Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Curation for PyPI Pillow package #25983

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dangoor
Copy link
Contributor

@dangoor dangoor commented Oct 30, 2023

As seen from all of the previous curations, Pillow is licensed HPND.

See also the license file.

@capfei
Copy link
Member

capfei commented Oct 31, 2023

@dangoor It looks like this PR has more than a curation in it. Did you mean to include a GitHub action, README update and updating the package.json?

@capfei capfei added the feedback requested Unclear curation. PRs with this label will be closed after 60 days if no activity. label Oct 31, 2023
@dangoor
Copy link
Contributor Author

dangoor commented Oct 31, 2023

🤦 That's what I get for doing this manually (we were seeing issues with tooling not being able to open PRs for some reason). I'll fix this.

As seen from all of the previous curations, Pillow is licensed HPND.

See also [the license file](https://github.com/python-pillow/Pillow/blob/main/LICENSE).
@dangoor
Copy link
Contributor Author

dangoor commented Oct 31, 2023

OK, fixed!

@capfei
Copy link
Member

capfei commented Nov 1, 2023

@dangoor Thanks for the update!

I have had this discussion about other Pillow curations but I think this should be updated to MIT-CMU. Following the SPDX matching guidelines, this is a match. Also, SPDX uses Pillow as a reference to this license.
https://spdx.org/licenses/MIT-CMU.html
image

What do you think?

@dangoor
Copy link
Contributor Author

dangoor commented Nov 1, 2023

@capfei Interesting that it's a text match for MIT-CMU. In fact, it looks like the text is a match for MIT-CMU but not for HPND despite the fact that Pillow's license file says it's HPND

I think you're right that the more correct license is MIT-CMU.

@AE49
Copy link
Contributor

AE49 commented Nov 2, 2023

@ariel11 for visibility on this because the license says "HPND", however, as @capfei pointed out the SPDX match is MIT-CMU.

@dangoor
Copy link
Contributor Author

dangoor commented Nov 2, 2023

It may be worth opening a pull request with the Pillow project to change the license file to remove the HPND sentence, since it's incorrect.

@ariel11
Copy link
Contributor

ariel11 commented Dec 12, 2023

@capfei - what should we do here? Technically, with the colored font on the SPDX templates, one could determine the pillow license (this portion) matches the HPND or MIT-CMU SPDX identifiers. I agree the MIT-CMU is the more complete SPDX identifier but then the pillow license calls itself HPND. Thoughts on opening an Issue or PR on this with pillow?

@capfei
Copy link
Member

capfei commented Apr 4, 2024

Sorry for the long delay here. I have opened an issue with Pillow asking about either changing the license name to MIT-CMU or simply listing the SPDX identifer in the license file.
python-pillow/Pillow#7942

HPND does not include the first paragraph in the matchable text so I would argue that it is not a match to HPND since the first paragraph looks to be a part of the license text.
image

@capfei capfei added researching Issue with multiple versions and removed feedback requested Unclear curation. PRs with this label will be closed after 60 days if no activity. labels Apr 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
researching Issue with multiple versions
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants