Launch: license and make the repo public #19

Closed
opened 2026-10-02 01:38:36 +00:00 by jhgaylor · 1 comment
Owner

Blocks: #28 (and through it the control track)

Make the repo public, with a license, so the install page has something to point at.

Decided 2026-10-01: dual MIT OR Apache-2.0, hosted here on Forgejo (git.inevitable.fyi).

  • LICENSE-MIT and LICENSE-APACHE at the root; license = "MIT OR Apache-2.0" in the workspace Cargo.toml (and web/package.json).
  • Third-party notices for what ships in the binaries: libghostty (Ghostty, MIT), the Rust dependency tree (cargo about or cargo deny check licenses), and the web client's bundled npm packages.
  • Scan the whole history for secrets before flipping visibility (gitleaks detect over all commits). Tokens, tailnet auth keys, the wisp token and the Cloudflare token are referenced by path in the docs; make sure none were ever committed.
  • Decide what to do about personal infrastructure in the history and docs (geek's tailnet name and IP, widgets.wtf). Not secret, but public once this flips. Rewriting history isn't planned; the README is swept in #23.
  • Repo description, website link (the page), topics.
  • Flip the repo to public.

Done when

  • An anonymous git clone https://git.inevitable.fyi/jhgaylor/illogical works and the license is visible on the repo page.
**Blocks:** #28 (and through it the control track) Make the repo public, with a license, so the install page has something to point at. Decided 2026-10-01: dual **MIT OR Apache-2.0**, hosted here on Forgejo (git.inevitable.fyi). - [ ] `LICENSE-MIT` and `LICENSE-APACHE` at the root; `license = "MIT OR Apache-2.0"` in the workspace `Cargo.toml` (and `web/package.json`). - [ ] Third-party notices for what ships in the binaries: libghostty (Ghostty, MIT), the Rust dependency tree (`cargo about` or `cargo deny check licenses`), and the web client's bundled npm packages. - [ ] Scan the whole history for secrets before flipping visibility (`gitleaks detect` over all commits). Tokens, tailnet auth keys, the wisp token and the Cloudflare token are referenced by path in the docs; make sure none were ever committed. - [ ] Decide what to do about personal infrastructure in the history and docs (geek's tailnet name and IP, `widgets.wtf`). Not secret, but public once this flips. Rewriting history isn't planned; the README is swept in #23. - [ ] Repo description, website link (the page), topics. - [ ] Flip the repo to public. ### Done when - An anonymous `git clone https://git.inevitable.fyi/jhgaylor/illogical` works and the license is visible on the repo page.
Author
Owner

Done (2026-10-01).

  • LICENSE-MIT, LICENSE-APACHE; MIT OR Apache-2.0 in Cargo.toml and web/package.json.
  • THIRD_PARTY.md from just notices: cargo-about for the crates (all permissive), Ghostty's MIT text, and the six bundled npm packages. CI fails if it's stale.
  • gitleaks over the whole history: the only hit was RFC 6455's sample WebSocket nonce in a spike script (allowed inline). CI runs gitleaks on every push.
  • Personal infrastructure: geek's setup moved to docs/geek.md; history wasn't rewritten.
  • Description, website and topics set. The repo and homebrew-tap are public; anonymous clone works.
Done (2026-10-01). - `LICENSE-MIT`, `LICENSE-APACHE`; `MIT OR Apache-2.0` in Cargo.toml and web/package.json. - `THIRD_PARTY.md` from `just notices`: cargo-about for the crates (all permissive), Ghostty's MIT text, and the six bundled npm packages. CI fails if it's stale. - gitleaks over the whole history: the only hit was RFC 6455's sample WebSocket nonce in a spike script (allowed inline). CI runs gitleaks on every push. - Personal infrastructure: geek's setup moved to `docs/geek.md`; history wasn't rewritten. - Description, website and topics set. **The repo and `homebrew-tap` are public**; anonymous clone works.
Sign in to join this conversation.
No description provided.