hello my project has quite a lot of dependencies. about 500 of them. I looked for a few
posts but they old. I was wondering if I'm publishing both the source code and the binary.
do i still need to have to bundle all of their licenses(I know licenses vary from one another. I'm mostly talking about mit, apache and similar permisive licenses). if i have to bundle them. do i have to contain a full copy or is an spdx identifier or a link to the project enough.
the project will be AGPLv3 licensed but i doubt its affect on bundling licenses. I'm still mentioning it just in case.
I provide licenses to all OSS I use in my projects. It's easy, and you can ask AI for a full list to save time. However, you may ignore that and more likely nothing will happen, unless your company filed for IPO.
thanks but I would rather not use ai.
IANAL, but I have worked with lawyers on open source license compliance in the past.
For most licenses, the "include the license text" clause is about distribution of the licensed code. So when you're providing only your source, with an expectation that users download dependencies themselves (by hand or via Cargo), there is no need to include attribution.
As soon as you ship binaries (or vendor the source, but vendoring usually pulls in licenses anyway), the license clauses start to fire. That means you need to include proper attribution for all of your dependencies as specified in their licenses. You'll likely have to include full license text for some dependencies, but it's common practice to deduplicate those licenses (IE, including only one copy of the GPL, one of Apache, and one of MIT, then specifying which dependencies use which license files)
There are tools (such as cargo-bundle-licenses and cargo-about) that can help generate the appropriate attribution for you based on your Cargo.toml
thanks. I was exactly wondering about the binary release. as I'm pretty sure the average user either doesn't know what compiling is or they don't want to bother.
You might be interested in https://rosenlaw.com/oslbook.htm: it's getting older, but is freely available and should still be a good introduction to copyright and licenses.
In general, shipping your source code on its own has very different requirements from shipping the aggregate compiled binary.