Skip to content

chore: add dual license (Apache-2.0 code + CC-BY-4.0 docs) - #202

Merged
kambleakash0 merged 1 commit into
mainfrom
chore/add-license
Sep 9, 2026
Merged

kambleakash0 merged 1 commit into
mainfrom
chore/add-license

Conversation

@kambleakash0

@kambleakash0 kambleakash0 commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

User description

What

Adds the license the pre-publication audit flagged as missing (a public repo with no LICENSE defaults to all-rights-reserved, which conflicts with the open-for-contributors intent).

  • LICENSE — Apache-2.0, covering code + configuration (matches the Mistral-7B base and Granite Guardian, both Apache-2.0).
  • LICENSE-docs — CC-BY-4.0, covering the prose deliverables (docs/, and the narrative write-ups under reports/ including reports/safestack_report.md).
  • README — a License section documenting the split.

Third-party datasets/models keep their own upstream licenses (see RESPONSIBLE_USE.md and the manifests).

Pre-publication audit (context)

A 5-dimension audit ran before this: sanitized data (all harmful sources hash-only), notebook outputs (no harmful generations, no secrets), secrets across the full 116-commit history (clean), private-artifact/weight leakage (none ever committed), and responsible-use docs (coherent). All 18 private HF adapter repos confirmed gated (401 unauthenticated). This LICENSE was the only remaining gap.

Closes #201


PR Type

Other, Documentation


Description

  • Add Apache-2.0 licensing for code and configuration.

  • License prose deliverables under CC-BY-4.0.

  • Document licensing boundaries and upstream license exceptions.


File Walkthrough

Relevant files
Licensing
LICENSE
Add Apache-2.0 license for code and configuration               

LICENSE

  • Add the Apache License 2.0 text, including copyright and patent
    grants, redistribution conditions, and liability disclaimers.
  • Include a copyright notice for Akash Kamble dated 2026.
+201/-0 
LICENSE-docs
Define prose licensing scope and third-party exceptions   

LICENSE-docs

  • Add a CC-BY-4.0 notice covering docs/ and narrative write-ups under
    reports/.
  • Explicitly retain Apache-2.0 coverage for code, configuration,
    notebooks, and machine-readable report artifacts.
  • Summarize attribution requirements and link to the full legal text and
    human-readable license summary.
  • Clarify that third-party materials retain upstream licenses,
    referencing RESPONSIBLE_USE.md and dataset manifests.
+32/-0   
Documentation
README.md
Document license split and upstream licensing references 

README.md

  • Add a License section linking to LICENSE and LICENSE-docs.
  • Explain the split between Apache-2.0 code/configuration and CC-BY-4.0
    prose deliverables.
  • Note upstream licensing for third-party datasets, models, and tools.
+9/-0     

…lic release

- LICENSE: Apache-2.0, covering code and configuration (safestack/, tests/,
  configs/, notebooks/, machine-readable metrics artifacts).
- LICENSE-docs: CC-BY-4.0, covering the prose deliverables (docs/ and the
  narrative write-ups under reports/, including reports/safestack_report.md).
- README: add a License section documenting the split.

Prerequisite for making the repo public (open-for-contributors needs an
explicit grant). Third-party datasets/models keep their upstream licenses.

Closes #201
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🎫 Ticket compliance analysis ✅

201 - PR Code Verified

Compliant requirements:

  • Add Apache-2.0 licensing for repository code.
  • Add CC-BY-4.0 licensing for prose deliverables in docs/ and reports/.
  • Add a README License section documenting the licensing split.

Requires further human verification:

  • Confirm these licensing changes are merged before the repository is made public.
⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected

@kambleakash0
kambleakash0 merged commit 3644cbc into main Sep 9, 2026
3 checks passed
@kambleakash0
kambleakash0 deleted the chore/add-license branch September 9, 2026 01:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add LICENSE (Apache-2.0 code + CC-BY-4.0 docs) before public release

1 participant