Problem.
- LICENSING.md:59-66 offers commercial and OEM licenses that release buyers from the AGPL, and DESIGN_PARTNERS.md promises partners access to them. CONTRIBUTING.md:173-180 invites outside PRs with no CLA, no DCO and no statement of inbound terms, and there is no CLA check in .github/. Today all human commits are the maintainer's. The first external PR merged will be AGPL-only code that cannot be relicensed without its contributor's permission.
web-ui/package.json:4 has no license field, so license-checker reports UNLICENSED.
Acceptance criteria.
- A CLA (e.g. the CLA Assistant check) that grants relicensing rights, documented in CONTRIBUTING.md before external PRs are accepted, or the commercial promise is qualified.
"license": "AGPL-3.0-or-later" is added to web-ui/package.json.
Severity: medium · area: legal/docs · source: SaaS launch review 2026-09-25 (plan in tasks/todo.md).
Problem.
web-ui/package.json:4has nolicensefield, so license-checker reportsUNLICENSED.Acceptance criteria.
"license": "AGPL-3.0-or-later"is added to web-ui/package.json.Severity: medium · area: legal/docs · source: SaaS launch review 2026-09-25 (plan in
tasks/todo.md).