The repo contradicted itself — package.json/CONTRIBUTING said MPL-2.0 (permits
commercial use) while README/docs/LICENSE said Creative Commons NonCommercial
(forbids it), with no root LICENSE. The owner chose Creative Commons
Attribution-NonCommercial 4.0 International; this makes every surface agree.
- Add a root LICENSE with the full official CC BY-NC 4.0 legal text plus a
StepForge copyright header and SPDX identifier. Packages already ship it as
the copyright file (verified in the built .deb).
- package.json license -> CC-BY-NC-4.0; RPM spec License -> CC-BY-NC-4.0.
- docs/LICENSE becomes a short pointer to the root LICENSE (no more competing
paraphrase); README and CONTRIBUTING state CC BY-NC 4.0 (contributions
licensed under the same license + DCO sign-off for provenance).
- app:info now reports the license so the About view can't contradict.
- New tests/unit/license.test.js guards consistency: root LICENSE present with
the full legal text, package.json is CC-BY-NC-4.0, no shipping surface
mentions MPL, and the story matches across README/CONTRIBUTING/docs/spec.
Updated the RPM-spec packaging test accordingly.
Note: the historical planning archives under ai_prompts/ still mention the old
MPL target; they are point-in-time design notes, not the license, so they are
left as-is.
Verified: 289 unit tests pass; the built .deb ships the CC BY-NC 4.0 text as
its copyright file.
Co-Authored-By: Claude Fable 5 <[email protected]>
Phase 3 of the improvement plan (PR 9 of the sequence): the dnf/Fedora
packaging half, in separate Linux-specific files, mirroring the apt/.deb work.
- packaging/linux/common/stage-runtime.sh: shared runtime-only payload staging
extracted from the .deb builder so the two package formats never drift. It
copies app code + a fixed Electron runtime + production npm deps (npm ls
--omit=dev), guards against dev-dep leaks, and fails without node_modules.
The .deb builder now delegates to it.
- packaging/linux/fedora/stepforge.spec: runtime Requires (nss, nspr, gtk3,
…), Recommends (xinput, portal, pipewire), %license, and a %post that makes
chrome-sandbox setuid and refreshes desktop/MIME/icon caches. No compilation
— it packages the prebuilt BuildRoot.
- packaging/linux/fedora/package.sh: stages the shared payload, substitutes
version/maintainer into the spec, and runs rpmbuild against the prebuilt
BuildRoot with detected arch. Requires rpmbuild + node_modules; emits an
.rpm + sha256.
- scripts/linux/dnf/install-runtime-deps.sh and install-build-deps.sh:
separate runtime vs build dependency sets for dnf (runtime installs no build
tools).
- docs/linux/dnf.md: Fedora/RHEL install + build guide, distinct from apt.md.
Tests: packaging-linux.test.js gains Fedora/dnf structural checks (spec
Requires + MPL-2.0 + %license + sandbox setup, builder shares staging +
requires rpmbuild, dnf build/runtime dep separation, shared staging never
copies the whole dev tree). tests/integration/linux/package-rpm.test.sh builds
a real .rpm and asserts runtime-only contents (honest skip when rpmbuild is
absent, as on this apt host).
Verified: 13 packaging unit tests pass; the refactored .deb builder still
produces a valid runtime-only package (integration test green); the .rpm
integration test skips cleanly where rpmbuild is unavailable.
Co-Authored-By: Claude Fable 5 <[email protected]>