Blackduck Software and IP

Paul Lussier p.lussier at comcast.net
Fri Jan 16 14:44:37 EST 2009


Bill McGonigle <bill at bfccomputing.com> writes:

> Are they fixing the debs too?

I don't know.  They may be submitting bug reports against them, but to
my knowledge, they're not.  One of the difficulties they help solve is
the derivative-works licenseing issue.

For example, if I release something under the GPL, but I depend upon
libs released under the BSD, Apache, and some
share-ware-send-me-a-postcard-or-pizza license, which one is *really*
in effect, legally speaking.  Of course the answer to that is, it depends.

They, I believe, can assist with that problem, in the sense that they
have audited the packages and know which licenses affect things.
Sadly, it's not a case of simply saying, "Oh, this package is under
the GPL.".  If you're redistributing that package and it's
dependancies, you need to know what licenses all of those packages are
under.  It can get very, very messy.

So, no, I doubt they're fixing the problem.  It's too widespread and
convoluted, and "not their job".  But that's purely speculation on my
part.  I don't know for a fact whether or not they are.

-- 
Seeya,
Paul


More information about the gnhlug-discuss mailing list