www-legal-discuss mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Ralph Goers (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (LEGAL-333) Maven Central Repository terms are incompatible with the Apache License
Date Mon, 25 Sep 2017 15:01:08 GMT

    [ https://issues.apache.org/jira/browse/LEGAL-333?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16179143#comment-16179143

Ralph Goers commented on LEGAL-333:

I am sorry you feel our goal is to close this issue. Our goal is generally to resolve issues.

The problem with this issue as you have stated it is that you are trying to tie the Apache
license to Sonatype's agreement.  The Apache license applies to consumers of the Apache licensed
work. You yourself have admitted that they are not affected by Sonatype's terms. That means
that what is left is a question as to whether the ASF is OK with Sonatype's terms. That is
more of a policy discussion than a legal one.

I don't want to go into the details of your proposal on how to change how Maven works as this
isn't the appropriate forum. If you wish to discuss that you should bring it up on the Maven
dev list.

As to Sean's third bullet, all ASF projects do publish to an ASF hosted Maven repository.
The ASF repo then forwards the released artifacts to Maven Central.  And FWIW, Maven does
not actually point to Maven Central. It refers to a DNS entry maintained by the ASF.

> Maven Central Repository terms are incompatible with the Apache License
> -----------------------------------------------------------------------
>                 Key: LEGAL-333
>                 URL: https://issues.apache.org/jira/browse/LEGAL-333
>             Project: Legal Discuss
>          Issue Type: Question
>            Reporter: Carte Project
>            Assignee: Chris A. Mattmann
> All or nearly all of the ASF's Java software projects are distributed through the Maven
Central Repository operated by Sonatype, Inc. Their "full terms of service" (as they are described
in [this page|http://central.sonatype.org/pages/ossrh-guide.html]) can be found here:
> [http://central.sonatype.org/pages/central-repository-producer-terms.html]
> The "Indemnity for Submissions" clause states:
> bq. You agree to indemnify and hold harmless Sonatype and its affiliates, suppliers,
partners, officers, agents, and employees from and against any claim, demand, losses, damages
or expenses (including reasonable attorney's fees) arising from your Submissions.
> To me, the obligation to indemnify against any claim "arising from your Submissions"
sounds somewhat incompatible with the 8 and 9 clauses of the [Apache License 2.0|http://www.apache.org/licenses/LICENSE-2.0].
And my understanding is that all of the ASF's Maven artifacts are nearly-automatically deployed
on that repository.
> Am I missing something?  Any comments?

This message was sent by Atlassian JIRA

To unsubscribe, e-mail: legal-discuss-unsubscribe@apache.org
For additional commands, e-mail: legal-discuss-help@apache.org

View raw message