cip-dev.lists.cip-project.org archive mirror
 help / color / mirror / Atom feed
* [cip-dev] [cip core] license compliance for CIP core image releases
@ 2020-07-27  4:59 Daniel Sangorrin
  0 siblings, 0 replies; only message in thread
From: Daniel Sangorrin @ 2020-07-27  4:59 UTC (permalink / raw)
  To: cip-dev

[-- Attachment #1: Type: text/plain, Size: 1366 bytes --]

Hello,

During the last CIP Core meeting we discussed about license compliance for CIP core image releases.
In particular, we talked about how to make sure that users can get exactly the same source code version used to build the Debian binary packages included on each image.

We concluded that we should not rely on Debian repositories, but rather create our own apt mirror with snapshots for each release.

However, today I asked myself: when people upload a Docker image to Dockerhub, what do they do to comply with the licenses of all of the packages inside.

I thought that Microsoft would be one of the most cautious and checked their Docker images.

https://hub.docker.com/_/microsoft-dotnet-core (click "Discover licensing for Linux image contents") 

If you read their document, it looks like the rely on the Debian source code packages to be always available either in the Debian repo or the Snapshots repository.

[Note] additionally they rely on the license and copyright information provided by Debian to be correct (they do not verify it manually)

I would like to know your opinions about this. Do you think it is worth the effort to build, pay and maintain a repository mirror with snapshots? or can we rely on Debian snapshot repositories (for users to retrieve source code, not for building the image)?

Thanks,
Daniel
 



[-- Attachment #2: Type: text/plain, Size: 419 bytes --]

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.

View/Reply Online (#5017): https://lists.cip-project.org/g/cip-dev/message/5017
Mute This Topic: https://lists.cip-project.org/mt/75816703/4520388
Group Owner: cip-dev+owner@lists.cip-project.org
Unsubscribe: https://lists.cip-project.org/g/cip-dev/leave/8129055/727948398/xyzzy  [cip-dev@archiver.kernel.org]
-=-=-=-=-=-=-=-=-=-=-=-

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2020-07-27  4:59 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-07-27  4:59 [cip-dev] [cip core] license compliance for CIP core image releases Daniel Sangorrin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).