Open guillemsola opened 1 year ago
hi @guillemsola I'd be happy to switch to a more permissive licence, the original choice was mostly for quick, non-legal requirements. I need to figure out if/how I can just replace the licence (maybe it's sufficient to switch the LICENCE file, but I am afraid it may not be that simple as it has been GPL2 for a while), I will keep this open as a reminder, but I can't promise it won't take a while. I do not mind people redistributing my library as part of permanently closed source software (assuming they recognise the author of the library as mandated by most open licences), but I appreciate you may need more legal assurance than me saying "I'm OK with that" :)
@UnoSD thanks for considering this.
To give you some more context, I decided to share this as I'm using Snyk to check vulnerabilities and this message caught my attention
License issues:
✗ GPL-2.0 license (new) [High Severity][https://snyk.io/vuln/snyk:lic:nuget:moq.dapper:GPL-2.0] in Moq.Dapper@1.0.4
introduced by Moq.Dapper@1.0.4
I do agree that changing the license type may not be that straightforward as I believe all contributors need to ack it.
We've got the same issue; our security team won't allow a GPL 2.0 license. If the license isn't resolved, we'll have to use an alternative approach.
Please, consider using an alternate license that better more aligned with the Dapper project
As a result of using this license anyone using this library must be publishing the software too, so this limits usage in many environments or force people to do something illegal