index 112a713..3707f90 100644 --- a/content/software-licensing-old.md +++ b/content/software-licensing-old.md @@ -1,4 +1,4 @@ -# Software licensing +# OLD Software licensing ```{objectives} - Knowing about what derivative work is and whether we can share it. From d75e3354247e0c1a24cdb20da65918a90868a1f9 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 21:54:10 +0200 Subject: [PATCH 71/99] Fix heading level --- content/software-licensing.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 8f7b8c6..938fd10 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -191,7 +191,7 @@ which is why this lesson equips you with a direct, EU-aligned framework for soft -### Standardizing In-File Declarations: SPDX Identifiers +## Standardizing In-File Declarations: SPDX Identifiers Selecting a license is only half the battle; automated scanners and CI/CD pipelines need a machine-readable way to verify license compliance per file without parsing long legal texts. @@ -205,14 +205,14 @@ Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exc Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. -### License Selection Decision Matrix & Scenario Index +## License Selection Decision Matrix & Scenario Index To help you navigate open-source compliance, the matrix below serves as an upfront quick-reference summary and interactive index for the core licensing scenarios encountered in research software engineering. -* [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) +### [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) * Our decision framework is grounded in the European Commission's **JLA**, which evaluates software assets across six criteria categories: * Can (Permissions) From dfad432f01b6fe315ed0212455fc70d2bf718b58 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 21:56:39 +0200 Subject: [PATCH 72/99] Indicate that JLA matches shown are examples --- content/software-licensing.md | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 938fd10..af1b1ad 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -256,7 +256,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your 2. **Must Column**: Select `Incl. Copyright` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Permissive vs. Public Domain (EU Civil Law Nuance)**: Public domain dedications (e.g., `CC0`, `Unlicense`) attempt to give away all rights. However, under EU civil law, authors cannot legally give up their moral rights (*droit moral*). Selecting an explicit permissive license like `MIT` or `Apache-2.0` grants broad permissions globally, remains legally valid under European copyright law, and guarantees academic citation credit. @@ -290,7 +290,7 @@ You developed a custom mathematical solver implementing algorithms from academic 2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` +* **Example JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` * **Copyleft Mechanics (EUPL vs. GPL Nuance)**: `GPL-3.0` is the standard global copyleft license, but `EUPL-1.2` is specifically tailored for European institutions. EUPL-1.2 is officially published in 23 EU language versions (each with equal legal validity), includes built-in compatibility clauses with GPL, and explicitly defaults to EU Member State jurisdiction and courts. @@ -329,7 +329,7 @@ You are building an RSE tool and copied a helper function or utility snippet fro 2. **Must Column**: Select `Incl. Copyright` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Notice Preservation Nuance**: Permissive licenses are flexible, but they are not license-free. If you copy code from an Apache-2.0 or BSD-3-Clause project into your MIT-licensed repository, you must retain the original author's copyright statement and license identifier directly above the embedded code block. @@ -372,7 +372,7 @@ You are building an software tool and copied a non-trivial code snippet from a t 2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `GPL-3.0`, `EUPL-1.2` +* **Example JLA Matches**: `GPL-3.0`, `EUPL-1.2` * **Copyleft Scope & EUPL Compatibility (Legal Nuance)**: Directly copying copyleft code into your source files extends the copyleft obligation to your entire codebase. If the embedded snippet is `EUPL-1.2`, its built-in compatibility provisions allow you to license your combined project under `GPL-3.0` if your project ecosystem requires it, resolving license conflicts without violating EUPL terms. @@ -419,7 +419,7 @@ You are developing an software application that imports or links against an exte 2. **Must Column**: Select `Incl. Copyright`, `Disclose source`, and `Copyleft/Share a.` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `GPL-3.0`, `EUPL-1.2` +* **Example JLA Matches**: `GPL-3.0`, `EUPL-1.2` * **Linking Boundaries & License Selection (Legal Nuance)**: * **Why GPL forces copyleft**: Linking against a standard `GPL-3.0` library extends copyleft to your entire project. Your repository must adopt a compatible copyleft license (`GPL-3.0` or `EUPL-1.2`, which explicitly lists GPL-3.0 in its compatibility appendix). @@ -459,7 +459,7 @@ You are creating a `Dockerfile`, Conda `environment.yml`, or build recipe to aut 2. **Must Column**: Select `Incl. Copyright` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **Recipe vs. Image Nuance**: The license applied to a `Dockerfile` covers only the recipe instructions, not the software packages installed inside the container when `docker build` runs. A permissively licensed Dockerfile can install both permissive and copyleft packages without legal conflict. @@ -497,7 +497,7 @@ You compiled and published a pre-built container image (e.g., pushing a compiled 2. **Must Column**: Select `Incl. Copyright` and `Disclose source` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `Multi-License Bundle` (Governed by constituent package terms) +* **Example JLA Matches**: `Multi-License Bundle` (Governed by constituent package terms) * **Multi-License Aggregation Nuance**: Applying a permissive license (like MIT) to your application code inside the container does not override or erase the GPL/LGPL obligations of base system packages installed in `/usr/lib` or `/usr/bin`. Distributing the built image binary makes you a distributor of all installed packages. @@ -545,7 +545,7 @@ You used AI tools (e.g., GitHub Copilot, ChatGPT, Claude) to write functions, un 2. **Must Column**: Select `Incl. Copyright` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` +* **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` * **AI Code Generation & Verification Nuance**: Because non-human AI output cannot hold copyright, your copyright applies to the overall project structure, human-written logic, and creative choices. To protect your repository against accidental copyright infringement or copyleft contamination from AI memorization, turn on public code matching filters in your AI tools and run automated code-similarity scanners before releasing your repository. @@ -583,7 +583,7 @@ You are developing research software that includes source code alongside trained 2. **Must Column**: Select `Incl. Copyright` 3. **Support Column**: Select `OSI approved` -* **JLA Filter Matches**: `MIT`, `Apache-2.0` (for the code component) +* **Example JLA Matches**: `MIT`, `Apache-2.0` (for the code component) * **Code vs. Data/Weights & OpenRAIL Nuance**: Never apply software licenses like GPL or MIT to raw datasets or model weights. Use **CC-BY-4.0** or **CC0** for non-code assets. Additionally, behavioral licenses (such as OpenRAIL) impose usage restrictions (e.g., prohibiting specific harmful uses), which means they do **not** qualify as OSI-approved open-source software and cannot be filtered via standard JLA open-source queries. From 06357d704323f5d47f6f9835832c2c90809a9fac Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 22:41:12 +0200 Subject: [PATCH 73/99] lock mephinxcontrib-mermaid version untill a solution found for rendering --- content/software-licensing.md | 2 +- requirements.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index af1b1ad..4b4c708 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -55,7 +55,7 @@ comply with terms attached to code written by others (inbound reuse). ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% -flowchart LR +flowchart TB subgraph box["How License Selection Governs Code Reuse"] A["Your Research Codebase (Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] diff --git a/requirements.txt b/requirements.txt index d98c203..0bb27c6 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,7 +1,7 @@ Sphinx sphinx_rtd_theme sphinx_rtd_theme_ext_color_contrast -sphinxcontrib.mermaid +phinxcontrib-mermaid==0.7.1 myst_nb git+https://github.com/rkdarst/sphinx-copybutton.git@exclude-unselectable-3 sphinx-lesson From 3b2246a32128f228d30274d6dc7254d4f04eb8ed Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 22:44:44 +0200 Subject: [PATCH 74/99] Fix typo in package name --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 0bb27c6..684c460 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,7 +1,7 @@ Sphinx sphinx_rtd_theme sphinx_rtd_theme_ext_color_contrast -phinxcontrib-mermaid==0.7.1 +sphinxcontrib-mermaid==0.7.1 myst_nb git+https://github.com/rkdarst/sphinx-copybutton.git@exclude-unselectable-3 sphinx-lesson From ebfc14168ba05f5c6c36e9a0ca08520c20fa2b4f Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Mon, 21 Sep 2026 23:03:08 +0200 Subject: [PATCH 75/99] Reduce lesson duration by not presentting all scenarios --- content/index.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/index.rst b/content/index.rst index cb019e3..430a25f 100644 --- a/content/index.rst +++ b/content/index.rst @@ -40,7 +40,7 @@ navigating and deciding on licenses. :delim: ; 20 min ; :doc:`social-coding` - 90 min ; :doc:`software-licensing` + 45 min ; :doc:`software-licensing` 20 min ; :doc:`software-citation` 10 min ; :doc:`sharing-data` From 232d235c29e43cfa81afaf4888a667a190c64277 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 23 Sep 2026 13:23:26 +0200 Subject: [PATCH 76/99] Fix terminology accordgin to EU regualtions --- content/software-licensing.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 4b4c708..a36a006 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -41,12 +41,12 @@ comply with terms attached to code written by others (inbound reuse). * Open-source licenses fall into two main families: - * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep crediti*. + * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit*. Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. * **Copyleft/Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom - to run and modify, but mandates that any distributed derivative or combined work must + to run and modify, but mandates that any distributed adaptations or combined work must also be released under matching copyleft terms. Often informally referred to as *viral* or *infectious* because its open-source requirements propagate across code boundaries (such as embedding snippets or static linking) into downstream projects. The diagram @@ -281,7 +281,7 @@ You developed a custom mathematical solver implementing algorithms from academic * **Licensing Goal**: You want to enforce **reciprocity** (share-alike), preventing third parties from incorporating your algorithm into proprietary, closed-source software without sharing their modifications. * **Legal Reality**: Mathematical concepts and formulas themselves are not copyrightable, but your specific code implementation is fully protected by copyright. Applying a copyleft license legally binds anyone who distributes modified versions of your implementation to release their source code under matching reciprocal terms. -* **JLA Selection Strategy**: To enforce reciprocal sharing, you must mandate that downstream distributors disclose their modified source code (`Disclose source`) and license their derivative works under matching terms (`Copyleft/Share a.`). +* **JLA Selection Strategy**: To enforce reciprocal sharing, you must mandate that downstream distributors disclose their modified source code (`Disclose source`) and license their adaptations or combined worrks under matching terms (`Copyleft/Share a.`). :::{solution} **What to select in the JLA interface:** @@ -423,7 +423,7 @@ You are developing an software application that imports or links against an exte * **Linking Boundaries & License Selection (Legal Nuance)**: * **Why GPL forces copyleft**: Linking against a standard `GPL-3.0` library extends copyleft to your entire project. Your repository must adopt a compatible copyleft license (`GPL-3.0` or `EUPL-1.2`, which explicitly lists GPL-3.0 in its compatibility appendix). - * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library is licensed under `LGPL` (which includes an explicit linking exception) or `EUPL-1.2` (where European Commission guidance takes the position that dynamically linking an EUPL work through its API does not by itself create a derivative work), copyleft does not extend to your application. In these dynamic linking scenarios, your own project can stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). However, note that this EUPL stance reflects Commission guidance rather than settled CJEU case law, and static linking or direct code incorporation continues to trigger EUPL copyleft obligations. + * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library is licensed under `LGPL` (which includes an explicit linking exception) or `EUPL-1.2` (where European Commission guidance takes the position that dynamically linking an EUPL work through its API does not by itself create a adaptation work), copyleft does not extend to your application. In these dynamic linking scenarios, your own project can stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). However, note that this EUPL stance reflects Commission guidance rather than settled CJEU case law, and static linking or direct code incorporation continues to trigger EUPL copyleft obligations. * **Downstream Obligations**: Downstream users who receive or run your application must receive full access to your source code under `GPL-3.0` (or `EUPL-1.2`), along with all upstream copyright notices and build scripts required to recompile the project. From 76ad7270304d280ea594678e9559b5b49e58a74a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Wed, 23 Sep 2026 13:29:11 +0200 Subject: [PATCH 77/99] Fix terminology callout --- content/software-licensing.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/content/software-licensing.md b/content/software-licensing.md index a36a006..0a3216e 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -189,6 +189,15 @@ face a different legal reality related to exceptions, author ownership, and code Relying blindly on AI legal advice creates significant compliance blind spots, which is why this lesson equips you with a direct, EU-aligned framework for software licensing. +```{discussion} Terminology Trap: "Derivative Work" (US) vs. "Adaptation" (EU) + +When searching online or asking AI coding assistants about software modification, you will almost always encounter the term **"derivative work"**. Understanding the origin of this term is crucial for EU-based software developers: + +* **US Common Law (17 U.S.C. ยง 101)**: Formally defines and uses the term *"Derivative Work"*. Because AI models and search engines are heavily trained on US web data, AI assistants default to using "derivative work" for almost any code modification. +* **EU Statutory Law (Directive 2009/24/EC, Art. 4(1)(b))**: Does **not** use or recognize the term "derivative work". Instead, EU software copyright grants exclusive rights over **"translation, adaptation, arrangement, and any other alteration "**collectively governed under EU law as an **adaptation**. +* **Why Licenses Use "Derivative Work"**: License contracts like `EUPL-1.2` or `GPL-3.0` define "Derivative Works" within their legal text as a contractual term to ensure international enforceability across jurisdictions, even though EU statutes govern the act as an *adaptation*. + +**Key Takeaway**: When AI tells you that a snippet or linked library creates a "derivative work", remember that under EU law you must evaluate whether the modification constitutes a statutory **adaptation** or a **combined work** across API boundaries. ## Standardizing In-File Declarations: SPDX Identifiers From 30ec29ea6dae9e1fd4e104090237551661666ded Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 17:50:31 +0200 Subject: [PATCH 78/99] Roni recomendations for Limitation and context of this lesson --- content/software-licensing.