Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Transfer of did-sdk-js #20

Open
hendrikebbers opened this issue Oct 7, 2024 · 4 comments
Open

Transfer of did-sdk-js #20

hendrikebbers opened this issue Oct 7, 2024 · 4 comments
Labels
hashgraph transfer Related to the transfer of the Hashgraph projects

Comments

@hendrikebbers
Copy link
Contributor

No description provided.

@hendrikebbers
Copy link
Contributor Author

no unidentified accounts with 1+ commit without DCO signing

@hendrikebbers
Copy link
Contributor Author

hendrikebbers commented Oct 8, 2024

Licenses of (transitive) dependencies we need to check:

[email protected]: 'CC0-1.0'

@hendrikebbers
Copy link
Contributor Author

@SimiHunjan we need to find a replacement for [email protected]: 'CC0-1.0'

@hendrikebbers
Copy link
Contributor Author

About [email protected]: 'CC0-1.0':

CC0-1.0 is not a suitable license for code, as it does not grant patent rights. This particular piece of code was worrisome for me, not just because of this, but also because it didn't seem to be that widely used and was completely run by a single maintainer and hadn't been touched in 4 years (and thus, would be an excellent attack vector for a software supply chain attack on Hiero/the hashgraph network). If you can, I would remove or replace this code.

@hendrikebbers hendrikebbers added the hashgraph transfer Related to the transfer of the Hashgraph projects label Nov 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
hashgraph transfer Related to the transfer of the Hashgraph projects
Projects
None yet
Development

No branches or pull requests

1 participant