Licence
The project is licensed under the GNU Affero General Public License v3.0 only
(AGPL-3.0-only) — see LICENSE and the decision at the end of
this page.
Until 2026-09-26 the repository had no licence ("license": "UNLICENSED", no LICENSE file),
which legally meant “all rights reserved”. The comparison below is the neutral one the owner
decided from; it compares the three candidates discussed in the CMS roadmap and is kept for the
record. It is not legal advice.
The situation the licence has to fit
Section titled “The situation the licence has to fit”- The code is a web application run as a service: a school installs it on its own server, and visitors and staff use it over the network. Nobody receives a copy of the program by using the site.
- Schools install it themselves, for free. A hosting company could also offer “school website as a service” built on it — with or without contributing back.
- Schools are the main users; most will run it unmodified. A few (a computer-science teacher, a hired developer) may change it.
Comparison
Section titled “Comparison”| MIT | Apache-2.0 | AGPL-3.0 | |
|---|---|---|---|
| Kind | Permissive | Permissive | Strong copyleft, including network use |
| A school may install, use and modify it | Yes | Yes | Yes |
| What it asks of a school running it unmodified | Nothing beyond keeping the notice in the code | Nothing beyond keeping the notices | Nothing extra |
| What it asks of a school running a modified version | Nothing | Nothing (changed files must say they were changed if redistributed) | Offer the complete modified source to everyone who uses the site over the network (section 13) |
| A hosting company may sell hosted sites built on it | Yes | Yes | Yes |
| …and keep its own modifications closed | Yes | Yes | No — users of the hosted service are entitled to the modified source |
| …and ship it inside a proprietary product | Yes | Yes | Only if the whole combined work is offered under AGPL-3.0 |
| Explicit patent grant from contributors | No | Yes, with termination on patent suits | Yes (GPLv3 terms) |
| Attribution / notice files | Keep copyright + licence text | Keep licence, copyright and any NOTICE file |
Keep licence and copyright notices |
| Length and familiarity | ~170 words, universally understood | Long, well known in companies | Long; some organisations have policies against using AGPL software |
In short: MIT and Apache-2.0 let anyone, a hosting company included, take the code in any direction, closed or open. AGPL-3.0 lets anyone use and host it too, but whoever runs a modified version for others must publish those modifications — which keeps improvements flowing back and also makes the code less attractive to companies that want a closed fork.
Compatibility with the dependencies
Section titled “Compatibility with the dependencies”Licences of the production packages in package-lock.json, counted from each package’s
license field (npx license-checker needs a download, so the lock file was read instead). The
lock file lists the optional prebuilt binaries of every platform; a server installs only its own:
| Licence of dependency | Production packages | Examples |
|---|---|---|
| MIT | 159 | express, argon2, better-sqlite3, helmet, marked, multer, pino |
| Apache-2.0 | 40 | ejs, sharp, @aws-sdk/client-s3 and its modules |
| ISC | 13 | |
| BSD-2-Clause / BSD-3-Clause | 5 / 3 | dotenv (BSD-2-Clause) |
| BlueOak-1.0.0 | 4 | tar |
| MIT-0, 0BSD, dual MIT/WTFPL, triple BSD/MIT/Apache | 4 | nodemailer (MIT-0) |
| LGPL-3.0-or-later (alone or combined) | 14 | @img/sharp-libvips-* — the prebuilt libvips binaries behind sharp |
- Permissive dependencies (MIT, ISC, BSD, BlueOak, MIT-0, 0BSD, Apache-2.0) can be used by a project under any of the three candidates. Apache-2.0 code is compatible with AGPL-3.0 (the GPLv3 family accepts it) and with MIT-licensed projects (each part keeps its own licence).
- libvips (LGPL-3.0-or-later) is a separate shared library loaded by
sharp, not code we modify. Our own licence choice does not change; but whoever distributes it — the Docker image on GHCR does — must keep its licence text and allow it to be replaced. The prebuilt packages include their licence files; worth checking they survive in the published image. - The Docker base image (
node:20-slim, Debian) brings its own mix of licences; that is normal for any image and does not constrain the application’s licence. - The font
public/fonts/Commissioner-Variable.woff2is redistributed with the code under the SIL Open Font License 1.1; its licence text is next to it,public/fonts/OFL-Commissioner.txt(the file published with Commissioner in google/fonts), and ships in the image withpublic/. docs/design/anddocs/audits/are content, not code, and are left out of the public repository (public-snapshot.md).
Checked against the installed packages
Section titled “Checked against the installed packages”The same check was repeated on the packages actually installed for production
(npm ls --omit=dev --all, 214 packages on the machine that wrote this page), reading the
license field of each package.json under node_modules. Everything is MIT, ISC,
BSD-2-Clause, BSD-3-Clause or Apache-2.0 except:
| Package | Licence | Compatible with AGPL-3.0-only |
|---|---|---|
nodemailer |
MIT-0 | Yes (permissive, no attribution required) |
tar, chownr, minipass, yallist |
BlueOak-1.0.0 | Yes (permissive) |
tslib |
0BSD | Yes (permissive) |
expand-template |
MIT OR WTFPL | Yes (used under MIT) |
rc |
BSD-2-Clause OR MIT OR Apache-2.0 | Yes (any of the three) |
@img/sharp-<platform> and @img/sharp-libvips-<platform> |
Apache-2.0 AND LGPL-3.0-or-later / LGPL-3.0-or-later | Yes — LGPL-3.0 libraries may be used by GPLv3-family works; the distribution note on libvips above applies |
No dependency is under a licence that conflicts with AGPL-3.0-only (no GPL-2.0-only, no SSPL, no “non-commercial” or proprietary terms).
Decision
Section titled “Decision”AGPL-3.0-only, chosen by the owner on 2026-09-26. The reasons:
- Free for schools without conditions. A school or any educational institution may install, use, change and host the site at no cost. Running it unmodified asks nothing of them; the obligations start only when someone modifies it and offers it to others.
- Closed SaaS forks must share their changes. A company that builds a hosted “school website” service on a modified version has to publish those modifications to its users (section 13), so improvements come back to every school instead of disappearing into a closed product.
- OSI-approved. An approved open-source licence lets the project join open-source catalogues and apply to grant programmes that require one.
- The owner keeps the copyright and may still license the code separately to anyone under other terms.
-only rather than -or-later: a future AGPL version will not apply automatically; moving to one
would be a new decision.
What was done: LICENSE at the root holds the licence text, package.json (and the root entry of
package-lock.json) say "license": "AGPL-3.0-only", README has a «Ліцензія» section.
No SPDX headers in source files — the owner does not want them; the root LICENSE and the
package.json field are the licence statement.
Still open:
- The
LICENSEtext was written without network access and must be diffed against https://www.gnu.org/licenses/agpl-3.0.txt before publishing (see publishing-checklist.md). - How a running site offers its source to users (section 13 is about modified versions, but a visible link — for example on the admin «Що нового» page or in the site footer, pointing at the release’s source — keeps every installation compliant by default). Not implemented yet.