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 0a3216e..4e884b2 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -13,7 +13,7 @@ This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** -* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. +* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. At the same time EU has directives they only set the minimum requirements in some aspects, but Member states may have different implementations and additional regulation that are not covered here e.g. some member states have made exceptions so that University researchers retain their ownership to computer programs thus are not treated like employees * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. * This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. From 833c5df9925e4652ab9fd7de66589dab10eeb1c9 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:08:51 +0200 Subject: [PATCH 79/99] Roni recomendations author and copyright holder my differ --- content/software-licensing.md | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 4e884b2..b9e450b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -13,7 +13,7 @@ This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** -* Regional Focus: Guidance is grounded in EU statutory directives, European institutional frameworks and developers based in Europe with a global focus. At the same time EU has directives they only set the minimum requirements in some aspects, but Member states may have different implementations and additional regulation that are not covered here e.g. some member states have made exceptions so that University researchers retain their ownership to computer programs thus are not treated like employees +* EU directives set only minimum requirements in some areas: Member States implement them differently and may add national rules not covered here. For example, some Member States let university researchers retain ownership of the programs they write instead of applying the employer rule in Art. 2(3). * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. * This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. @@ -29,11 +29,9 @@ If you need formal guidance references below and legal experts, especially if yo ## Introduction: What is a Software License? -Under copyright law worldwide, software without an explicit license automatically -defaults to *All Rights Reserved*: meaning nobody else has the legal right to run, -modify, embed, or cite your code. A software license is a legal permission grant -created by the author that overrides this statutory default, defining how -downstream researchers can reuse your work. +Under copyright law worldwide, software without an explicit license defaults to All Rights Reserved: nobody else may run, copy, modify, distribute, or build on your code. A software license is how the copyright holder exercises their exclusive rights, granting others permission to reproduce, distribute, modify, and sometimes sublicense the work. + +Note that author and copyright holder may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. In this lesson, we focus on open-source licenses to define both how we grant permissions for software we develop (outbound licensing) and how we safely @@ -621,7 +619,7 @@ def load_pipeline(): ## Best Practices: Attaching a License to Your Repository -Once you have selected a license using the JLA, you must officially attach it to your repository so automated scanners, package registries, and downstream researchers can verify your terms. +Once you have selected a license using the JLA, you must officially attach it to your repository so automated scanners, package registries, and downstream users can verify your terms. ### 1. Adding the Root `LICENSE` File From a11b00fab5107fcab9e595295c50368b8850c1cc Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:25:08 +0200 Subject: [PATCH 80/99] Roni include LGPL --- content/software-licensing.md | 27 +++++++++++++-------------- 1 file changed, 13 insertions(+), 14 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index b9e450b..6990160 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -31,24 +31,23 @@ If you need formal guidance references below and legal experts, especially if yo Under copyright law worldwide, software without an explicit license defaults to All Rights Reserved: nobody else may run, copy, modify, distribute, or build on your code. A software license is how the copyright holder exercises their exclusive rights, granting others permission to reproduce, distribute, modify, and sometimes sublicense the work. -Note that author and copyright holder may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. +Note that author and copyright holder may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. This matters in practice, because the person choosing the license for a research project is often not the person who wrote the code. -In this lesson, we focus on open-source licenses to define both how we grant -permissions for software we develop (outbound licensing) and how we safely -comply with terms attached to code written by others (inbound reuse). +In this lesson, we focus on open-source licenses to define both how we grant permissions for software we develop (outbound licensing) and how we safely comply with terms attached to code written by others (inbound reuse). -* Open-source licenses fall into two main families: +Open-source licenses fall into three main families: - * **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit*. - Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code - in open or closed projects. +* **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit.* Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. - * **Copyleft/Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom - to run and modify, but mandates that any distributed adaptations or combined work must - also be released under matching copyleft terms. Often informally referred to as *viral* - or *infectious* because its open-source requirements propagate across code boundaries - (such as embedding snippets or static linking) into downstream projects. The diagram - below unifies these license choices and their downstream rights: +* **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom to run and modify, but requires that any distributed adaptation or combined work also be released under matching copyleft terms. + +* **Weak copyleft (e.g., LGPL-3.0, MPL-2.0, EPL-2.0):** *Share alike, but only within a boundary.* Reciprocity applies to the file (MPL-2.0) or the library (LGPL), not to your whole project. Your surrounding code can usually stay permissive or even closed, while modifications to the covered files or library must stay open. + +You will hear copyleft called *viral* or *infectious* in developer conversation. The slang is worth knowing, but it is misleading in two ways: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or a container image is unaffected, and the requirement only triggers when you **distribute**, not when you run modified code internally. Reciprocity reaches only across specific technical boundaries such as embedding snippets or static linking, and how far it reaches depends on which copyleft license you are dealing with. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. + +Weak copyleft is worth a closer look, because it is widely used and its terms are more conditional than the label suggests. LGPL-3.0 ยง4 lets you ship a combined work under your own terms only if those terms do not restrict modification of the LGPL portions, or reverse engineering for debugging those modifications, and this condition applies whether you linked statically or dynamically. Since most proprietary end-user licenses forbid reverse engineering, the common shorthand that "dynamic linking is safe" is not the whole story. The practical lesson is that "does this dependency force my project open?" has no general answer: it depends on which copyleft license, and at which boundary. + +The diagram below unifies these license choices and their downstream rights: ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% From 1317cc2c6ab8418c51b1f84604c60262705dcb69 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:27:29 +0200 Subject: [PATCH 81/99] Roni include LGPL in mermaid --- content/software-licensing.md | 50 +++++++++++++++++++++++------------ 1 file changed, 33 insertions(+), 17 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 6990160..b58fe35 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -55,37 +55,53 @@ The diagram below unifies these license choices and their downstream rights: flowchart TB subgraph box["How License Selection Governs Code Reuse"] - A["Your Research Codebase (Source code, container recipes, prompt templates)"] -->|"No License Attached(Statutory Default)"| B["All Rights ReservedโŒ Zero permissions: Cannot run, modify, or share"] + A["Your Research Codebase
(Source code, container recipes, prompt templates)"] -->|"No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Cannot run, modify, or share"] - A -->|"Attach License(Explicit Permission Grant)"| C{"Select License"} + A -->|"Attach License
(Explicit Permission Grant)"| C{"Select License"} - C -->|"Goal: Maximum adoption & unrestricted reuse"| D["Permissive License"] - C -->|"Goal: Ensure changes stay open-source (Reciprocity)"| E["Copyleft License"] - C -->|"Goal: Proprietary control & restricted access"| F["Closed Source / Restricted๐Ÿšซ Flavour not discussed in this lesson"] + C -->|"Goal: Maximum adoption & unrestricted reuse"| D["Permissive
MIT, Apache-2.0, 0BSD"] + C -->|"Goal: Keep the library open, allow closed users"| W["Weak Copyleft
LGPL-3.0, MPL-2.0, EPL-2.0"] + C -->|"Goal: Ensure changes stay open-source (Reciprocity)"| E["Copyleft
GPL-3.0, EUPL-1.2"] + C -->|"Goal: Proprietary control & restricted access"| F["Closed Source / Restricted
๐Ÿšซ Not discussed in this lesson"] - D --> D1["Run & Modify? Yes!"] - D --> D2["Embed in closed product? Yes!"] - D --> D3["Must changes stay open? No (Optional)"] + D --> D1["Run & Modify? Yes"] + D --> D2["Embed in closed product? Yes"] + D --> D3["Must changes stay open? No (optional)"] + + W --> W1["Run & Modify? Yes"] + W --> W2["Embed in closed product? Yes, with conditions"] + W --> W3["Must changes stay open? Only the covered file or library"] + + E --> E1["Run & Modify? Yes"] + E --> E2["Embed in closed product? No"] + E --> E3["Must changes stay open? Yes (mandatory)"] + end + + G["Reciprocity only triggers on distribution
Running modified code internally creates no obligation"] + E -.-> G + W -.-> G - E --> E1["Run & Modify? Yes!"] - E --> E2["Embed in closed product? No!"] - E --> E3["Must changes stay open? Yes! (Mandatory)"] - end classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef white fill:#f8f9fa,stroke:#adb + classDef amber fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; + classDef white fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,color:#212529; classDef dashed fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; classDef dashed_red fill:#ffe3e3,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; - classDef defaultState fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef note fill:#ffffff,stroke:#868e96,stroke-width:1px,stroke-dasharray: 3 3,color:#212529; classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; - - class D1,D2,D3,E1,E3 green; + + class D1,D2,D3,W1,E1 green; + class W2,W3 amber; class E2 red; - class D,E yellow; + class E3 green; + class D yellow; + class W amber; + class E yellow; class F dashed; class B dashed_red; class A,C white; + class G note; class box box_fill; ``` From b91b0ea5d05f6b2662c4724f621615a5f08f9145 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:31:12 +0200 Subject: [PATCH 82/99] Roni suggesion, Copyright Foundation: Expression vs. Ideas --- content/software-licensing.md | 35 +++++++++++------------------------ 1 file changed, 11 insertions(+), 24 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index b58fe35..7609c56 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -107,37 +107,24 @@ flowchart TB ### Copyright Foundation: Expression vs. Ideas -To understand why licenses are required, you must understand how copyright law treats software. -Under EU statutory law (Directive 2009/24/EC) and international treaties, software is protected -under copyright as a **literary work**. +Under Directive 2009/24/EC, software is protected by copyright as a **literary work** (Art. 1(1)). But copyright protects only the **expression**, not the ideas beneath it: Art. 1(2) explicitly excludes "ideas and principles which underlie any element of a computer program, including those which underlie its interfaces." -However, copyright law draws a sharp, fundamental distinction between what is protected and what -is free for anyone to use: +* **Protected**: your specific source code text, binaries, container recipes, prompt text, and preparatory design material. +* **Not protected**: mathematical algorithms, scientific models, programming logic, data structures, and interfaces. -* **Protected (Code Expression)**: The specific source code text, variable names, binaries, - container build recipes, prompt engineering text, and preparatory design documents. -* **Not Protected (Underlying Ideas)**: Mathematical algorithms, scientific models, - programming logic, data structures, and interface principles. - -Because copyright restricts only the *creative human expression* and not the underlying -*ideas or algorithms*, developers could use open-source licenses to define the exact terms under -which that expression can be legally shared and modified. +The CJEU confirmed this line in *SAS Institute v World Programming* (C-406/10): a program's functionality, its programming language, and its data file formats are ideas, not expression, and are therefore outside copyright. Someone may reimplement your algorithm from scratch; they may not copy your code. This is exactly why licenses exist โ€” they set the terms for the expression, which is the only part copyright lets you control. ### Scope of this Lesson: What Counts as *Software*? -Across international legal frameworks (such as 17 U.S.C. ยง 101 and WIPO-World Intellectual Property Organization -model provisions), software is broadly defined as a set of instructions to be used directly or indirectly in -a computer to bring about a certain result. +Across international frameworks (17 U.S.C. ยง 101 and WIPO model provisions), software is broadly defined as a set of statements or instructions used directly or indirectly in a computer to bring about a certain result. Research software goes well beyond Python scripts, so this lesson covers six asset types โ€” find the ones matching your own project, since the scenarios later map onto them: -Because modern research software extends beyond simple Python scripts, this lesson applies -copyright and licensing principles across six core research software assets: +* **Source Code** โ€” original algorithms, or implementations of published methods. +* **Third-Party Integrations** โ€” embedded snippets and linked libraries (static or dynamic). +* **Infrastructure as Code** โ€” Ansible playbooks, Terraform configs, container recipes (`Dockerfile`, Apptainer `.def`). +* **Container Images** โ€” built binary snapshots (`.sif` files, OCI registry images). +* **AI-Assisted Code** โ€” generated or refactored with human oversight. +* **AI Prompt Templates** โ€” engineered system prompts meeting the threshold of human authorship. -* **Source Code**: Original algorithms written from scratch or implemented from scientific papers. -* **Third-Party Integrations**: Embedded permissive or copyleft code snippets and linked libraries (dynamically/statically). -* **Infrastructure as Code**: Ansible playbooks,Terraform configurations,container Recipes (`Dockerfile`, Apptainer `.def`). -* **Container Images**: Bundled binary filesystem snapshots (`.sif` files, OCI registry images). -* **AI-Assisted Code**: Code generated, refactored, or assembled with human creative oversight. -* **AI Prompt Templates**: Complex, engineered system prompts and structured frameworks meeting the threshold of human creative authorship. ## Motivation: Debugging a License Compliance Failure From b032c4fb62906dbaed6749a7c88160df17d82fef Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:41:13 +0200 Subject: [PATCH 83/99] Roni recomendations for limitations --- content/software-licensing.md | 94 ++++++++++++++--------------------- 1 file changed, 37 insertions(+), 57 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 7609c56..8fc49bf 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -125,40 +125,40 @@ Across international frameworks (17 U.S.C. ยง 101 and WIPO model provisions), so * **AI-Assisted Code** โ€” generated or refactored with human oversight. * **AI Prompt Templates** โ€” engineered system prompts meeting the threshold of human authorship. - - ## Motivation: Debugging a License Compliance Failure -With the understanding of the difference between Permissive and Copyleft licenses, -examine what happens when they collide inside an automated CI/CD pipeline: +With the three license families in mind, examine what happens when they collide inside an automated CI/CD pipeline: ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% flowchart TB subgraph box["CI/CD License Compliance Debugging Pipeline"] - A[Paste snippet copyied from somewhere ] --> A2["Build Trigger:Push to my-code-base"] - A2["Build Trigger: Push to my-code-base"] --> B["Run Compliance Scanner"] - B --> C{"Check Inbound vs.Outbound Terms"} - - C -->|"Target License:Permissive but pasted snippet:Copyleft"| D["โŒ BUILD FAILURE
Pasted copyleft snippet restricts MIT release"] - + A["Paste a snippet copied from somewhere"] --> A2["Build Trigger: Push to my-code-base"] + A2 --> B["Run Compliance Scanner"] + B --> C{"Check Inbound vs.
