mirror of
https://github.com/pgsty/minio.git
synced 2026-08-09 15:53:28 +03:00
docs: adopt the no-CLA plus DCO policy and fix copyright terms
Brings the server in line with the contribution and copyright policy already adopted in pgsty/mc. Copyright terms were derived from the clock: startupBanner overwrote the ldflags-injected CopyrightYear with time.Now().Year() and printed it as the end of MinIO, Inc.'s term, so every January would have extended the upstream copyright claim past the 2025 end of upstream development, and release builds silently discarded the injected year. Both banners now credit MinIO, Inc. for 2015-2025 and PGSTY from 2025 through the release-stamped year, falling back to the current year in source builds. NOTICE names PGSTY as the holder of the fork's modifications, matching the banners and the packaging vendor field. Contributions are accepted inbound=outbound under AGPL-3.0-or-later with no CLA - the core is Copyright MinIO, Inc., so the combined work can never be relicensed and a CLA would buy nothing. What a fork carrying a downstream delta does need is provenance, so DCO 1.1 sign-off is now mandatory and enforced by a workflow that rejects unsigned non-bot commits. CONTRIBUTING documents sign-off, repair, cherry-pick provenance, dual copyright headers, trailer preservation across squash merges, and that assistive-tooling trailers carry no authorship or copyright claim. verify-rebrand.sh pins the copyright split and the policy files so neither can regress. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Signed-off-by: Feng Ruohang <rh@vonng.com>
This commit is contained in:
@@ -112,6 +112,21 @@ require_text .github/workflows/release.yml "packages_checksums.txt"
|
||||
require_text .github/workflows/docker-release.yml "Attest multi-architecture image provenance"
|
||||
require_text .github/workflows/docker-release.yml "index.docker.io/pgsty/silo"
|
||||
|
||||
# Copyright notices credit both parties with fixed terms: upstream MinIO
|
||||
# development ends at its own last year, and the fork's own term starts when
|
||||
# the fork did. Deriving the upstream end year from the clock would extend
|
||||
# MinIO's copyright term every January.
|
||||
require_text cmd/build-constants.go 'upstreamCopyrightEndYear = "2025"'
|
||||
require_text cmd/build-constants.go 'forkCopyrightStartYear = "2025"'
|
||||
require_text cmd/main.go 'upstreamCopyrightEndYear'
|
||||
reject_text cmd/main.go 'CopyrightYear = strconv.Itoa(time.Now().Year())'
|
||||
|
||||
# Contribution policy: no CLA, inbound=outbound, DCO sign-off enforced in CI.
|
||||
require_file .github/workflows/dco.yml
|
||||
require_text .github/workflows/dco.yml "Signed-off-by"
|
||||
require_text CONTRIBUTING.md "developercertificate.org"
|
||||
require_text CONTRIBUTING.md "No CLA"
|
||||
|
||||
for file in .github/nfpm.yml Dockerfile.goreleaser silo.service; do
|
||||
reject_text "${file}" "/usr/bin/minio"
|
||||
reject_text "${file}" "/usr/local/bin/minio"
|
||||
|
||||
Reference in New Issue
Block a user