|
| 1 | +// SPDX-License-Identifier: CC-BY-SA-4.0 |
| 2 | +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk> |
| 3 | += Licence Flags — Estate Audit & Optimization (2026-07) |
| 4 | +:icons: font |
| 5 | + |
| 6 | +[.lead] |
| 7 | +Flag-only record for the estate audit-and-optimization program (umbrella |
| 8 | +`hyperpolymath/standards#460`). Per the Manual-Only licence policy |
| 9 | +(`.claude/CLAUDE.md`), this program made **no** licence/SPDX edits and generated |
| 10 | +**no** automated licence-change PRs. This document records that discipline and |
| 11 | +flags — for owner review only — anything licence-adjacent that surfaced. |
| 12 | + |
| 13 | +== Discipline upheld |
| 14 | + |
| 15 | +* No SPDX headers were added, changed, or swept in any wave (0, 1, 3, 4, 5, 6). |
| 16 | +* New files created by the program carry the SPDX identifier matching the |
| 17 | + repo's classification at birth (authoring, not relicensing): scripts → |
| 18 | + `MPL-2.0`, prose/specs → `CC-BY-SA-4.0`. This is consistent with the estate |
| 19 | + policy that new files may carry the correct SPDX from birth. |
| 20 | +* The DYADT verifier (`did-you-actually-do-that/`) treats any licence/SPDX claim |
| 21 | + as `manual-only` end to end — it returns `unverifiable`, never auto-`confirmed`, |
| 22 | + and the consequence ledger's confirmation rate is explicitly unaffected by |
| 23 | + licence verdicts. The Manual-Only policy is preserved *by construction* in the |
| 24 | + new tooling. |
| 25 | + |
| 26 | +== Flags for owner review (no action taken) |
| 27 | + |
| 28 | +None of the following were edited; they are surfaced for the owner to rule on. |
| 29 | + |
| 30 | +[cols="1,3", options="header"] |
| 31 | +|=== |
| 32 | +| Location | Observation (flag-only) |
| 33 | + |
| 34 | +| `rhodium-standard-repositories/rsr-audit.sh` |
| 35 | +| Header carries a dual `SPDX-License-Identifier: MPL-2.0 AND Palimpsest-0.8`. |
| 36 | + Palimpsest is a carve-out family; whether this file should carry a |
| 37 | + Palimpsest component is an owner ruling, not an audit action. Left untouched. |
| 38 | + |
| 39 | +| `SECURITY-ADVISORIES.adoc` |
| 40 | +| A standing deferred `rand < 0.9.3` advisory is recorded. Not a licence matter, |
| 41 | + but flagged alongside release hygiene: renew with an expiry date or bump. |
| 42 | + (Tracked under the umbrella's release-hygiene item.) |
| 43 | +|=== |
| 44 | + |
| 45 | +== No sweep, no auto-PR |
| 46 | + |
| 47 | +This program did not run, and must not be read as licensing, any bulk SPDX |
| 48 | +normalisation. Licence drift findings remain FLAG-ONLY and owner-gated, per the |
| 49 | +neurophone#99 precedent and the estate licence-policy umbrella. |
0 commit comments