Outbound Terms"} + + C -->|"Target license: Permissive
Pasted snippet: Copyleft"| D["โŒ BUILD FAILURE
Pasted copyleft snippet blocks MIT release"] + D --> E{"Select Patch Option"} - - E -->|"Option A: Keep MIT & add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override copyleft terms"] - E -->|"Option B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license matches the pasted copyleft snippet"] - E -->|"Option C: Rewrite code from scratch to replace snippet"| H["โœ… BUILD PASS
New code expression frees your target license"] - E -->|"Option D: Delete LICENSE file to bypass scanner"| I["โš ๏ธ PASSED SCANNER (LEGAL TRAP!)
Infringes third-party copyright & locks own code to All Rights Reserved"] - P["Permissive
(MIT, Apache-2.0, 0BSD)'Do whatever you want, just keep credit'"] - CL["Copyleft / Reciprocal
(GPL-3.0, EUPL-1.2)'Must share changes under same terms'"] + E -->|"A: Keep MIT, add comment '# Originally GPL'"| F["โŒ BUILD FAIL
Comments do not override license terms"] + E -->|"B: Re-license repo to GPL-3.0 / EUPL-1.2"| G["โœ… BUILD PASS
Your license now matches the snippet"] + E -->|"C: Reimplement the functionality yourself"| H["โœ… BUILD PASS
Your own expression, your own license"] + E -->|"D: Delete LICENSE file to silence the scanner"| I["โš ๏ธ SCANNER PASSES โ€” LEGAL TRAP
Still infringing, and your own code reverts to All Rights Reserved"] + + P["Permissive
MIT, Apache-2.0, 0BSD"] + WC["Weak Copyleft
LGPL, MPL-2.0, EPL-2.0"] + CL["Copyleft
GPL-3.0, EUPL-1.2"] end - P -.->|"I want to use"| C - CL -.->|"Pasted code snippet uses"| C + P -.->|"What I want for my repo"| C + CL -.->|"What the pasted snippet uses"| C + WC -.->|"Would often have been fine"| C classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef copyleft fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef amber fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c0000; classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; @@ -166,73 +166,53 @@ flowchart TB class P,G,H pass; class CL copyleft; + class WC amber; class D,F fail; class I warning; - class A,B,C,E neutral; + class A,A2,B,C,E neutral; class box box_fill; ``` +* Option D is the one worth dwelling on: deleting the `LICENSE` file makes the scanner quiet without changing anything legally. You are still distributing someone else's copyleft code without honouring its terms, and you have now stripped your own users of any permission to use your work. A green pipeline is not a compliance result. + +* Option C works only if you genuinely reimplement the functionality without copying the original expression. As the idea/expression split above establishes, the algorithm is free to reuse โ€” the specific code is not. Reading the original closely and retyping a close paraphrase is still copying. + + ## Limitations of AI-Assisted Licensing Advice Modern software developers and RSEs routinely rely on AI coding assistants (ChatGPT, Claude, GitHub Copilot) to generate boilerplate, refactor functions, and answer project setup questions. -However, using these tools for legal or licensing guidance introduces a subtle -risk of **AI legal bias** as AI models are overwhelmingly trained on US-centric -web data and legal forum posts, their outputs default almost universally -to **US common law concepts** such as *Fair Use*, *Work Made for Hire*, and -*Derivative Works*. - -In contrast, developers operating under EU statutory frameworks (such as Directive 2009/24/EC) -face a different legal reality related to exceptions, author ownership, and code adaptations. -Relying blindly on AI legal advice creates significant compliance blind spots, -which is why this lesson equips you with a direct, EU-aligned framework for software licensing. -```{discussion} Terminology Trap: "Derivative Work" (US) vs. "Adaptation" (EU) +However, using these tools for legal or licensing guidance introduces a subtle risk of **AI legal bias**. AI models are overwhelmingly trained on US-centric web data and legal forum posts, so their outputs default almost universally to **US common law concepts** such as *Fair Use*, *Work Made for Hire*, and *Derivative Works*. -When searching online or asking AI coding assistants about software modification, you will almost always encounter the term **"derivative work"**. Understanding the origin of this term is crucial for EU-based software developers: +Developers working under EU statutory frameworks face a different legal reality around exceptions, ownership, and code adaptation. The clearest example is the term you will hear constantly: -* **US Common Law (17 U.S.C. ยง 101)**: Formally defines and uses the term *"Derivative Work"*. Because AI models and search engines are heavily trained on US web data, AI assistants default to using "derivative work" for almost any code modification. -* **EU Statutory Law (Directive 2009/24/EC, Art. 4(1)(b))**: Does **not** use or recognize the term "derivative work". Instead, EU software copyright grants exclusive rights over **"translation, adaptation, arrangement, and any other alteration "**collectively governed under EU law as an **adaptation**. -* **Why Licenses Use "Derivative Work"**: License contracts like `EUPL-1.2` or `GPL-3.0` define "Derivative Works" within their legal text as a contractual term to ensure international enforceability across jurisdictions, even though EU statutes govern the act as an *adaptation*. - -**Key Takeaway**: When AI tells you that a snippet or linked library creates a "derivative work", remember that under EU law you must evaluate whether the modification constitutes a statutory **adaptation** or a **combined work** across API boundaries. +* **US law (17 U.S.C. ยง 101)** formally defines *"derivative work"*, and AI assistants reach for it to describe almost any code modification. +* **EU law (Directive 2009/24/EC, Art. 4(1)(b))** does not use that term at all. It grants exclusive rights over "the translation, adaptation, arrangement and any other alteration of a computer program" โ€” governed collectively as an **adaptation**. +* **Licenses use it anyway**: `GPL-3.0` and `EUPL-1.2` define "derivative work" inside their own text as a contractual term for international enforceability, even though EU statute treats the act as an adaptation. +So when an AI assistant tells you a snippet creates a "derivative work", treat that as a prompt to check the actual question under EU law: is this a statutory **adaptation**, or a **combined work** across a technical boundary? The rest of this lesson gives you that EU-aligned framework. ## Standardizing In-File Declarations: SPDX Identifiers -Selecting a license is only half the battle; automated scanners and CI/CD pipelines need a machine-readable way to verify license compliance per file without parsing long legal texts. +Selecting a license is only half the job. Automated scanners and CI/CD pipelines need a machine-readable way to verify compliance per file without parsing legal text. -Managed by the Linux Foundation, **SPDX identifiers** (Software Package Data Exchange) provide standardized short tags (e.g., `MIT`, `Apache-2.0`, `GPL-3.0-only`, `EUPL-1.2`) placed at the very top line of every source file: +Managed by the Linux Foundation, **SPDX identifiers** are standardized short tags (`MIT`, `Apache-2.0`, `GPL-3.0-only`, `EUPL-1.2`) placed at the top of every source file: ```python # SPDX-License-Identifier: MIT # Copyright (c) 2026 Author Name ``` -Throughout the exercise scenarios below, look for the **In-File Identification (SPDX)** callouts to see how these tags apply directly to Python scripts, container recipes, and engineered prompt templates. - +Every scenario below shows the SPDX tagging for its asset type โ€” Python scripts, container recipes, and prompt templates each have their own conventions. ## License Selection Decision Matrix & Scenario Index -To help you navigate open-source compliance, the matrix below serves as an upfront -quick-reference summary and interactive index for the core licensing scenarios -encountered in research software engineering. - - -### [Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses) - * Our decision framework is grounded in the European Commission's **JLA**, which evaluates software - assets across six criteria categories: - * Can (Permissions) - * Must (Obligations) - * Cannot (Restrictions) - * Compatible** (Interoperability) - * Law (Jurisdiction) - * Support(Governance) +Our decision framework is grounded in the European Commission's **[Joinup Licensing Assistant (JLA)](https://interoperable-europe.ec.europa.eu/collection/eupl/solution/licensing-assistant/find-and-compare-software-licenses)**, which sorts licenses across six criteria: **Can** (permissions), **Must** (obligations), **Cannot** (restrictions), **Compatible** (interoperability), **Law** (jurisdiction), and **Support** (governance). -Use this index to preview the demonstrated path for each scenario, or click any module link to jump -directly to its detailed exercise, legal analysis, and JLA selection instructions. +The scenarios below are independent. Find the row that matches what you are actually building, jump to it, and skip the rest. | Scenario Module | Demonstrated Path / Focus | Compliant Target Licenses | | :--- | :--- | :--- | From a529f1286819a955d90e82f441aa4be97b5408da Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:49:43 +0200 Subject: [PATCH 84/99] Roni recomendations scenario 1 --- content/software-licensing.md | 32 ++++++++++++++++---------------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 8fc49bf..82f9dd9 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -214,21 +214,21 @@ Our decision framework is grounded in the European Commission's **[Joinup Licens The scenarios below are independent. Find the row that matches what you are actually building, jump to it, and skip the rest. -| Scenario Module | Demonstrated Path / Focus | Compliant Target Licenses | -| :--- | :--- | :--- | -| [**1. Own Code**](#scenario-1) | ๐ŸŸข Permissive *(Default Choice)* | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| [**2. Implement an algorithm**](#scenario-2) | ๐ŸŸก Copyleft / Reciprocal | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | -| [**3. Embed Permissive**](#scenario-3) | ๐ŸŸข Permissive Focus *(Copyleft Flexible)* | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | -| [**4. Embed Copyleft**](#scenario-4) | ๐ŸŸก Mandatory Copyleft | `EUPL-1.2`, `GPL-3.0` | -| [**5. Link GPL Library**](#scenario-5) | ๐ŸŸก Mandatory Copyleft | `GPL-3.0`, `EUPL-1.2` | -| [**6. Container Recipe**](#scenario-6) | ๐ŸŸข Permissive Focus | `MIT`, `Apache-2.0`, `BSD-3-Clause` | -| [**7. Built Image**](#scenario-7) | โš ๏ธ Multi-License Bundle | Governed by individual layer/binary terms | -| [**8. AI-Assisted Code**](#scenario-8) | ๐ŸŸข Permissive Focus *(Author Choice)* | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | -| [**9. Prompt Chaining Architecture**](#scenario-9) | ๐ŸŸข Permissive Focus | `MIT`, `Apache-2.0` | - -### Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms - -When writing original code or implementing published mathematical logic, you control 100% of your copyright. +| If you are... | Scenario | Typical Outcome | Example Licenses | +| :--- | :--- | :--- | :--- | +| Writing everything yourself | [**1. Own code**](#scenario-1) | ๐ŸŸข Free choice | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| Implementing a published algorithm | [**2. Algorithm implementation**](#scenario-2) | ๐ŸŸข Free choice โ€” copyleft if you want reciprocity | `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` | +| Pasting in a permissive snippet | [**3. Embed permissive**](#scenario-3) | ๐ŸŸข Stay permissive, keep notices | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | +| Pasting in a copyleft snippet | [**4. Embed copyleft**](#scenario-4) | ๐ŸŸก Strong copyleft likely required | `EUPL-1.2`, `GPL-3.0` | +| Importing or linking a library | [**5. Link a library**](#scenario-5) | ๐ŸŸก Depends on which copyleft โ€” see below | `GPL-3.0`, `EUPL-1.2`, or permissive if weak copyleft | +| Writing a Dockerfile or `.def` | [**6. Container recipe**](#scenario-6) | ๐ŸŸข Free choice | `MIT`, `Apache-2.0`, `BSD-3-Clause` | +| Publishing a built image | [**7. Built image**](#scenario-7) | โš ๏ธ Multi-license bundle | Governed by each layer's own terms | +| Using Copilot, ChatGPT or Claude | [**8. AI-assisted code**](#scenario-8) | ๐ŸŸข Free choice, verify for memorization | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | +| Shipping prompts, weights or datasets | [**9. AI workflows & assets**](#scenario-9) | ๐ŸŸข Dual-license code vs. assets | `MIT` + `CC-BY-4.0` | + +## Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms + +When writing original code or implementing published algorithms, no third-party license constrains your choice โ€” but who owns the code depends on your employment contract and national rules, so check your institution's policy first. (scenario-1)= ::::{exercise} Scenario 1: Authoring original code and algorithms @@ -251,7 +251,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your * **Downstream Obligations**: Anyone who reuses, modifies, or integrates your code into their work must preserve your copyright notice and license text. They are not required to share their modifications or open-source their downstream projects. -* **Allowed Inbound Snippets**: If you want to include small third-party code snippets in your files, you can freely embed code licensed under **permissive terms** (e.g., MIT, BSD, Apache-2.0, 0BSD) or public domain waivers (CC0) without affecting your permissive license. However, embedding copyleft snippets (e.g., GPL, EUPL) will trigger reciprocal obligations, forcing your entire repository to be re-licensed under those copyleft terms. +* **Allowed Inbound Snippets**: If you want to include small third-party code snippets in your files, you can freely embed code licensed under **permissive terms** (e.g., MIT, BSD, Apache-2.0, 0BSD) or public domain waivers (CC0) without affecting your permissive license. However, embedding copyleft snippets (e.g., GPL, EUPL) might trigger reciprocal obligations, forcing your entire repository to be re-licensed under those copyleft terms. * **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: From b7121e58f10bd0471c8d7e7b70abad52cd7f373a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 18:55:17 +0200 Subject: [PATCH 85/99] Roni recomendations scenario 2 --- content/software-licensing.md | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 82f9dd9..2a674b9 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -235,7 +235,7 @@ When writing original code or implementing published algorithms, no third-party You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your repository contains only your original source code and dependency specifications (`requirements.txt`, `CMakeLists.txt`, `Cargo.toml`). * **Licensing Goal**: You want **maximum adoption** and zero friction for commercial or academic reuse. -* **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, you hold full copyright over your original codebase. +* **Legal Reality**: External dependencies remain separate works. Because you have not bundled third-party code inside your repository, no inbound license terms constrain your choice. * **JLA Selection Strategy**: To ensure downstream users must acknowledge your original authorship while granting them maximum flexibility to incorporate your code into both open and proprietary software, you require citation credit (`Incl. Copyright`) without imposing share-alike conditions (leaving `Copyleft/Share a.