Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .github/workflows/license.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
name: license

on: [push, pull_request]

jobs:
license:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: License posture (canonical EUPL-1.2 + SPDX headers)
run: bash scripts/license_check.sh
371 changes: 261 additions & 110 deletions LICENSE

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions hub_main.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# SPDX-License-Identifier: EUPL-1.2
# Copyright (c) 2026 AgStack project contributors.
# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text.

# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at https://mozilla.org/MPL/2.0/.
Expand Down
31 changes: 31 additions & 0 deletions scripts/license_check.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
#!/usr/bin/env bash
# Fail if the license posture regresses.
#
# Two invariants, both mechanical:
# 1. LICENSE is the canonical EUPL-1.2 English text, byte for byte.
# (Its predecessor here was a silently truncated license file that GitHub
# reported as NOASSERTION -- a hash comparison cannot fail that quietly.)
# 2. Every git-tracked Python file carries the SPDX EUPL-1.2 header.
set -euo pipefail

# sha256 of https://joinup.ec.europa.eu/sites/default/files/custom-page/attachment/2020-03/EUPL-1.2%20EN.txt
# computed 2026-08-26 (287 lines).
want="6fc9e709ccbfe0d77fbffa2427a983282be2eb88e47b1cdb49f21a83b4d1e665"
got=$(shasum -a 256 LICENSE | cut -d' ' -f1)
if [ "$got" != "$want" ]; then
echo "FAIL: LICENSE is not the canonical EUPL-1.2 text (sha256 $got)"
exit 1
fi

fail=0
while IFS= read -r f; do
if ! head -5 "$f" | grep -q "SPDX-License-Identifier: EUPL-1.2"; then
echo "FAIL: missing SPDX EUPL-1.2 header: $f"
fail=1
fi
done < <(git ls-files '*.py')

if [ "$fail" -eq 0 ]; then
echo "license posture OK: canonical EUPL-1.2 + headers on all tracked .py files"
fi
exit "$fail"
4 changes: 4 additions & 0 deletions user_database.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# SPDX-License-Identifier: EUPL-1.2
# Copyright (c) 2026 AgStack project contributors.
# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text.

# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at https://mozilla.org/MPL/2.0/.
Expand Down
4 changes: 4 additions & 0 deletions user_models.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# SPDX-License-Identifier: EUPL-1.2
# Copyright (c) 2026 AgStack project contributors.
# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text.

# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at https://mozilla.org/MPL/2.0/.
Expand Down
4 changes: 4 additions & 0 deletions user_schemas.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# SPDX-License-Identifier: EUPL-1.2
# Copyright (c) 2026 AgStack project contributors.
# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text.

# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at https://mozilla.org/MPL/2.0/.
Expand Down
4 changes: 4 additions & 0 deletions verify_jwt.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
# SPDX-License-Identifier: EUPL-1.2
# Copyright (c) 2026 AgStack project contributors.
# Licensed under the EUPL, Version 1.2; see the LICENSE file for the full text.

import sys
import jwt

Expand Down
Loading