[Pkg-cacti-maint] Bug#679980: cacti: license issue in include/treeview

Paul Gevers paul at climbing.nl
Mon Jul 2 19:33:04 UTC 2012


Package: cacti
Version: 0.8.4-1
Justification: Policy 2.2.1
Severity: serious

I spotted a license issue in cacti. The files in question are in the
include/treeview folder, i.e. ftiens4.js and ftiens4_export.js, and I am
sure the same issue is related to the icons in that folder. The
license for these files is not included in the project. A link [0] to
the web-site of the treeview project is provided in the headers of these
files. On the web-site a link can be found to what I believe are the two
possible licenses for this source.  When asked, debian-legal recommended
[1] notifying (cacti) upstream (I did that over one month ago [2]) and
one of three steps:

1) if cacti may work without the non-free files (possibly with
reduced functionality), those files should be dropped entirely

2) if cacti cannot work without those files, appropriate DFSG-free
and GPL-compatible replacements should be found (or clean-room
developed)

3) Gubusoft should be contacted and persuaded to re-license those
files under GPLv2-compatible terms

ad 3) After waiting for the cacti project to take action here, I asked
the treeview project several days ago to re-license the treeview files,
but I got no response yet, and I don't expect any.

ad 2) I am investigating the possibility to use other javascript source
code projects that have similar functionality, but with a DFSG-free
license. So far this seems hopeful, so I think this is the best solution
possible.

ad 1) The least attractive alternative would be to strip cacti from this
functionality, which works for small cacti sites, but is likely a
serious hit in usability for most large cacti sites.

I propose the following: discuss with the release team to replace cacti
in both stable and testing with a DFSG-free cacti. Either (preferred by
me) with alternative 2, or if that fails or comes too late with
alternative 1.

Paul

[0] http://www.treeview.net/
[1] http://lists.debian.org/debian-legal/2012/05/msg00020.html
[2] http://bugs.cacti.net/view.php?id=2228

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 262 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-cacti-maint/attachments/20120702/e23068b3/attachment.pgp>


More information about the Pkg-cacti-maint mailing list