` unselected). :::{solution} @@ -251,7 +251,7 @@ You wrote an original algorithm from scratch (in Python, C++, Rust, etc.). Your * **Downstream Obligations**: Anyone who reuses, modifies, or integrates your code into their work must preserve your copyright notice and license text. They are not required to share their modifications or open-source their downstream projects. -* **Allowed Inbound Snippets**: If you want to include small third-party code snippets in your files, you can freely embed code licensed under **permissive terms** (e.g., MIT, BSD, Apache-2.0, 0BSD) or public domain waivers (CC0) without affecting your permissive license. However, embedding copyleft snippets (e.g., GPL, EUPL) might trigger reciprocal obligations, forcing your entire repository to be re-licensed under those copyleft terms. +* **Allowed Inbound Snippets**: If you want to include small third-party code snippets in your files, you can freely embed code licensed under **permissive terms** (e.g., MIT, BSD, Apache-2.0, 0BSD) or public domain waivers (CC0) without affecting your permissive license. However, embedding copyleft snippets (e.g., GPL, EUPL) might trigger reciprocal obligations requiring you to re-license. Whether it does depends on which copyleft: weak copyleft (LGPL, MPL-2.0) often lets your surrounding code stay permissive, while strong copyleft generally does not. * **In-File Identification (SPDX)**: Apply standard machine-readable SPDX identifier comments directly at the top of your scripts: @@ -265,12 +265,12 @@ import numpy as np :::: (scenario-2)= -::::{exercise} Scenario 2: Implementing mathematical models with copyleft obligations -You developed a custom mathematical solver implementing algorithms from academic literature. You want to ensure that any downstream improvements, extensions, or modifications made by others remain open-source and are shared back with the scientific community. +::::{exercise} Scenario 2: Choosing reciprocity for your own implementation +You developed a custom solver implementing algorithms from academic literature. You want any downstream improvements, extensions, or modifications to remain open-source and be shared back with the scientific community. -* **Licensing Goal**: You want to enforce **reciprocity** (share-alike), preventing third parties from incorporating your algorithm into proprietary, closed-source software without sharing their modifications. -* **Legal Reality**: Mathematical concepts and formulas themselves are not copyrightable, but your specific code implementation is fully protected by copyright. Applying a copyleft license legally binds anyone who distributes modified versions of your implementation to release their source code under matching reciprocal terms. -* **JLA Selection Strategy**: To enforce reciprocal sharing, you must mandate that downstream distributors disclose their modified source code (`Disclose source`) and license their adaptations or combined worrks under matching terms (`Copyleft/Share a.`). +* **Licensing Goal**: You want to enforce **reciprocity** (share-alike), preventing third parties from incorporating your implementation into proprietary software without sharing their modifications. +* **Legal Reality**: The published algorithm itself is an unprotected idea โ€” anyone may implement it independently, as Scenario 1 and the *SAS* ruling establish. What copyright protects is *your* specific implementation. Nothing about implementing a published method forces a particular license; copyleft here is your deliberate choice to bind downstream distributors to matching terms. +* **JLA Selection Strategy**: To enforce reciprocal sharing, you must mandate that downstream distributors disclose their modified source code (`Disclose source`) and license their adaptations or combined works under matching terms (`Copyleft/Share a.`). :::{solution} **What to select in the JLA interface:** @@ -282,7 +282,7 @@ You developed a custom mathematical solver implementing algorithms from academic * **Example JLA Matches**: `EUPL-1.2`, `GPL-3.0`, `AGPL-3.0` * **Copyleft Mechanics (EUPL vs. GPL Nuance)**: `GPL-3.0` is the standard global copyleft license, but `EUPL-1.2` is specifically tailored for European institutions. EUPL-1.2 is officially published in 23 EU language versions (each with equal legal validity), includes built-in compatibility clauses with GPL, and explicitly defaults to EU Member State jurisdiction and courts. - +* **A caution before choosing strong copyleft**: reciprocity also limits who can combine with your code. Strong copyleft licenses are frequently incompatible with each other, so a future collaborator on a differently-licensed copyleft project may be unable to use your work at all. Scenario 5 covers this. * **Downstream Obligations**: Anyone who distributes your code or a modified version of it must provide complete access to the corresponding source code under the same copyleft license and preserve your original copyright notices. * **Allowed Inbound Snippets**: You can freely embed code snippets licensed under **permissive terms** (e.g., MIT, Apache-2.0, BSD) or public domain waivers (CC0). You may also embed snippets from compatible copyleft code (e.g., EUPL, GPL). However, you cannot embed closed-source or proprietary code snippets. From d75f3f7a4f09d0d40595e3c12c3e564c8bf0473a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 19:08:18 +0200 Subject: [PATCH 86/99] Roni recomendations scenario 5 --- content/software-licensing.md | 20 +++++++++----------- 1 file changed, 9 insertions(+), 11 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 2a674b9..22b4053 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -300,8 +300,7 @@ import numpy as np ## Module 2: The Dependency Minefield โ€“ Inbound Code & Linking -Embedding third-party source code snippets or linking against strong copyleft libraries -introduces legal boundaries that restrict your repository choices. +Embedding third-party snippets or linking against external libraries introduces boundaries that can constrain your license choice. How far those boundaries reach depends on which license the inbound code carries. (scenario-3)= ::::{exercise} Scenario 3: Embedding permissively licensed third-party code @@ -320,11 +319,11 @@ You are building an RSE tool and copied a helper function or utility snippet fro * **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **Notice Preservation Nuance**: Permissive licenses are flexible, but they are not license-free. If you copy code from an Apache-2.0 or BSD-3-Clause project into your MIT-licensed repository, you must retain the original author's copyright statement and license identifier directly above the embedded code block. +* **Notice Preservation Nuance**: Permissive licenses are flexible, but they are not license-free. If you copy code from an Apache-2.0 or BSD-3-Clause project into your MIT-licensed repository, you must retain the original author's copyright statement and license identifier directly above the embedded code block. Your repository license covers *your* code. It does not relicense the embedded snippet โ€” that code stays under its original license and its original copyright holder's terms. You are distributing one file containing two separately licensed contributions, which is why both notices must appear. * **Downstream Obligations**: Downstream users receive your project under your primary permissive license (e.g., MIT), but they must preserve both your overall copyright notice and the specific third-party notices attached to embedded snippets. -* **Allowed Inbound Snippets**: In addition to the embedded permissive snippet, you can freely embed other permissively licensed code (MIT, BSD, Apache-2.0) or public domain waivers (CC0). You cannot embed copyleft code (e.g., GPL, EUPL) without upgrading your entire repository's license to match that copyleft license. +* **Allowed Inbound Snippets**: In addition to the embedded permissive snippet, you can freely embed other permissively licensed code (MIT, BSD, Apache-2.0) or public domain waivers (CC0).Embedding **strong** copyleft code (GPL, EUPL) generally requires re-licensing your repository to match. Weak copyleft (LGPL, MPL-2.0) applies at a narrower boundary and often does not * **In-File Identification (SPDX)**: Mark both your overall file license and the specific embedded snippet using SPDX comments: @@ -348,10 +347,10 @@ def main(): (scenario-4)= ::::{exercise} Scenario 4: Embedding copyleft third-party code -You are building an software tool and copied a non-trivial code snippet from a third-party project licensed under a copyleft license (e.g., GPL-3.0 or EUPL-1.2) directly into one of your source files. +You are building a software tool and copied a non-trivial code snippet from a third-party project licensed under a copyleft license (e.g., GPL-3.0 or EUPL-1.2) directly into one of your source files. * **Licensing Goal**: Comply with legal requirements imposed by the inbound copyleft code while ensuring your overall repository remains legally compliant. -* **Legal Reality**: Copyleft licenses require that any work containing copyleft code must be shared under a compatible copyleft license as a whole. Embedding copyleft code directly into your repository creates a single combined work, making copyleft licensing mandatory for your entire project. +* **Legal Reality**: Copying a non-trivial copyleft snippet into your source files creates a single combined work, so copyleft licensing generally extends to your whole project. "Non-trivial" matters: a snippet too short or purely functional to qualify as the author's own intellectual creation (Art. 1(3)) may not carry copyright at all. There is no word count or line count that draws this line โ€” if you are unsure, assume it is protected and either comply or reimplement. * **JLA Selection Strategy**: Because the inbound copyleft code forces your repository to adopt reciprocal sharing terms, you must configure JLA to require source code disclosure (`Disclose source`) and reciprocal licensing (`Copyleft/Share a.`). :::{solution} @@ -395,10 +394,10 @@ When software incorporates external dependencies, whether by dynamic linking, st (scenario-5)= ::::{exercise} Scenario 5: Linking against a GPL-licensed library -You are developing an software application that imports or links against an external software library licensed under GPL-3.0 (e.g., importing a GPL Python package or linking a C/C++ static/shared library). +You are developing a software application that imports or links against an external software library licensed under GPL-3.0 (e.g., importing a GPL Python package or linking a C/C++ static/shared library). * **Licensing Goal**: Ensure legal compliance while using copyleft libraries as core dependencies in your software project. -* **Legal Reality**: Under mainstream copyright interpretation and the text of GPL-3.0, linking your code directly against a GPL library (whether statically or dynamically) creates a combined work. Consequently, the copyleft obligations of the external library extend to your entire repository. +* **Legal Reality**: Whether linking creates a combined work is genuinely unsettled, and often has to be decided case by case. The FSF's position is that linking a GPL library โ€” statically or dynamically โ€” creates a combined work; some legal scholars and Commission EUPL guidance disagree, particularly for dynamic linking through a stable API. Most Member States have no case law on this, so no firm general rule can be stated. The guidance below follows the conservative, widely-adopted reading. * **JLA Selection Strategy**: Because linking to a GPL library requires your distributed project to be released under matching reciprocal terms, you must configure JLA to mandate source code disclosure (`Disclose source`) and reciprocal licensing (`Copyleft/Share a.`). :::{solution} @@ -412,9 +411,8 @@ You are developing an software application that imports or links against an exte * **Linking Boundaries & License Selection (Legal Nuance)**: * **Why GPL forces copyleft**: Linking against a standard `GPL-3.0` library extends copyleft to your entire project. Your repository must adopt a compatible copyleft license (`GPL-3.0` or `EUPL-1.2`, which explicitly lists GPL-3.0 in its compatibility appendix). - * **Why LGPL or EUPL-1.2 libraries allow permissive licenses**: If the external library is licensed under `LGPL` (which includes an explicit linking exception) or `EUPL-1.2` (where European Commission guidance takes the position that dynamically linking an EUPL work through its API does not by itself create a adaptation work), copyleft does not extend to your application. In these dynamic linking scenarios, your own project can stay **permissively licensed** (e.g., MIT, Apache-2.0, BSD). However, note that this EUPL stance reflects Commission guidance rather than settled CJEU case law, and static linking or direct code incorporation continues to trigger EUPL copyleft obligations. - -* **Downstream Obligations**: Downstream users who receive or run your application must receive full access to your source code under `GPL-3.0` (or `EUPL-1.2`), along with all upstream copyright notices and build scripts required to recompile the project. +* **Copyleft licenses are not compatible with each other**: two strong copyleft licenses can each demand that the combined work use *their* terms, which makes the combination undistributable. The classic trap is `GPL-2.0-only`: without the "or later" clause you cannot upgrade to GPL-3.0 to resolve a conflict, so GPL-2.0-only code cannot be combined with GPL-3.0 or Apache-2.0 code at all. Always check the exact SPDX identifier โ€” `GPL-2.0-only` and `GPL-2.0-or-later` behave very differently. +* **Downstream Obligations**: Anyone to whom you **distribute** the application must receive full access to your source code under `GPL-3.0` (or `EUPL-1.2`), along with upstream copyright notices and the build scripts needed to recompile it. Running the software internally, without distributing it, creates no such obligation โ€” though note that `AGPL-3.0` extends this to network use. * **Allowed Inbound Code & Dependencies**: Your project can import or include other **permissively licensed** packages (MIT, BSD, Apache-2.0) and public domain waivers (CC0). However, all code linked together in the final executable or runtime environment must satisfy GPL compatibility. From 6397f21b7e4ec958ea8d9d2c79bd8fb1382535ff Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 19:13:17 +0200 Subject: [PATCH 87/99] Roni recomendations scenario 6 --- content/software-licensing.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 22b4053..09e871e 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -436,7 +436,7 @@ def solve_system(data): You are creating a `Dockerfile`, Conda `environment.yml`, or build recipe to automate the setup of your research environment. The recipe itself contains setup instructions, shell commands, and package lists. * **Licensing Goal**: You want **maximum adoption** and reuse of your build automation script so other researchers can freely adapt and build upon your workflow. -* **Legal Reality**: Build recipes and configuration scripts are plain-text source code separate from the software binaries they download at execution time. You hold copyright over the unique build instructions you write in the Dockerfile. +* **Legal Reality**: Build recipes and configuration scripts are plain-text source code, separate from the software binaries they download at build time. The build instructions you write are your expression โ€” but note that a very short recipe (a `FROM` line plus two `RUN` commands) may be too trivial to meet the Art. 1(3) originality threshold and may not attract copyright at all. Longer, non-obvious recipes clearly do. * **JLA Selection Strategy**: To allow anyone to reuse or adapt your container recipe without restrictions, you require citation credit (`Incl. Copyright`) while leaving reciprocal requirements (`Copyleft/Share a.