www-legal-discuss mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Carte Project (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (LEGAL-333) Maven Central Repository terms are incompatible with the Apache License
Date Mon, 02 Oct 2017 16:00:00 GMT

    [ https://issues.apache.org/jira/browse/LEGAL-333?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16188352#comment-16188352

Carte Project commented on LEGAL-333:

bq. Any redistribution site is going to have terms like that - they'd be idjits not to.

I disagree. One thing is saying "I'm not liable for your stuff", another is "if your stuff
is involved with any claim or expense, you are going to pay what I request from you, no matter
what the circumstances about the claim/expense are", and the latter is more or less what the
Sonatype clause says.

bq. if a complaint comes to them [Carte] regarding Codec, they feel the complaint should go
to Apache and not be something they have to handle

If somebody sues me because of Codec I am not going to pass you the legal bill, because you
are not to blame for the user being a moron and suing the wrong people. In that case, it is
somewhat obvious who should be paying the costs and it is not the ASF. And yes, dealing with
the possibility of someone suing me because of Codec (or anything else) is something that
I'd have to handle (in the direction that I mentioned), if that ever happened.

bq. Sonatype can point a complaint back to us, and we point to the software license's note
of limited liability.

I doubt that Sonatype would be happy at this interpretation of their terms of use (and it
is not the ASF opinion according to certain comment above).

Please note that all of the above are just opinions and not legal advice.

> Maven Central Repository terms are incompatible with the Apache License
> -----------------------------------------------------------------------
>                 Key: LEGAL-333
>                 URL: https://issues.apache.org/jira/browse/LEGAL-333
>             Project: Legal Discuss
>          Issue Type: Question
>            Reporter: Carte Project
>            Assignee: Chris A. Mattmann
> All or nearly all of the ASF's Java software projects are distributed through the Maven
Central Repository operated by Sonatype, Inc. Their "full terms of service" (as they are described
in [this page|http://central.sonatype.org/pages/ossrh-guide.html]) can be found here:
> [http://central.sonatype.org/pages/central-repository-producer-terms.html]
> The "Indemnity for Submissions" clause states:
> bq. You agree to indemnify and hold harmless Sonatype and its affiliates, suppliers,
partners, officers, agents, and employees from and against any claim, demand, losses, damages
or expenses (including reasonable attorney's fees) arising from your Submissions.
> To me, the obligation to indemnify against any claim "arising from your Submissions"
sounds somewhat incompatible with the 8 and 9 clauses of the [Apache License 2.0|http://www.apache.org/licenses/LICENSE-2.0].
And my understanding is that all of the ASF's Maven artifacts are nearly-automatically deployed
on that repository.
> Am I missing something?  Any comments?

This message was sent by Atlassian JIRA

To unsubscribe, e-mail: legal-discuss-unsubscribe@apache.org
For additional commands, e-mail: legal-discuss-help@apache.org

View raw message