-
Notifications
You must be signed in to change notification settings - Fork 96
supermassive-todomvc 1.0.1-0 #28748
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
supermassive-todomvc 1.0.1-0 #28748
Conversation
You can review the change introduced to the full definition at ClearlyDefined. |
If I'm reading this correctly, then it looks like this package shouldn't have been published publicly: microsoft/graphitation#154 I found this repo through the other packages, not this one. All of the other packages in the |
@capfei - well, if we go with what license information was provided in/for the package at the time it was (mistakenly) published, it would be "NONE," so I would recommend going with that. |
@capfei, @ariel11 I've added MIT as a license here because we got a Security Alert in our Pipeline Component Governance. I'll post below de description in case you don't have access to that:
If MIT is not the proper license, please help us figure out which one is as MIT is the only one I could find inside the package. |
@LSDima - this is a public open source project. Please contact your internal support if you have license or security questions. As for the curation of this component, ClearlyDefined simply reports the license info provided with/in the package. Where did you find MIT inside this package? |
Very sorry, I've meant the repo, not the package: https://github.com/microsoft/graphitation/blob/main/LICENSE. |
Hi! I'm the maintainer of the repository. The whole repository is licensed as MIT, therefore examples are MIT too, even if they are not published. |
@freiksenet - OK, great - with your confirmation that you meant for the [published NPM package] (https://www.npmjs.com/package/supermassive-todomvc/v/1.0.1-0) to also be MIT licensed (as the published package has no license information at all or a link back to the project repo), we can add "MIT" for the package to this public license repository (ClearlyDefined). @capfei - FYI on the license confirmation from the project maintainer. Thanks! |
Type: Missing
Summary:
supermassive-todomvc 1.0.1-0
Details:
Add MIT License
Resolution:
License Url:
https://github.com/microsoft/graphitation/blob/main/LICENSE
Description:
Pull request generated by Microsoft tooling.
Affected definitions: