@@ -52,8 +52,8 @@ controls:
5252
5353 - id : OSPS-LE-02
5454 title : |
55- Ensure that the license for the source code meets the OSI Open Source
56- Definition or the FSF Free Software Definition
55+ All licenses for the project MUST meet the OSI Open Source Definition
56+ or the FSF Free Software Definition.
5757 objective : |
5858 Ensure that the project's source code is distributed under a recognized
5959 and legally enforceable open source software license, providing clarity on
@@ -76,8 +76,8 @@ controls:
7676 assessment-requirements :
7777 - id : OSPS-LE-02.01
7878 text : |
79- The license for the source code MUST meet the OSI Open Source Definition
80- or the FSF Free Software Definition.
79+ While active, the license for the source code MUST meet the OSI Open
80+ Source Definition or the FSF Free Software Definition.
8181 applicability :
8282 - Maturity Level 1
8383 - Maturity Level 2
@@ -90,6 +90,22 @@ controls:
9090 Apache 2.0, Lesser GNU General Public License (LGPL), and the GNU
9191 General Public License (GPL). Releasing to the public domain meets
9292 this control if there are no other encumbrances such as patents.
93+ - id : OSPS-LE-02.02
94+ text : |
95+ While active, the license for the released software assets MUST meet
96+ the OSI Open Source Definition or the FSF Free Software Definition.
97+ applicability :
98+ - Maturity Level 1
99+ - Maturity Level 2
100+ - Maturity Level 3
101+ recommendation : |
102+ If a different license is included with released software assets,
103+ ensure it is an approved license by the Open Source Initiative (OSI),
104+ or a free license as approved by the Free Software Foundation (FSF).
105+ Examples of such licenses include the MIT, BSD 2-clause, BSD 3-clause
106+ revised, Apache 2.0, Lesser GNU General Public License (LGPL), and the
107+ GNU General Public License (GPL). Note that the license for the
108+ released software assets may be different than the source code.
93109
94110 - id : OSPS-LE-03
95111 title : |
@@ -124,19 +140,3 @@ controls:
124140 Include the project's source code license in the project's LICENSE
125141 file, COPYING file, or LICENSE/ directory to provide visibility and
126142 clarity on the licensing terms. The filename MAY have an extension.
127- - id : OSPS-LE-03.02
128- text : |
129- The license for the released software assets MUST meet the OSI Open
130- Source Definition or the FSF Free Software Definition.
131- applicability :
132- - Maturity Level 1
133- - Maturity Level 2
134- - Maturity Level 3
135- recommendation : |
136- If a different license is included with released software assets,
137- ensure it is an approved license by the Open Source Initiative (OSI),
138- or a free license as approved by the Free Software Foundation (FSF).
139- Examples of such licenses include the MIT, BSD 2-clause, BSD 3-clause
140- revised, Apache 2.0, Lesser GNU General Public License (LGPL), and the
141- GNU General Public License (GPL). Note that the license for the
142- released software assets may be different than the source code.
0 commit comments