`) unselected. :::{solution} @@ -474,7 +474,7 @@ COPY solver.py /app/solver.py You compiled and published a pre-built container image (e.g., pushing a compiled Docker image to Docker Hub, GitHub Container Registry, or an institutional registry) containing an OS layer, runtime binaries, dependencies, and your application code. * **Licensing Goal**: Safely distribute compiled container images without violating the license terms of any software layer or binary included inside the image. -* **Legal Reality**: A compiled container image is a **multi-license aggregate bundle**. Distributing pre-built binaries triggers source-code distribution obligations for any copyleft software (e.g., Linux base packages, coreutils, GPL libraries) pre-installed inside the image layers. +* **Legal Reality**: A compiled container image is a **multi-license aggregate bundle**, not a single combined work. Distributing pre-built binaries makes you a distributor of every package inside, so source-availability obligations apply to the copyleft components (Linux base packages, coreutils, GPL libraries). But those packages sitting in the same filesystem as your application do not make your application a derivative of them โ€” this is mere aggregation. Your own code keeps whatever license you chose; you simply also carry distributor obligations for the copyleft software you are shipping alongside it. * **JLA Selection Strategy**: Because a container image combines multiple distinct software components, JLA is used to evaluate constituent component obligations. When distributing compiled binaries containing copyleft layers, source disclosure requirements (`Disclose source`) must be fulfilled for those specific layers. :::{solution} @@ -484,11 +484,11 @@ You compiled and published a pre-built container image (e.g., pushing a compiled 2. **Must Column**: Select `Incl. Copyright` and `Disclose source` 3. **Support Column**: Select `OSI approved` -* **Example JLA Matches**: `Multi-License Bundle` (Governed by constituent package terms) +* **JLA Outcome**: No single license applies. Use JLA per component to check each one's obligations, then record the aggregate in your image metadata. * **Multi-License Aggregation Nuance**: Applying a permissive license (like MIT) to your application code inside the container does not override or erase the GPL/LGPL obligations of base system packages installed in `/usr/lib` or `/usr/bin`. Distributing the built image binary makes you a distributor of all installed packages. -* **Downstream Obligations**: You must ensure that downstream users can obtain the source code for copyleft components shipped inside the image, typically by publishing the `Dockerfile` and build steps used to generate the image from public upstream sources. +* **Downstream Obligations**: You must ensure downstream users can obtain the corresponding source for the copyleft components you shipped. Publishing your `Dockerfile` documents the build but does not by itself satisfy this โ€” the GPL asks for the source of the binaries actually distributed. In practice, most research images rely on unmodified upstream distribution packages, where pointing to the distributor's public source archives (as GPLv3 ยง6(d) permits) is the normal approach. If you modify or rebuild a copyleft component yourself, you must provide that source directly. * **Allowed Inbound Packages**: Before publishing an image binary, run automated compliance scanning tools (e.g., Syft, Trivy) to generate a Software Bill of Materials (SBOM) and verify that no non-redistributable or proprietary software is packaged inside. From 78467eba27dd97f01a95152bfa3a2e52db2d7349 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 19:17:21 +0200 Subject: [PATCH 88/99] Roni recomendations scenario 8 --- content/software-licensing.md | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 09e871e..8668dcd 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -534,8 +534,7 @@ You used AI tools (e.g., GitHub Copilot, ChatGPT, Claude) to write functions, un * **Example JLA Matches**: `MIT`, `Apache-2.0`, `BSD-3-Clause` -* **AI Code Generation & Verification Nuance**: Because non-human AI output cannot hold copyright, your copyright applies to the overall project structure, human-written logic, and creative choices. To protect your repository against accidental copyright infringement or copyleft contamination from AI memorization, turn on public code matching filters in your AI tools and run automated code-similarity scanners before releasing your repository. - +* **Marking AI-generated code**: Some projects and AI tool terms require contributors to disclose AI involvement โ€” via a commit trailer, a PR checkbox, or an in-file comment. Even where it is optional, marking AI-assisted sections is increasingly recommended practice: it records provenance, signals to reviewers where extra scrutiny is warranted, and makes later authorship or infringement questions much easier to resolve. Check the contribution guidelines of any project you submit to. * **Downstream Obligations**: Downstream users must preserve your copyright notice for the repository. They are free to reuse, modify, and integrate your code into commercial or open-source projects. * **Allowed Inbound Snippets**: You can include permissively licensed code, public domain code (CC0), and AI-generated snippets that have been verified against verbatim training data duplication. @@ -560,7 +559,7 @@ def filter_sensor_data(raw_readings: list[float]) -> list[float]: You are developing research software that includes source code alongside trained machine learning model weights (`.pt`, `.safetensors`) and benchmark datasets. * **Licensing Goal**: Apply a clear **dual-licensing strategy** that makes both the software source code and the non-code assets (data, weights) open and reusable under appropriate legal frameworks. -* **Legal Reality**: Standard open-source software licenses (MIT, GPL) are written specifically for source code and are legally ill-suited for datasets or neural network parameters. Under EU legal frameworks, datasets and model weights are governed by database rights (*sui generis* database protection) rather than traditional code copyright. +* **Legal Reality**: Standard software licenses (MIT, GPL) are written for source code and fit datasets and model parameters poorly. Datasets may attract the EU *sui generis* database right where there has been substantial investment in obtaining, verifying, or presenting their contents. Model weights are a harder case: they are neither code nor a database, and whether they attract any copyright protection in the EU is genuinely unsettled. Because of this uncertainty, applying an explicit license to weights is about setting clear terms for your users, not about relying on a settled legal right. * **JLA Selection Strategy**: Use JLA to select an OSI-approved open-source license for the executable code component (`Incl. Copyright` selected), while using Creative Commons licenses (e.g., `CC-BY-4.0` or `CC0`) for the dataset and weight files. :::{solution} @@ -572,7 +571,7 @@ You are developing research software that includes source code alongside trained * **Example JLA Matches**: `MIT`, `Apache-2.0` (for the code component) -* **Code vs. Data/Weights & OpenRAIL Nuance**: Never apply software licenses like GPL or MIT to raw datasets or model weights. Use **CC-BY-4.0** or **CC0** for non-code assets. Additionally, behavioral licenses (such as OpenRAIL) impose usage restrictions (e.g., prohibiting specific harmful uses), which means they do **not** qualify as OSI-approved open-source software and cannot be filtered via standard JLA open-source queries. +* **Code vs. Data/Weights & OpenRAIL Nuance**: Avoid applying software licenses like GPL or MIT to raw datasets or model weights โ€” their terms reference source code, object code, and linking, which leaves users guessing about what applies. Use **CC-BY-4.0** or **CC0** for non-code assets instead. Note also that behavioral licenses (such as OpenRAIL) impose usage restrictions (e.g., prohibiting specific harmful uses), so they do **not** qualify as OSI-approved open source and will not appear in standard JLA queries. * **Downstream Obligations**: Downstream users must cite your repository for the code (under your chosen software license) and give credit for the model weights and data under the corresponding Creative Commons license. @@ -687,4 +686,4 @@ flowchart TB * **Maintaining Permissive Defaults ([Scenario 1](#scenario-1) & [Scenario 3](#scenario-3))**: If you write original code or embed only permissively licensed snippets (MIT, Apache-2.0, BSD), selecting a permissive license (`MIT` or `Apache-2.0`) grants downstream users maximum adoption freedom while preserving your citation credit. * **Packaging and Build Automation ([Scenario 6](#scenario-6) & [Scenario 7](#scenario-7))**: Keep plain-text build recipes (Dockerfiles) permissively licensed for maximum reuse, while annotating compiled container image binaries as multi-license aggregate bundles to satisfy embedded base-layer obligations. * **AI Assets and Dual-Licensing ([Scenario 8](#scenario-8) & [Scenario 9](#scenario-9))**: Run code-similarity scanners to catch LLM training memorization before releasing AI-assisted code, and apply dual-licensing to separate executable software code (`MIT`) from non-code datasets and model weights (`CC-BY-4.0`). -* **Standardized Distribution**: By adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template, running `reuse lint` in your pipeline confirms 100% legal clarity for the entire scientific community. +* **Standardized Distribution**: By adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template, running `reuse lint` in your pipeline confirms 100% legal clarity for the entire scientific community. From 7e01ce8504fd000d4b06746289da7e86742cd175 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 19:22:31 +0200 Subject: [PATCH 89/99] Roni recomendations conclution section --- content/software-licensing.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 8668dcd..f17139b 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -226,6 +226,8 @@ The scenarios below are independent. Find the row that matches what you are actu | Using Copilot, ChatGPT or Claude | [**8. AI-assisted code**](#scenario-8) | ๐ŸŸข Free choice, verify for memorization | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | | Shipping prompts, weights or datasets | [**9. AI workflows & assets**](#scenario-9) | ๐ŸŸข Dual-license code vs. assets | `MIT` + `CC-BY-4.0` | +This lesson covers nine scenarios, a typical session works through three or four. The rest are here for reference when your project changes + ## Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms When writing original code or implementing published algorithms, no third-party license constrains your choice โ€” but who owns the code depends on your employment contract and national rules, so check your institution's policy first. @@ -610,8 +612,7 @@ Always place the full text of your chosen license in a plain-text file named `LI ```text Copyright (c) 2026 [Author Name or Institution Name] ``` -* **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Custom license edits create *non-standard* legal texts that compliance scanners cannot parse, defaulting your repository back to restricted status. - +* **Do Not Edit Terms**: Never modify the legal wording of standard licenses (e.g., removing clauses from GPL or MIT). Edited texts are no longer the license they claim to be: compliance scanners cannot classify them, package registries may flag them, and downstream users have to get their own legal review before touching your code. If a standard license does not fit, pick a different standard license. ### 2. Documenting License Status in `README.md` @@ -683,7 +684,7 @@ flowchart TB ### Scenario Mapping Across the Pipeline * **Handling Inbound Copyleft ([Scenario 4](#scenario-4) & [Scenario 5](#scenario-5))**: When you copy non-trivial copyleft code snippets (e.g., CC BY-SA from Stack Overflow or GPL snippets) or link directly against a GPL library, your overall project becomes a combined work. Selecting a compatible copyleft license upfront (`GPL-3.0` or `EUPL-1.2`) satisfies the reciprocal sharing terms and allows the pipeline scanner to pass without conflict. -* **Maintaining Permissive Defaults ([Scenario 1](#scenario-1) & [Scenario 3](#scenario-3))**: If you write original code or embed only permissively licensed snippets (MIT, Apache-2.0, BSD), selecting a permissive license (`MIT` or `Apache-2.0`) grants downstream users maximum adoption freedom while preserving your citation credit. +* **Handling Inbound Copyleft ([Scenario 4](#scenario-4) & [Scenario 5](#scenario-5))**: Copying a non-trivial copyleft snippet (e.g., CC BY-SA code from Stack Overflow, or a GPL fragment) creates a combined work. Linking against a copyleft library may do the same, depending on the license and the linking method. In both cases, selecting a compatible copyleft license upfront (`GPL-3.0` or `EUPL-1.2`) satisfies the reciprocal terms and lets the scanner pass โ€” and checking the exact SPDX identifier first avoids the `GPL-2.0-only` incompatibility trap. * **Packaging and Build Automation ([Scenario 6](#scenario-6) & [Scenario 7](#scenario-7))**: Keep plain-text build recipes (Dockerfiles) permissively licensed for maximum reuse, while annotating compiled container image binaries as multi-license aggregate bundles to satisfy embedded base-layer obligations. * **AI Assets and Dual-Licensing ([Scenario 8](#scenario-8) & [Scenario 9](#scenario-9))**: Run code-similarity scanners to catch LLM training memorization before releasing AI-assisted code, and apply dual-licensing to separate executable software code (`MIT`) from non-code datasets and model weights (`CC-BY-4.0`). -* **Standardized Distribution**: By adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template, running `reuse lint` in your pipeline confirms 100% legal clarity for the entire scientific community. +* **Standardized Distribution**: Adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template lets `reuse lint` confirm that every asset has a declared, documented license. Note what this does and does not prove: the linter verifies that declarations exist and are well-formed, not that they are legally correct or mutually compatible. Automation makes your intent auditable โ€” it does not replace the judgment calls in the scenarios above. From 885f440bd9f536253b33e9f9dc21f578029e46a3 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sat, 26 Sep 2026 23:30:35 +0200 Subject: [PATCH 90/99] improve motivation diagram --- content/software-licensing.md | 64 +++++++++++------------------------ 1 file changed, 20 insertions(+), 44 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index f17139b..0fb6980 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -49,61 +49,37 @@ Weak copyleft is worth a closer look, because it is widely used and its terms ar The diagram below unifies these license choices and their downstream rights: + ```{mermaid} -%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff', 'fontSize': '16px' }}}%% flowchart TB - subgraph box["How License Selection Governs Code Reuse"] - A["Your Research Codebase
(Source code, container recipes, prompt templates)"] -->|"No License Attached
(Statutory Default)"| B["All Rights Reserved
โŒ Zero permissions: Cannot run, modify, or share"] - - A -->|"Attach License
(Explicit Permission Grant)"| C{"Select License"} - - C -->|"Goal: Maximum adoption & unrestricted reuse"| D["Permissive
MIT, Apache-2.0, 0BSD"] - C -->|"Goal: Keep the library open, allow closed users"| W["Weak Copyleft
LGPL-3.0, MPL-2.0, EPL-2.0"] - C -->|"Goal: Ensure changes stay open-source (Reciprocity)"| E["Copyleft
GPL-3.0, EUPL-1.2"] - C -->|"Goal: Proprietary control & restricted access"| F["Closed Source / Restricted
๐Ÿšซ Not discussed in this lesson"] + P["You paste a snippet
from another project"] --> J["โŒ license-check FAILED
job #142"] - D --> D1["Run & Modify? Yes"] - D --> D2["Embed in closed product? Yes"] - D --> D3["Must changes stay open? No (optional)"] + J -->|"Tempting: delete
your LICENSE file"| X["โš ๏ธ Scanner quiet,
nothing fixed

Your code reverts to
All Rights Reserved"] - W --> W1["Run & Modify? Yes"] - W --> W2["Embed in closed product? Yes, with conditions"] - W --> W3["Must changes stay open? Only the covered file or library"] + J -->|"Better: what does
the snippet require?"| Q{"Which license
family is it?"} - E --> E1["Run & Modify? Yes"] - E --> E2["Embed in closed product? No"] - E --> E3["Must changes stay open? Yes (mandatory)"] - end - - G["Reciprocity only triggers on distribution
Running modified code internally creates no obligation"] - E -.-> G - W -.-> G + Q --> D["Permissive
