From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mike Gerwitz Subject: Re: npm (mitigation) Date: Fri, 14 Jul 2017 23:34:51 -0400 Message-ID: <871spi5q5g.fsf@gnu.org> References: Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:57847) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dWDrM-0005Id-QC for guix-devel@gnu.org; Fri, 14 Jul 2017 23:35:13 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dWDrL-0005M7-QE for guix-devel@gnu.org; Fri, 14 Jul 2017 23:35:12 -0400 In-Reply-To: (Jelle Licht's message of "Fri, 14 Jul 2017 13:57:30 +0200") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Jelle Licht Cc: guix-devel --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Fri, Jul 14, 2017 at 13:57:30 +0200, Jelle Licht wrote: > Regardless, the biggest issue that remains is still that npm-land is mired > in cyclical dependencies and a fun-but-not-actually unique dependency > resolving scheme. I still think the largest issue is trying to determine if a given package and its entire [cyclic cluster] subgraph is Free. That's a lot of manual verification to be had (to verify any automated checks). npm's package.json does include a `license' field, but that is metadata with no legal significance, and afaik _defaults_ to "MIT" (implying Expat), even if there's actually no license information in the repository. =2D-=20 Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: D6E9 B930 028A 6C38 F43B 2388 FEF6 3574 5E6F 6D05 https://mikegerwitz.com --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJZaY1bAAoJEIyRe39dxRuiWxQP+wafWOkbUKt7OjTqQKKDYe36 4D+bMfYAg0HI5xJH+OPmBQAOq74Kh0P+eYH18rIrZsXtqs0sy0R+sKyU6chjaftq dBX2ySCYLJZPKIUvmYYcBSZsBXQY1erO+I/8+1oR+mwtjigtm6T8QMdtGUOI1tu7 cEd5hZ5mm2qw47IsEp1d2+ZcHIpTmw4nRjsA36pAnBnNTWFzHGHKUZAJC5EHM5s/ OWDqdyJpl/CNbKGsodlF5etSA6dVBP8IAW7ituG8JLTrmptS6bR/f+4DlYo2twjE g9ASaHwAl7y7rSsThQzrNK6HacLQzhlU9SCLPmDgYFXzRDsz2MQGciD+/wq2irVO VcknISH7GGUz2AFJ2ErrttNrJ7iCgE098V7zkFygVCCpdACpaatUWSiyC1hc5VLc O5FmA4wJJsBPsi0rZvxUqiosHCI8vUatAw/SNvQsAfxk8Y+POApjI/+FmqfoBrOX RS8kufCWbk1eMcu5+e1eVUytIsSVzgNXBcjILx/OY8z1v1nrqEJEicLVOkD4iY4S Tx8TV5pWb58TSGCSD4208PHzgHbVLb0u6qELWi+XMSw8VHO2bfjCJqD5UMVrilvz 11AyDhjHkiC0rw+IN+MzRc21DcuSekqVcnCu3+ydmD7+3BcjJ5C1a6BY0pkgcVkB 7F8zxgMI9aEswYSPXVIs =l1cO -----END PGP SIGNATURE----- --=-=-=--