License under MIT

No licence file meant nobody had permission to redistribute this, which is a
strange position for a public repo with an AUR package pointing at it. The
PKGBUILD said license=('custom') because there was nothing truthful to put
there.

MIT is not one of the licences Arch keeps in /usr/share/licenses/common, so
the package now fetches the licence from its own tag and installs a copy. The
release workflow checksums that copy from the tag it checked out, rather than
trusting whatever main has drifted to.

Declared in package.json and Cargo.toml too, so the manifests and the package
agree on the answer.
This commit is contained in:
pj committed 2026-08-12 21:30:13 +05:30
1 parent fef1ad7ff5
commit 3323496a34
5 files changed
+41 -5

No files matched your search

+10 -2
View File
@@ -188,7 +188,10 @@ jobs:
needs: [prepare, publish]
runs-on: ubuntu-latest
steps:
# The tag, not main, so the template and the licence are the ones this release shipped.
- uses: actions/checkout@v7
with:
ref: ${{ needs.prepare.outputs.tag }}
- name: Render the PKGBUILD for this release
env:
@@ -199,8 +202,13 @@ jobs:
# From the published asset, so the checksum is of the artifact users will actually fetch.
curl -fsSL --retry 3 -o package.deb "$URL"
SHA=$(sha256sum package.deb | cut -d' ' -f1)
sed -e "s/@VERSION@/$VERSION/g" -e "s/@SHA256@/$SHA/g" packaging/aur/PKGBUILD.in > PKGBUILD
echo "pkgver $VERSION, sha256 $SHA"
# The PKGBUILD fetches the licence from the tag, so checksum the copy at that same tag.
LICENSE_SHA=$(sha256sum LICENSE | cut -d' ' -f1)
sed -e "s/@VERSION@/$VERSION/g" \
-e "s/@SHA256@/$SHA/g" \
-e "s/@LICENSE_SHA256@/$LICENSE_SHA/g" \
packaging/aur/PKGBUILD.in > PKGBUILD
echo "pkgver $VERSION, deb $SHA, licence $LICENSE_SHA"
- name: Generate .SRCINFO
# makepkg is Arch-only and refuses to run as root, hence the container and the throwaway