MIT, Apache-2.0
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โŒ"] + Q --> W["Weak Copyleft
LGPL, MPL-2.0
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Changes open โœ… file only"] + Q --> E["Copyleft
GPL-3.0, EUPL-1.2
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Changes open โœ…"] classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef red fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; classDef amber fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; + classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; + classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; + classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c0000; classDef white fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,color:#212529; - classDef dashed fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; - classDef dashed_red fill:#ffe3e3,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; - classDef note fill:#ffffff,stroke:#868e96,stroke-width:1px,stroke-dasharray: 3 3,color:#212529; - classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; - - class D1,D2,D3,W1,E1 green; - class W2,W3 amber; - class E2 red; - class E3 green; - class D yellow; + + class D green; class W amber; class E yellow; - class F dashed; - class B dashed_red; - class A,C white; - class G note; - class box box_fill; + class J fail; + class X warning; + class P,Q white; ``` +Deleting the `LICENSE` file only silences the scanner. You are still using someone else's code without permission, and with no license attached your own software defaults to **All Rights Reserved** โ€” so nobody may legally run, copy or build on it either. A green pipeline is not a compliance result. The real question is which family the snippet belongs to. Note that weak copyleft's conditions are where people get caught: LGPL lets you ship inside a closed product only if you don't restrict modification of the LGPL parts or reverse engineering for debugging them. Note too that reciprocity only triggers on **distribution** โ€” running modified copyleft code internally creates no obligation at all. The rest of this lesson works through these situations scenario by scenario. ### Copyright Foundation: Expression vs. Ideas @@ -226,7 +202,7 @@ The scenarios below are independent. Find the row that matches what you are actu | Using Copilot, ChatGPT or Claude | [**8. AI-assisted code**](#scenario-8) | ๐ŸŸข Free choice, verify for memorization | `MIT`, `Apache-2.0`, `EUPL-1.2`, `GPL-3.0` | | Shipping prompts, weights or datasets | [**9. AI workflows & assets**](#scenario-9) | ๐ŸŸข Dual-license code vs. assets | `MIT` + `CC-BY-4.0` | -This lesson covers nine scenarios, a typical session works through three or four. The rest are here for reference when your project changes +This lesson covers nine scenarios; a typical session works through three or four. The rest are here for reference when your project changes. ## Module 1: Clean Slate โ€“ Authoring Original Code & Algorithms @@ -646,7 +622,7 @@ legal status of every single asset in your codebase. ## Summary: Resolving the Compliance Pipeline -When developing research software, license compliance is not an afterthought to debug at the end of a project, it is a proactive design choice. By using the **Joinup Licensing Assistant (JLA)** framework to align your repository license with your inbound dependencies from day one, your CI/CD pipeline passes cleanly on the first run. +When developing research software, license compliance is not an afterthought to debug at the end of a project, it is a proactive design choice. By using the **Joinup Licensing Assistant (JLA)** framework to align your repository license with your inbound dependencies from day one, your pipeline is far less likely to fail on a license conflict late in the project. The diagram below illustrates how selecting a compatible license upfront ensures your code passes automated compliance checks and results in a legally sound release: @@ -683,7 +659,7 @@ flowchart TB ### Scenario Mapping Across the Pipeline -* **Handling Inbound Copyleft ([Scenario 4](#scenario-4) & [Scenario 5](#scenario-5))**: When you copy non-trivial copyleft code snippets (e.g., CC BY-SA from Stack Overflow or GPL snippets) or link directly against a GPL library, your overall project becomes a combined work. Selecting a compatible copyleft license upfront (`GPL-3.0` or `EUPL-1.2`) satisfies the reciprocal sharing terms and allows the pipeline scanner to pass without conflict. +* **Choosing Your Own Terms ([Scenario 1](#scenario-1), [Scenario 2](#scenario-2) & [Scenario 3](#scenario-3))**: When you write original code, implement a published algorithm, or embed only permissive snippets, no inbound license constrains you โ€” the choice follows your goal. Pick permissive (`MIT`, `Apache-2.0`) for maximum adoption, or copyleft (`EUPL-1.2`, `GPL-3.0`) if you want downstream improvements shared back. Either way, preserve any third-party notices attached to code you embedded. * **Handling Inbound Copyleft ([Scenario 4](#scenario-4) & [Scenario 5](#scenario-5))**: Copying a non-trivial copyleft snippet (e.g., CC BY-SA code from Stack Overflow, or a GPL fragment) creates a combined work. Linking against a copyleft library may do the same, depending on the license and the linking method. In both cases, selecting a compatible copyleft license upfront (`GPL-3.0` or `EUPL-1.2`) satisfies the reciprocal terms and lets the scanner pass โ€” and checking the exact SPDX identifier first avoids the `GPL-2.0-only` incompatibility trap. * **Packaging and Build Automation ([Scenario 6](#scenario-6) & [Scenario 7](#scenario-7))**: Keep plain-text build recipes (Dockerfiles) permissively licensed for maximum reuse, while annotating compiled container image binaries as multi-license aggregate bundles to satisfy embedded base-layer obligations. * **AI Assets and Dual-Licensing ([Scenario 8](#scenario-8) & [Scenario 9](#scenario-9))**: Run code-similarity scanners to catch LLM training memorization before releasing AI-assisted code, and apply dual-licensing to separate executable software code (`MIT`) from non-code datasets and model weights (`CC-BY-4.0`). From d2afef63c67266c60d629e9049234973d1c889b0 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 00:06:54 +0200 Subject: [PATCH 91/99] Trim the intro --- content/software-licensing.md | 50 +++++++++++++---------------------- 1 file changed, 18 insertions(+), 32 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 0fb6980..ab74a28 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -27,59 +27,45 @@ If you need formal guidance references below and legal experts, especially if yo * [Research Software Alliance Policy Directory](https://www.researchsoft.org/software-policies/) ``` -## Introduction: What is a Software License? - -Under copyright law worldwide, software without an explicit license defaults to All Rights Reserved: nobody else may run, copy, modify, distribute, or build on your code. A software license is how the copyright holder exercises their exclusive rights, granting others permission to reproduce, distribute, modify, and sometimes sublicense the work. - -Note that author and copyright holder may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. This matters in practice, because the person choosing the license for a research project is often not the person who wrote the code. - -In this lesson, we focus on open-source licenses to define both how we grant permissions for software we develop (outbound licensing) and how we safely comply with terms attached to code written by others (inbound reuse). - -Open-source licenses fall into three main families: - -* **Permissive (e.g., MIT, Apache-2.0, 0BSD):** *Do whatever you want, just keep credit.* Grants maximum reuse freedom, allowing anyone to modify, embed, or re-license your code in open or closed projects. - -* **Copyleft / Reciprocal (e.g., GPL-3.0, EUPL-1.2):** *Share alike.* Grants full freedom to run and modify, but requires that any distributed adaptation or combined work also be released under matching copyleft terms. -* **Weak copyleft (e.g., LGPL-3.0, MPL-2.0, EPL-2.0):** *Share alike, but only within a boundary.* Reciprocity applies to the file (MPL-2.0) or the library (LGPL), not to your whole project. Your surrounding code can usually stay permissive or even closed, while modifications to the covered files or library must stay open. - -You will hear copyleft called *viral* or *infectious* in developer conversation. The slang is worth knowing, but it is misleading in two ways: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or a container image is unaffected, and the requirement only triggers when you **distribute**, not when you run modified code internally. Reciprocity reaches only across specific technical boundaries such as embedding snippets or static linking, and how far it reaches depends on which copyleft license you are dealing with. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. +## Introduction: What is a Software License? -Weak copyleft is worth a closer look, because it is widely used and its terms are more conditional than the label suggests. LGPL-3.0 ยง4 lets you ship a combined work under your own terms only if those terms do not restrict modification of the LGPL portions, or reverse engineering for debugging those modifications, and this condition applies whether you linked statically or dynamically. Since most proprietary end-user licenses forbid reverse engineering, the common shorthand that "dynamic linking is safe" is not the whole story. The practical lesson is that "does this dependency force my project open?" has no general answer: it depends on which copyleft license, and at which boundary. +Under copyright law worldwide, software without an explicit license defaults to **All Rights Reserved**: nobody else may run, copy, modify, distribute, or build on your code. A software license is how the copyright holder exercises their exclusive rights, granting others permission to reproduce, distribute, modify, and sometimes sublicense the work. -The diagram below unifies these license choices and their downstream rights: +Note that *author* and *copyright holder* may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. This matters in practice, because the person choosing the license for a research project is often not the person who wrote the code. +Open-source licenses fall into three families, which differ in what they let downstream users do: ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff', 'fontSize': '16px' }}}%% flowchart TB - P["You paste a snippet
from another project"] --> J["โŒ license-check FAILED
job #142"] - - J -->|"Tempting: delete
your LICENSE file"| X["โš ๏ธ Scanner quiet,
nothing fixed

Your code reverts to
All Rights Reserved"] - - J -->|"Better: what does
the snippet require?"| Q{"Which license
family is it?"} + A["Your code"] -->|"no license"| B["All Rights Reserved
Nobody may run,
copy or modify it"] + A -->|"attach a license"| C{"What do you want
downstream users
to be able to do?"} - Q --> D["Permissive
MIT, Apache-2.0
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โŒ"] - Q --> W["Weak Copyleft
LGPL, MPL-2.0
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Changes open โœ… file only"] - Q --> E["Copyleft
GPL-3.0, EUPL-1.2
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Changes open โœ…"] + C --> D["Permissive
MIT, Apache-2.0
'Reuse freely, keep credit'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โŒ"] + C --> W["Weak Copyleft
LGPL, MPL-2.0
'Share alike, within a boundary'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Changes open โœ… file/library only"] + C --> E["Copyleft
GPL-3.0, EUPL-1.2
'Share alike'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Changes open โœ…"] classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef amber fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; classDef yellow fill:#fff9db,stroke:#f59f00,stroke-width:2px,color:#5c3c00; - classDef fail fill:#ffe3e3,stroke:#e03131,stroke-width:2px,color:#5c0000; - classDef warning fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c0000; + classDef dashed_red fill:#ffe3e3,stroke:#adb5bd,stroke-width:2px,stroke-dasharray: 5 5,color:#000000; classDef white fill:#f8f9fa,stroke:#adb5bd,stroke-width:2px,color:#212529; class D green; class W amber; class E yellow; - class J fail; - class X warning; - class P,Q white; + class B dashed_red; + class A,C white; ``` -Deleting the `LICENSE` file only silences the scanner. You are still using someone else's code without permission, and with no license attached your own software defaults to **All Rights Reserved** โ€” so nobody may legally run, copy or build on it either. A green pipeline is not a compliance result. The real question is which family the snippet belongs to. Note that weak copyleft's conditions are where people get caught: LGPL lets you ship inside a closed product only if you don't restrict modification of the LGPL parts or reverse engineering for debugging them. Note too that reciprocity only triggers on **distribution** โ€” running modified copyleft code internally creates no obligation at all. The rest of this lesson works through these situations scenario by scenario. + +Three things the table above cannot show. **Weak copyleft's conditions are where people get caught**: LGPL-3.0 ยง4 lets you ship inside a closed product only if your terms don't restrict modification of the LGPL portions or reverse engineering for debugging them, and that holds whether you linked statically or dynamically. **Reciprocity only triggers on distribution**: running modified copyleft code internally creates no obligation. And **copyleft licenses are often incompatible with each other**, so choosing one also decides who can combine with your work later. + +You will hear copyleft called *viral* or *infectious*. The slang is worth knowing, but it misleads: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or container image is unaffected. Reciprocity reaches only across specific technical boundaries, such as embedding snippets or static linking, and how far it reaches depends on which copyleft license applies. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. + +This lesson covers both directions: choosing terms for software you write, and complying with terms attached to code written by others. The scenarios later work through each case. ### Copyright Foundation: Expression vs. Ideas From 24f399490b4f20b599a74b113932a96a997fb7e7 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 00:12:45 +0200 Subject: [PATCH 92/99] Make the conclusion coherent with intro --- content/software-licensing.md | 43 +++++++++++++++++------------------ 1 file changed, 21 insertions(+), 22 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index ab74a28..578c7bd 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -613,35 +613,34 @@ When developing research software, license compliance is not an afterthought to The diagram below illustrates how selecting a compatible license upfront ensures your code passes automated compliance checks and results in a legally sound release: ```{mermaid} - -%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff' }}}%% +%%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff', 'fontSize': '16px' }}}%% flowchart TB - subgraph local["1. Local Authoring & Standardization"] - A["Inbound Reuse Trigger:
User copies copyleft snippet (Scenario 4)
or links GPL library (Scenario 5)"] --> B["JLA Selection Strategy:
Select compatible copyleft license
(GPL-3.0 / EUPL-1.2)"] - - B --> C["Standardize Local Codebase:
1. Add SPDX Headers to all files (Scenarios 1-9)
2. Add root LICENSE file & README badge"] - end + subgraph local["โ‘  What you do differently now โ€” before pushing"] + direction LR + A["Paste a snippet
copied from somewhere"] --> L["Identify its
license family"] --> S["Choose a compatible
license + add
SPDX headers"] + end - subgraph cicd["2. Automated CI/CD & Verification"] - C -->|"Git Push to Repository"| D["Build Trigger: Run Compliance Scanner
(Executes reuse lint in CI/CD)"] - - D --> E{"Verify Inbound vs.
