License OIC under PolyForm Noncommercial 1.0.0 - #36
Conversation
inventor1975
left a comment
There was a problem hiding this comment.
POLYFORM-NONCOMMERCIAL-REVIEW-001 — Institutional-Compiler
Independent reviewer role only. Composition was checked before substantive
content. No branch mutation was performed: no edit, push, rebase, amend, merge,
or auto-merge.
REVIEWED HEAD: 3e9f91d
BASE: 62f1485
SYNTHETIC MERGE: 3b1f3f3
All three match the stated composition exactly. 12 changed files, exactly the 12 listed.
- LICENSE canonical — YES, byte-identical. Not eyeballed: sha256
ffcca38841adb694b6f380647e15f17c446a4d1656fed51a1e2041d064c94cc8, identical to
the SPDX license-list text for PolyForm-Noncommercial-1.0.0. - SPDX identity exact — license = "PolyForm-Noncommercial-1.0.0".
- Metadata ships LICENSE — license-files = ["LICENSE"]; setuptools>=77.0.3.
- Obsolete statements reconciled without touching unrelated claims. Every changed
line outside LICENSE was enumerated; all are licensing text. - No open-source claim remains. One occurrence survives in AGENTS.md and it is a
prohibition ("Do not describe it as open source"), which is correct. - Public GitHub description reads "Source-available…" — verified against the live repo.
- Commercial rights explicitly NOT granted — "commercial use requires a separate
written license from Veraxis", in AGENTS.md, README.md, VERSIONING.md,
sbom/README.md and scripts/generate_sbom.sh. - Corpus/source rights kept separate — FOUNDATION.md: "dependency and corpus-source
rights remain separately bounded and unadjudicated." - SBOM generator and licensing tests changed only to reflect the new licensing truth.
- No product semantics, benchmarks, workflows, dependencies, architecture, ZTL/VEIP
behavior or semantic-gate state changed. The only non-licensing change in the whole
diff is setuptools>=77.0.0 -> >=77.0.3, which the work order expects. - Gate K is correctly bounded: machine-readable discovery and licensing only. It does
not imply production readiness, open-source status, commercial rights, or
third-party compatibility. - CI 33085985238 is bound to this exact head — head_sha matches, conclusion success,
event pull_request.
DISPOSITION: APPROVED, bound to head 3e9f91d.
SCOPE AND LIMITATIONS — read before relying on this review:
- Mechanical, not legal. Verified: text identity, exact strings, metadata, file-level
change scope, CI binding. NOT assessed: legal effect, enforceability, or whether
PolyForm Noncommercial is the right instrument. Those require counsel. - Third-party license compatibility is not established here, and the repository says so.
- The reviewer is not an independent party: this review was produced by Vitaly Reznik's
assistant, and Vitaly Reznik is a collaborator of the repository owner.
MERGE NOT AUTHORIZED BY THIS REVIEW.
POLYFORM-NONCOMMERCIAL-REVIEW-001 COMPLETE — INDEPENDENT REVIEW RECORDED
inventor1975
left a comment
There was a problem hiding this comment.
APPROVED — POLYFORM-NONCOMMERCIAL-REVIEW-001
This changes the GitHub review state only. The substantive review is the earlier
COMMENT on this same head; nothing in it is amended, and no new verification is
claimed here.
Head re-verified immediately before submitting this approval, not taken from
earlier notes. CI re-checked and still green on the same head.
The limitations recorded in the substantive review continue to apply and travel
with this approval:
- The review is MECHANICAL, not legal. Verified: canonical licence text by
sha256, exact SPDX string, package metadata, file-level change scope,
dependency provenance, CI binding to the exact head. NOT assessed: legal
effect, enforceability, or whether PolyForm Noncommercial is the right
instrument. Those require counsel. - Third-party licence compatibility is not established.
- THE REVIEWER IS NOT AN INDEPENDENT PARTY. This was produced by Vitaly Reznik's
assistant, and Vitaly Reznik is a collaborator of the repository owner. A green
approval badge should not be read as independent adjudication.
No branch was modified. No merge was performed or authorized by this review.
Owner-authorized licensing reconciliation under POLYFORM-NONCOMMERCIAL-LICENSE-RECONCILIATION-001 and metadata correction POLYFORM-NONCOMMERCIAL-RECONCILIATION-002.
Base: 62f1485
Final head: 3e9f91d
GitHub synthetic merge: 3b1f3f3
Final CI: 33085985238 — SUCCESS
Machine-readable metadata:
license = "PolyForm-Noncommercial-1.0.0"
license-files = ["LICENSE"]
Build-system floor: setuptools>=77.0.3
Generated Core Metadata: License-Expression: PolyForm-Noncommercial-1.0.0; License-File: LICENSE.
Provider description before: Open-source reference implementation for compiling institutionally warranted policy into machine-operational controls with preserved provenance, versioning, authority boundaries, and verifiable source-to-execution traceability.
Provider description after: Source-available reference implementation for compiling institutionally warranted policy into machine-operational controls with preserved provenance, versioning, authority boundaries, and verifiable source-to-execution traceability.
All nine required jobs succeeded: dependency-review, advisory-scan, bootstrap-integrity, schema-validation, lint, typecheck, test, sbom, compose-validation.
The canonical PolyForm Noncommercial License 1.0.0 text is unchanged. Third-party dependency and Canada corpus-rights limitations remain unchanged. Commercial use is not granted. This is not an open-source claim. No product semantics, dependencies, workflows, benchmarks, or architecture changed.
CI GREEN IS EVIDENCE, NOT ACCEPTANCE.
NOT SELF-ADJUDICATED.