Перейти до вмісту

Licence

The project is licensed under the GNU Affero General Public License v3.0 only (AGPL-3.0-only) — see LICENSE and the decision at the end of this page.

Until 2026-09-26 the repository had no licence ("license": "UNLICENSED", no LICENSE file), which legally meant “all rights reserved”. The comparison below is the neutral one the owner decided from; it compares the three candidates discussed in the CMS roadmap and is kept for the record. It is not legal advice.

  • The code is a web application run as a service: a school installs it on its own server, and visitors and staff use it over the network. Nobody receives a copy of the program by using the site.
  • Schools install it themselves, for free. A hosting company could also offer “school website as a service” built on it — with or without contributing back.
  • Schools are the main users; most will run it unmodified. A few (a computer-science teacher, a hired developer) may change it.
MIT Apache-2.0 AGPL-3.0
Kind Permissive Permissive Strong copyleft, including network use
A school may install, use and modify it Yes Yes Yes
What it asks of a school running it unmodified Nothing beyond keeping the notice in the code Nothing beyond keeping the notices Nothing extra
What it asks of a school running a modified version Nothing Nothing (changed files must say they were changed if redistributed) Offer the complete modified source to everyone who uses the site over the network (section 13)
A hosting company may sell hosted sites built on it Yes Yes Yes
…and keep its own modifications closed Yes Yes No — users of the hosted service are entitled to the modified source
…and ship it inside a proprietary product Yes Yes Only if the whole combined work is offered under AGPL-3.0
Explicit patent grant from contributors No Yes, with termination on patent suits Yes (GPLv3 terms)
Attribution / notice files Keep copyright + licence text Keep licence, copyright and any NOTICE file Keep licence and copyright notices
Length and familiarity ~170 words, universally understood Long, well known in companies Long; some organisations have policies against using AGPL software

In short: MIT and Apache-2.0 let anyone, a hosting company included, take the code in any direction, closed or open. AGPL-3.0 lets anyone use and host it too, but whoever runs a modified version for others must publish those modifications — which keeps improvements flowing back and also makes the code less attractive to companies that want a closed fork.

Licences of the production packages in package-lock.json, counted from each package’s license field (npx license-checker needs a download, so the lock file was read instead). The lock file lists the optional prebuilt binaries of every platform; a server installs only its own:

Licence of dependency Production packages Examples
MIT 159 express, argon2, better-sqlite3, helmet, marked, multer, pino
Apache-2.0 40 ejs, sharp, @aws-sdk/client-s3 and its modules
ISC 13
BSD-2-Clause / BSD-3-Clause 5 / 3 dotenv (BSD-2-Clause)
BlueOak-1.0.0 4 tar
MIT-0, 0BSD, dual MIT/WTFPL, triple BSD/MIT/Apache 4 nodemailer (MIT-0)
LGPL-3.0-or-later (alone or combined) 14 @img/sharp-libvips-* — the prebuilt libvips binaries behind sharp
  • Permissive dependencies (MIT, ISC, BSD, BlueOak, MIT-0, 0BSD, Apache-2.0) can be used by a project under any of the three candidates. Apache-2.0 code is compatible with AGPL-3.0 (the GPLv3 family accepts it) and with MIT-licensed projects (each part keeps its own licence).
  • libvips (LGPL-3.0-or-later) is a separate shared library loaded by sharp, not code we modify. Our own licence choice does not change; but whoever distributes it — the Docker image on GHCR does — must keep its licence text and allow it to be replaced. The prebuilt packages include their licence files; worth checking they survive in the published image.
  • The Docker base image (node:20-slim, Debian) brings its own mix of licences; that is normal for any image and does not constrain the application’s licence.
  • The font public/fonts/Commissioner-Variable.woff2 is redistributed with the code under the SIL Open Font License 1.1; its licence text is next to it, public/fonts/OFL-Commissioner.txt (the file published with Commissioner in google/fonts), and ships in the image with public/.
  • docs/design/ and docs/audits/ are content, not code, and are left out of the public repository (public-snapshot.md).

The same check was repeated on the packages actually installed for production (npm ls --omit=dev --all, 214 packages on the machine that wrote this page), reading the license field of each package.json under node_modules. Everything is MIT, ISC, BSD-2-Clause, BSD-3-Clause or Apache-2.0 except:

Package Licence Compatible with AGPL-3.0-only
nodemailer MIT-0 Yes (permissive, no attribution required)
tar, chownr, minipass, yallist BlueOak-1.0.0 Yes (permissive)
tslib 0BSD Yes (permissive)
expand-template MIT OR WTFPL Yes (used under MIT)
rc BSD-2-Clause OR MIT OR Apache-2.0 Yes (any of the three)
@img/sharp-<platform> and @img/sharp-libvips-<platform> Apache-2.0 AND LGPL-3.0-or-later / LGPL-3.0-or-later Yes — LGPL-3.0 libraries may be used by GPLv3-family works; the distribution note on libvips above applies

No dependency is under a licence that conflicts with AGPL-3.0-only (no GPL-2.0-only, no SSPL, no “non-commercial” or proprietary terms).

AGPL-3.0-only, chosen by the owner on 2026-09-26. The reasons:

  • Free for schools without conditions. A school or any educational institution may install, use, change and host the site at no cost. Running it unmodified asks nothing of them; the obligations start only when someone modifies it and offers it to others.
  • Closed SaaS forks must share their changes. A company that builds a hosted “school website” service on a modified version has to publish those modifications to its users (section 13), so improvements come back to every school instead of disappearing into a closed product.
  • OSI-approved. An approved open-source licence lets the project join open-source catalogues and apply to grant programmes that require one.
  • The owner keeps the copyright and may still license the code separately to anyone under other terms.

-only rather than -or-later: a future AGPL version will not apply automatically; moving to one would be a new decision.

What was done: LICENSE at the root holds the licence text, package.json (and the root entry of package-lock.json) say "license": "AGPL-3.0-only", README has a «Ліцензія» section. No SPDX headers in source files — the owner does not want them; the root LICENSE and the package.json field are the licence statement.

Still open:

  • The LICENSE text was written without network access and must be diffed against https://www.gnu.org/licenses/agpl-3.0.txt before publishing (see publishing-checklist.md).
  • How a running site offers its source to users (section 13 is about modified versions, but a visible link — for example on the admin «Що нового» page or in the site footer, pointing at the release’s source — keeps every installation compliant by default). Not implemented yet.