Outbound Terms
"} - - E -->|"SPDX Headers & License Match Confirmed!"| F["โœ… BUILD PASSES
Compliance verified automatically"] - - F --> SUCCESS["๐ŸŽ‰ COMPLIANT OPEN-SOURCE RELEASE
Legally sound, reproducible & ready for scientific reuse"] - end + subgraph ci["โ‘ก The same pipeline as before"] + direction LR + T["Build Trigger:
Push to my-code-base"] --> B["Run Compliance
Scanner"] --> C{"Check Inbound vs.
Outbound Terms"} + end - classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; - classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; - classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; + S --> T + C -->|"terms match"| P["โœ… BUILD PASS ยท job #143
Compliant, reusable release"] + + classDef pass fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; + classDef neutral fill:#f8f9fa,stroke:#495057,stroke-width:2px,color:#212529; + classDef fix fill:#e7f5ff,stroke:#1c7ed6,stroke-width:2px,color:#0b3d6b; + classDef box_fill fill:#ffffff,stroke:#adb5bd,stroke-width:1px; - class F,SUCCESS pass; - class A,B,C,D,E neutral; - class local,cicd box_fill; + class P pass; + class A,T,B,C neutral; + class L,S fix; + class local,ci box_fill; ``` +Compare this with the failing pipeline at the start of the lesson: the pipeline itself is identical. Nothing about the scanner changed โ€” the only difference is two decisions made before pushing. ### Scenario Mapping Across the Pipeline From 16b0a6fe1762c6e37a0fef8c19a8b129300fa888 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 00:25:55 +0200 Subject: [PATCH 93/99] formating --- content/software-licensing.md | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 578c7bd..70d0237 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -11,13 +11,13 @@ ```{discussion} Limitations and context of this lesson -This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice** +This lesson is designed as practical educational material for researchers and research software engineers, **not formal legal advice**. * EU directives set only minimum requirements in some areas: Member States implement them differently and may add national rules not covered here. For example, some Member States let university researchers retain ownership of the programs they write instead of applying the employer rule in Art. 2(3). * Institutional Context: Employment contracts, grant agreements, and university policies heavily influence software ownership and licensing choices. * This lesson covers only the general principles of open-source reuse, copyright scope, and software adaptation. -If you need formal guidance references below and legal experts, especially if you have legal services at your host institute, could be of help: +If you need formal guidance, the references below can help โ€” and so can legal experts, especially if your host institute has a legal services office: * [EUR Directive 2009/24/EC](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32009L0024) * [Compendium of U.S. Copyright Office Practices (3rd Ed.) โ€“ Chapter 700, Section 721: Computer Programs](https://www.copyright.gov/comp3/) @@ -61,7 +61,7 @@ flowchart TB class A,C white; ``` -Three things the table above cannot show. **Weak copyleft's conditions are where people get caught**: LGPL-3.0 ยง4 lets you ship inside a closed product only if your terms don't restrict modification of the LGPL portions or reverse engineering for debugging them, and that holds whether you linked statically or dynamically. **Reciprocity only triggers on distribution**: running modified copyleft code internally creates no obligation. And **copyleft licenses are often incompatible with each other**, so choosing one also decides who can combine with your work later. +Three things the diagram above cannot show. **Weak copyleft's conditions are where people get caught**: LGPL-3.0 ยง4 lets you ship inside a closed product only if your terms don't restrict modification of the LGPL portions or reverse engineering for debugging them, and that holds whether you linked statically or dynamically. **Reciprocity only triggers on distribution**: running modified copyleft code internally creates no obligation. And **copyleft licenses are often incompatible with each other**, so choosing one also decides who can combine with your work later. You will hear copyleft called *viral* or *infectious*. The slang is worth knowing, but it misleads: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or container image is unaffected. Reciprocity reaches only across specific technical boundaries, such as embedding snippets or static linking, and how far it reaches depends on which copyleft license applies. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. @@ -100,7 +100,7 @@ flowchart TB A2 --> B["Run Compliance Scanner"] B --> C{"Check Inbound vs.
Outbound Terms"} - C -->|"Target license: Permissive
Pasted snippet: Copyleft"| D["โŒ BUILD FAILURE
Pasted copyleft snippet blocks MIT release"] + C -->|"Target license: Permissive
Pasted snippet: Copyleft"| D["โŒ BUILD FAILURE ยท job #142
Pasted copyleft snippet blocks MIT release"] D --> E{"Select Patch Option"} @@ -153,7 +153,7 @@ Developers working under EU statutory frameworks face a different legal reality * **US law (17 U.S.C. ยง 101)** formally defines *"derivative work"*, and AI assistants reach for it to describe almost any code modification. * **EU law (Directive 2009/24/EC, Art. 4(1)(b))** does not use that term at all. It grants exclusive rights over "the translation, adaptation, arrangement and any other alteration of a computer program" โ€” governed collectively as an **adaptation**. -* **Licenses use it anyway**: `GPL-3.0` and `EUPL-1.2` define "derivative work" inside their own text as a contractual term for international enforceability, even though EU statute treats the act as an adaptation. +* **Licenses vary**: `EUPL-1.2` defines "Derivative Works" in its own text as a contractual term, and `GPL-2.0` used the phrase too. `GPL-3.0` deliberately dropped it in favour of "modify" and "a work based on the Program", because its drafters recognised the term means different things in different jurisdictions โ€” the same problem you face when an AI assistant uses it. So when an AI assistant tells you a snippet creates a "derivative work", treat that as a prompt to check the actual question under EU law: is this a statutory **adaptation**, or a **combined work** across a technical boundary? The rest of this lesson gives you that EU-aligned framework. @@ -438,7 +438,7 @@ COPY solver.py /app/solver.py You compiled and published a pre-built container image (e.g., pushing a compiled Docker image to Docker Hub, GitHub Container Registry, or an institutional registry) containing an OS layer, runtime binaries, dependencies, and your application code. * **Licensing Goal**: Safely distribute compiled container images without violating the license terms of any software layer or binary included inside the image. -* **Legal Reality**: A compiled container image is a **multi-license aggregate bundle**, not a single combined work. Distributing pre-built binaries makes you a distributor of every package inside, so source-availability obligations apply to the copyleft components (Linux base packages, coreutils, GPL libraries). But those packages sitting in the same filesystem as your application do not make your application a derivative of them โ€” this is mere aggregation. Your own code keeps whatever license you chose; you simply also carry distributor obligations for the copyleft software you are shipping alongside it. +* **Legal Reality**: A compiled container image is a **multi-license aggregate bundle**, not a single combined work. Distributing pre-built binaries makes you a distributor of every package inside, so source-availability obligations apply to the copyleft components (Linux base packages, coreutils, GPL libraries). But those packages sitting in the same filesystem as your application do not make your application a derivative of them, this is mere aggregation. Your own code keeps whatever license you chose; you simply also carry distributor obligations for the copyleft software you are shipping alongside it. * **JLA Selection Strategy**: Because a container image combines multiple distinct software components, JLA is used to evaluate constituent component obligations. When distributing compiled binaries containing copyleft layers, source disclosure requirements (`Disclose source`) must be fulfilled for those specific layers. :::{solution} @@ -603,8 +603,7 @@ pip install reuse reuse lint ``` -When `reuse lint` passes, downstream researchers can automatically verify the -legal status of every single asset in your codebase. +When `reuse lint` passes, every asset in your codebase carries a declared, machine-readable license that downstream users can check. ## Summary: Resolving the Compliance Pipeline From b5ae45bcbe674a44a521cb8960caf6e7755ed38f Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 00:43:59 +0200 Subject: [PATCH 94/99] Include a gloassary --- content/software-licensing.md | 90 +++++++++++++++++++++++++++++++++++ 1 file changed, 90 insertions(+) diff --git a/content/software-licensing.md b/content/software-licensing.md index 70d0237..9e96d01 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -648,3 +648,93 @@ Compare this with the failing pipeline at the start of the lesson: the pipeline * **Packaging and Build Automation ([Scenario 6](#scenario-6) & [Scenario 7](#scenario-7))**: Keep plain-text build recipes (Dockerfiles) permissively licensed for maximum reuse, while annotating compiled container image binaries as multi-license aggregate bundles to satisfy embedded base-layer obligations. * **AI Assets and Dual-Licensing ([Scenario 8](#scenario-8) & [Scenario 9](#scenario-9))**: Run code-similarity scanners to catch LLM training memorization before releasing AI-assisted code, and apply dual-licensing to separate executable software code (`MIT`) from non-code datasets and model weights (`CC-BY-4.0`). * **Standardized Distribution**: Adding machine-readable **SPDX headers** across every script, Dockerfile, and prompt template lets `reuse lint` confirm that every asset has a declared, documented license. Note what this does and does not prove: the linter verifies that declarations exist and are well-formed, not that they are legally correct or mutually compatible. Automation makes your intent auditable โ€” it does not replace the judgment calls in the scenarios above. + +## Glossary + +````{admonition} Glossary of terms (click to expand) +:class: dropdown + +```{glossary} +Adaptation + EU term (Art. 4(1)(b)) for translating, arranging, or altering a program; roughly the US *derivative work*. + +AGPL-3.0 + Strong copyleft that also requires sharing source when users interact with modified software over a network. + +All Rights Reserved + Default for unlicensed software: nobody but the copyright holder may run, copy, modify, or share it. + +Author + The person who created the program; not always the copyright holder. + +Combined work + One work formed by merging separately licensed code, e.g. embedding a snippet or static linking. + +Compatibility + Whether two licenses allow their code to be combined and distributed together. + +Container image + A built binary snapshot (`.sif`, OCI image) bundling many packages under many licenses. + +Container recipe + The plain-text build instructions (`Dockerfile`, `.def`); source code in its own right. + +Copyleft + Licenses requiring distributed adaptations to use matching terms (GPL-3.0, EUPL-1.2). + +Copyright holder + Whoever holds the economic rights and can license the work: the author, employer, or assignee. + +Corresponding source + The full source and build scripts needed to rebuild the exact binaries you distributed. + +Derivative work + US term (17 U.S.C. ยง 101) for a work based on another; EU law says *adaptation*. + +Distribution + Giving copies to others outside your organisation; this is what triggers copyleft obligations. + +Dynamic linking + Loading a separate library at runtime; whether it creates a combined work is unsettled. + +Economic rights + Exclusive rights to copy, adapt, and distribute; often exercised by the employer (Art. 2(3)). + +EUPL-1.2 + The European Commission's copyleft license, available in 23 EU languages. + +Expression vs. ideas + Copyright protects your code, not the underlying algorithms, functionality, or interfaces. + +Inbound licensing + The licenses on others' code you bring into your project. + +JLA + Joinup Licensing Assistant, the Commission's tool for comparing licenses. + +LGPL + Weak copyleft for libraries; your app may use other terms if it allows modifying and debugging the library. + +Memorization + When an AI model reproduces training code verbatim; that code keeps its original license. + +Mere aggregation + Separate programs shipped side by side; copyleft does not spread between them. + +-only / -or-later + SPDX suffixes: `GPL-2.0-only` cannot move to GPL-3.0; `-or-later` can. + +Originality threshold + A program is protected only if it is the author's own intellectual creation (Art. 1(3)). + +Outbound licensing + The license you choose for your own project. + +Permissive + Licenses allowing any reuse if notices are kept (MIT, Apache-2.0, BSD). + +Reciprocity + The copyleft requirement to share adaptations under matching terms. + +REUSE + FSFE standard for per-file license declarations; From f3b755767f225eb2ed93d80d27486d897f7fef6a Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 18:45:10 +0200 Subject: [PATCH 95/99] make LGPL simpler --- content/software-licensing.md | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 9e96d01..dd9e042 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -34,6 +34,8 @@ Under copyright law worldwide, software without an explicit license defaults to Note that *author* and *copyright holder* may differ: under Art. 2(3), an employer exercises the economic rights in code written by an employee on the job, unless a contract says otherwise. The employee is still the author; the employer is who licenses it. This matters in practice, because the person choosing the license for a research project is often not the person who wrote the code. +This lesson focuses on open-source licenses. If your employment terms and institutional policy allow you to open-source the code you write, we recommend doing so. It makes you a better citizen of the research community, since others can reuse, verify, and build on your work. It also protects **your future self**: code your employer owns and never licenses stays locked behind All Rights Reserved when you change jobs, whereas an open license grants everyone the right to reuse it, including you. + Open-source licenses fall into three families, which differ in what they let downstream users do: ```{mermaid} @@ -61,7 +63,11 @@ flowchart TB class A,C white; ``` -Three things the diagram above cannot show. **Weak copyleft's conditions are where people get caught**: LGPL-3.0 ยง4 lets you ship inside a closed product only if your terms don't restrict modification of the LGPL portions or reverse engineering for debugging them, and that holds whether you linked statically or dynamically. **Reciprocity only triggers on distribution**: running modified copyleft code internally creates no obligation. And **copyleft licenses are often incompatible with each other**, so choosing one also decides who can combine with your work later. +Three rules of thumb the diagram cannot show: + +* **Copyleft only applies when you share the code.