# Suggestion: Put licenses for dependencies in deps

**URL:** <https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743>\
**Category:** Internals & Design\
**Tags:** suggestions\
**Created:** [April 4, 2019, 12:21pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743 "2019-04-04T12:21:20Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![madprogrammer](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@madprogrammer](https://discourse.julialang.org/u/madprogrammer)\
**Post date:** [April 4, 2019, 12:21pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/1 "2019-04-04T12:21:21Z")

</div>

I would like to suggest the addition of a license directory in deps, where we could have a copy of the dependencies license files. I think that is important to make it clear to the user which licenses they are dealing with.

---

<div class="post-metadata">

**Author:** ![Nosferican](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/nosferican/32/9275_2.png) [@Nosferican](https://discourse.julialang.org/u/Nosferican)\
**Post date:** [April 4, 2019, 4:40pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/2 "2019-04-04T16:40:55Z")

</div>

That sounds like you are asking for [FOSSA](https://app.fossa.com/projects) support for Julia.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 4, 2019, 4:49pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/3 "2019-04-04T16:49:37Z")

</div>

It’s a little unclear what exactly you’re asking for but [JuliaTeam](https://juliacomputing.com/products/juliateam.html) has some support for analyzing the licenses of the packages used in a given manifest and will have more support for that kind of thing in the future.

---

<div class="post-metadata">

**Author:** ![madprogrammer](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@madprogrammer](https://discourse.julialang.org/u/madprogrammer)\
**Post date:** [April 4, 2019, 5:24pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/4 "2019-04-04T17:24:46Z")

</div>

Sorry for not making it clear. What I was thinking is related to have a standard of adding the licenses for dependencies on Pkg.jl/deps/licenses or something similar/better.

I’ve seen some packages with this behavior, for example imagine PkgX.jl has MIT license, but it downloads libpkgx (on most cases already compiled) which has a license different than MIT. You will find the license only by searching this library. But adding the license to deps would make it easier to find the information needed.

I understand that it may no be a good idea to add it to the source code, but it could be useful to have this after the building process.

---

<div class="post-metadata">

**Author:** ![madprogrammer](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@madprogrammer](https://discourse.julialang.org/u/madprogrammer)\
**Post date:** [April 4, 2019, 5:26pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/5 "2019-04-04T17:26:20Z")

</div>

Interesting tool. Thanks for sharing it.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 4, 2019, 7:58pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/6 "2019-04-04T19:58:28Z")

</div>

I don’t think that it makes much sense to put the licenses in the source directory of a project. After all, we don’t put the source code of dependencies in the there, why would we put their licenses in there? It does, however, make a lot of sense to make license info easily accessible programmatically and provide tooling support for license analysis for an entire application.

---

<div class="post-metadata">

**Author:** ![arnavsood](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/arnavsood/32/4675_2.png) [@arnavsood](https://discourse.julialang.org/u/arnavsood)\
**Post date:** [April 4, 2019, 9:25pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/7 "2019-04-04T21:25:37Z")

</div>

@StefanKarpinski I think there’s one distinction, which is that many (if not all) licenses explicitly require that copies be included in any derivative works. Along with the actual copyright statement.

In practice, this isn’t something which really happens, but having some sort of automated tool for it would be nice…

Edit: That said, maybe links would be a better approach, like in Julia’s own LICENSE file.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 4, 2019, 9:37pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/8 "2019-04-04T21:37:31Z")

</div>

You don’t have to include the license unless you’re shipping the code, in which case you’re already shipping the license file…

---

<div class="post-metadata">

**Author:** ![arnavsood](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/arnavsood/32/4675_2.png) [@arnavsood](https://discourse.julialang.org/u/arnavsood)\
**Post date:** [April 4, 2019, 11:07pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/9 "2019-04-04T23:07:06Z")

</div>

> [@StefanKarpinski](#):
>
> You don’t have to include the license unless you’re shipping the code, in which case you’re already shipping the license file…

Oh. I’d figured creating a git release/registry PR counted as shipping in this case. But am not a lawyer or expert, so will defer to you on that.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 4, 2019, 11:25pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/10 "2019-04-04T23:25:15Z")

</div>

You are not shipping or publishing your dependencies then, only your own code.

---

<div class="post-metadata">

**Author:** ![bicycle1885](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/bicycle1885/32/107_2.png) [@bicycle1885](https://discourse.julialang.org/u/bicycle1885)\
**Post date:** [April 5, 2019, 3:24am UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/11 "2019-04-05T03:24:09Z")

</div>

I think this is a related issue ([distribute license files in binary tarballs · Issue #309 · JuliaPackaging/BinaryBuilder.jl · GitHub](https://github.com/JuliaPackaging/BinaryBuilder.jl/issues/309)) but no comments.

---

<div class="post-metadata">

**Author:** ![madprogrammer](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@madprogrammer](https://discourse.julialang.org/u/madprogrammer)\
**Post date:** [April 5, 2019, 2:31pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/12 "2019-04-05T14:31:32Z")

</div>

I understand that when shipping code the license is really required and not necessary on Julia packages’ case. But for example, on linux if you check /usr/share/doc you will be able to see documentation, including licenses, for software installed with the package manager. With the package manager you get the compiled software, not the source code.

Now, an specific case. IANAL but if you are using a library with GPL, it means the package needs to be compatible with GPL. In this situation having the licensing information is kind of important.

> [@StefanKarpinski](#):
>
> make a lot of sense to make license info easily accessible programmatically

Adding license files was only a suggestion based on what I mentioned about Linux before, but may not be practicable. Having the information easily accessible would be really interesting.

---

<div class="post-metadata">

**Author:** ![StefanKarpinski](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/stefankarpinski/32/24_2.png) [@StefanKarpinski](https://discourse.julialang.org/u/StefanKarpinski)\
**Post date:** [April 5, 2019, 4:05pm UTC](https://discourse.julialang.org/t/suggestion-put-licenses-for-dependencies-in-deps/22743/13 "2019-04-05T16:05:26Z")

</div>

> [@madprogrammer](#):
>
> But for example, on linux if you check /usr/share/doc you will be able to see documentation, including licenses, for software installed with the package manager. With the package manager you get the compiled software, not the source code.

Julia packages are installed as source including any license file that is in the package repo.