** Running modified GPL code on your own machine or cluster creates no obligations. +* **"Weak" copyleft still has conditions.** For example, if you ship an LGPL library inside a closed product, you must still let users modify and debug that library. +* **Copyleft licenses often don't mix.** Code under two different copyleft licenses may not be combinable, so your choice today decides who can build on your work later. You will hear copyleft called *viral* or *infectious*. The slang is worth knowing, but it misleads: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or container image is unaffected. Reciprocity reaches only across specific technical boundaries, such as embedding snippets or static linking, and how far it reaches depends on which copyleft license applies. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. From db404625afcb684948666da2926f3c054dfa92de Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 18:47:12 +0200 Subject: [PATCH 96/99] viral jagon --- content/software-licensing.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index dd9e042..64efffd 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -69,7 +69,7 @@ Three rules of thumb the diagram cannot show: * **"Weak" copyleft still has conditions.** For example, if you ship an LGPL library inside a closed product, you must still let users modify and debug that library. * **Copyleft licenses often don't mix.** Code under two different copyleft licenses may not be combinable, so your choice today decides who can build on your work later. -You will hear copyleft called *viral* or *infectious*. The slang is worth knowing, but it misleads: nothing spreads by mere contact, so code merely sitting beside GPL code in a repository or container image is unaffected. Reciprocity reaches only across specific technical boundaries, such as embedding snippets or static linking, and how far it reaches depends on which copyleft license applies. Choosing copyleft over permissive is a project-level decision, not a sign that a license is harmful. +You will hear copyleft called *viral* or *infectious*. The slang is misleading: copyleft doesn't spread just because GPL code sits next to yours in a repository or container. It only applies when you build GPL code into your own, for example by copying in a snippet. And choosing copyleft is a legitimate project decision, not a sign that a license is harmful. This lesson covers both directions: choosing terms for software you write, and complying with terms attached to code written by others. The scenarios later work through each case. From 6e43016dc3b63060867e5c94dab4a7c5f0e0d304 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 22:08:01 +0200 Subject: [PATCH 97/99] Change permisive icon to question mark --- content/software-licensing.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 64efffd..7261e6c 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -46,7 +46,7 @@ flowchart TB A["Your code"] -->|"no license"| B["All Rights Reserved
Nobody may run,
copy or modify it"] A -->|"attach a license"| C{"What do you want
downstream users
to be able to do?"} - C --> D["Permissive
MIT, Apache-2.0
'Reuse freely, keep credit'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โŒ"] + C --> D["Permissive
MIT, Apache-2.0
'Reuse freely, keep credit'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โ“"] C --> W["Weak Copyleft
LGPL, MPL-2.0
'Share alike, within a boundary'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Changes open โœ… file/library only"] C --> E["Copyleft
GPL-3.0, EUPL-1.2
'Share alike'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Changes open โœ…"] From a8d45959b382ce80dd21c5014604a404c329c456 Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 22:53:48 +0200 Subject: [PATCH 98/99] Make permissive more clearer --- content/software-licensing.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 7261e6c..51a7005 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -38,6 +38,7 @@ This lesson focuses on open-source licenses. If your employment terms and instit Open-source licenses fall into three families, which differ in what they let downstream users do: + ```{mermaid} %%{init: {'themeVariables': { 'edgeLabelBackground': '#faf5ff', 'fontSize': '16px' }}}%% @@ -46,9 +47,9 @@ flowchart TB A["Your code"] -->|"no license"| B["All Rights Reserved
Nobody may run,
copy or modify it"] A -->|"attach a license"| C{"What do you want
downstream users
to be able to do?"} - C --> D["Permissive
MIT, Apache-2.0
'Reuse freely, keep credit'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Changes open โ“"] - C --> W["Weak Copyleft
LGPL, MPL-2.0
'Share alike, within a boundary'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Changes open โœ… file/library only"] - C --> E["Copyleft
GPL-3.0, EUPL-1.2
'Share alike'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Changes open โœ…"] + C --> D["Permissive
MIT, Apache-2.0
'Reuse freely, keep credit'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ…
Must share changes โŒ"] + C --> W["Weak Copyleft
LGPL, MPL-2.0
'Share alike, within a boundary'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โœ… cond.
Must share changes โœ… file/library only"] + C --> E["Copyleft
GPL-3.0, EUPL-1.2
'Share alike'
โ”โ”โ”โ”โ”โ”
Run & modify โœ…
Closed product โŒ
Must share changes โœ…"] classDef green fill:#e6ffe6,stroke:#2b8a3e,stroke-width:2px,color:#1b4332; classDef amber fill:#fff3bf,stroke:#f08c00,stroke-width:2px,color:#5c3c00; From f26885e2dd3836036804e8c9946bb2a5c919f87e Mon Sep 17 00:00:00 2001 From: Sabry Razick Date: Sun, 27 Sep 2026 23:35:01 +0200 Subject: [PATCH 99/99] Update glossary --- content/software-licensing.md | 86 +++++++++++++++++++++++++++++++++-- 1 file changed, 81 insertions(+), 5 deletions(-) diff --git a/content/software-licensing.md b/content/software-licensing.md index 51a7005..09686e2 100644 --- a/content/software-licensing.md +++ b/content/software-licensing.md @@ -64,7 +64,7 @@ flowchart TB class A,C white; ``` -Three rules of thumb the diagram cannot show: +Three rules of thumb as an compliment to the diagram: * **Copyleft only applies when you share the code.** Running modified GPL code on your own machine or cluster creates no obligations. * **"Weak" copyleft still has conditions.** For example, if you ship an LGPL library inside a closed product, you must still let users modify and debug that library. @@ -142,7 +142,7 @@ flowchart TB class box box_fill; ``` -* Option D is the one worth dwelling on: deleting the `LICENSE` file makes the scanner quiet without changing anything legally. You are still distributing someone else's copyleft code without honouring its terms, and you have now stripped your own users of any permission to use your work. A green pipeline is not a compliance result. +* Option D : deleting the `LICENSE` file makes the scanner quiet without changing anything legally. You are still distributing someone else's copyleft code without honouring its terms, and you have now stripped your own users of any permission to use your work. A green pipeline is not a compliance result. * Option C works only if you genuinely reimplement the functionality without copying the original expression. As the idea/expression split above establishes, the algorithm is free to reuse โ€” the specific code is not. Reading the original closely and retyping a close paraphrase is still copying. @@ -662,6 +662,9 @@ Compare this with the failing pipeline at the start of the lesson: the pipeline :class: dropdown ```{glossary} +0BSD + Zero-Clause BSD, a permissive license so minimal it doesn't even require keeping the copyright notice. + Adaptation EU term (Art. 4(1)(b)) for translating, arranging, or altering a program; roughly the US *derivative work*. @@ -671,9 +674,33 @@ AGPL-3.0 All Rights Reserved Default for unlicensed software: nobody but the copyright holder may run, copy, modify, or share it. +Apache-2.0 + Permissive license like MIT, plus an explicit patent grant and a requirement to note changes you made. + +API + Application Programming Interface: the defined way one program calls another. The idea of an interface is not protected by copyright; the code implementing it is. + Author The person who created the program; not always the copyright holder. +BSD-3-Clause + Permissive license like MIT, plus a clause forbidding use of the authors' names to promote derived products. + +CC BY-SA + Creative Commons share-alike license used for code posted on Stack Overflow; adaptations must carry the same terms, much like copyleft. + +CC-BY-4.0 + Creative Commons license allowing any reuse if the creator is credited; suited to data, documentation, and models rather than code. + +CC0 + Creative Commons tool waiving rights as far as the law allows, placing a work as close to the public domain as possible. + +CI/CD + Continuous Integration / Continuous Delivery: automated pipelines that build, test, and check code on every push, including license compliance checks. + +CJEU + Court of Justice of the European Union; its rulings interpret EU law for all Member States. + Combined work One work formed by merging separately licensed code, e.g. embedding a snippet or static linking. @@ -707,12 +734,21 @@ Dynamic linking Economic rights Exclusive rights to copy, adapt, and distribute; often exercised by the employer (Art. 2(3)). +EPL-2.0 + Eclipse Public License, a weak copyleft license applying at the file/module level. + EUPL-1.2 The European Commission's copyleft license, available in 23 EU languages. Expression vs. ideas Copyright protects your code, not the underlying algorithms, functionality, or interfaces. +FSF + Free Software Foundation, the US non-profit that publishes the GPL family of licenses. + +GPL + GNU General Public License, the most widely used strong copyleft license. `GPL-3.0` is the current version; `GPL-2.0` is still common. + Inbound licensing The licenses on others' code you bring into your project. @@ -722,18 +758,33 @@ JLA LGPL Weak copyleft for libraries; your app may use other terms if it allows modifying and debugging the library. +LLM + Large Language Model, the technology behind AI assistants such as ChatGPT, Copilot, and Claude. + Memorization When an AI model reproduces training code verbatim; that code keeps its original license. Mere aggregation Separate programs shipped side by side; copyleft does not spread between them. --only / -or-later - SPDX suffixes: `GPL-2.0-only` cannot move to GPL-3.0; `-or-later` can. +MIT + The most widely used permissive license: short, simple, and requires only that the copyright and license notice be kept. + +MPL-2.0 + Mozilla Public License, a weak copyleft license applying per file: modified MPL files stay MPL, new files can use any license. + +OCI + Open Container Initiative, the standard format for container images used by Docker, Podman, and registries. + +OpenRAIL + Behavioral licenses for AI models that forbid specific harmful uses; because they restrict use, they are not OSI open source. Originality threshold A program is protected only if it is the author's own intellectual creation (Art. 1(3)). +OSI + Open Source Initiative, the non-profit that approves licenses as meeting the Open Source Definition. + Outbound licensing The license you choose for your own project. @@ -744,4 +795,29 @@ Reciprocity The copyleft requirement to share adaptations under matching terms. REUSE - FSFE standard for per-file license declarations; + FSFE standard for per-file license declarations; `reuse lint` checks they exist, not that they are correct. + +RSE + Research Software Engineer: a professional who develops and maintains software used in research. + +SPDX identifier + Standard license tag in file headers, e.g. `MIT`, `GPL-3.0-or-later`. + +SPDX version suffixes + `-only` and `-or-later`: `GPL-2.0-only` cannot move to GPL-3.0; `GPL-2.0-or-later` can. + +Static linking + Copying library code into your binary at build time; generally creates a combined work. + +Sublicense + Passing on permissions under your own terms; allowed by MIT, generally not by copyleft. + +Sui generis database right + EU right protecting databases built with substantial investment; unclear for model weights. + +Viral / infectious + Misleading slang for copyleft; it does not spread by mere contact. + +Weak copyleft + Reciprocity limited to a file (MPL-2.0) or library (LGPL). +```