Re: OSI Adopts SPDX IDs for License URLs

Simon Phipps <[email protected]> Tue, 10 Mar 2026 22:26:17 +0000
Newsgroups gmane.comp.licenses.open-source.general
Message-ID <CAA4ffp_xT9O=mFOVMh23DJjbSGHMmdX=jR=KNuZV-f5QaM74xA@mail.gmail.com>
--===============7612656747701667983==
Content-Type: multipart/alternative; boundary="000000000000c88644064cb302bf"
Content-Transfer-Encoding: 7bit

--000000000000c88644064cb302bf
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I agree with Richard here. The -only and -or-later variants are all
deployment options for the GPL licenses and do not reflect the licenses
that OSI has actually approved, which embrace both variants.

Simon
(in a personal capacity)

On Tue, Mar 10, 2026 at 9:00=E2=80=AFPM Richard Fontana via License-discuss=
 <
[email protected]> wrote:

> I agree with the comment. SPDX's replacement of GPL-2.0/GPL-2.0+ with
> "GPL-2.0-only"/"GPL-2.0-or-later" (etc.) (at the instigation of the
> FSF) has been pretty much a complete debacle IMO, but "GPL-2.0"
> continues to be a valid SPDX identifier and I think it is usefully
> used for things like this where the license is one level of
> abstraction removed from its actual application to some sort of
> licensable material.
>
> Richard
>
> On Tue, Mar 10, 2026 at 11:19=E2=80=AFAM Nick Vidal <nick.vidal@opensourc=
e.org>
> wrote:
> >
> > Cross posting comment from ferdnyc at
> https://github.com/spdx/license-list-XML/issues/2959#issuecomment-4018341=
555
> >
> > I wanted to bring up the GPL specifically: I notice that OSI is listing
> all of the GPL versions as "GPL-X.Y-only" (and in fact, URLs like
> https://opensource.org/license/GPL-3.0-or-later result in a 404 error),
> but the license text displayed at
> https://opensource.org/license/GPL-3.0-only has a "How to Apply These
> Terms..." section that includes the "either version 3 of the License, or
> (at your option) any later version." text, making it appear to be
> GPL-3.0-or-later.
> >
> > (In truth, AIUI the FSF doesn't differentiate between GPL-3.0-only and
> GPL-3.0-or-later themselves, the difference is in how you choose to apply
> the license to your work. But in light of that, calling the license
> "GPL-3.0-only" doesn't appear to be correct... it's either just "GPL-3.0"=
,
> or it's "GPL-3.0-or-later" (as it allows for the "any later version"
> stipulation, or it's BOTH.)
> >
> > On Tue, Mar 10, 2026 at 9:16=E2=80=AFAM Nick Vidal <nick.vidal@opensour=
ce.org>
> wrote:
> >>
> >> Hi everyone,
> >>
> >> The OSI is looking for feedback from the community about an important
> change to the OSI-Approved licenses listed on our website.
> >>
> >> We've standardized OSI license URLs using SPDX identifiers, while
> carefully preserving compatibility with the many links that already exist
> across the web and tools.
> >>
> >> The full set of OSI-approved licenses continues to be available at:
> >>
> >> https://opensource.org/licenses
> >>
> >> More details about the update is available here:
> >>
> >> https://opensource.org/blog/osi-adopts-spdx-ids-for-license-urls
> >>
> >> If you spot any broken links or odd behaviour, please let us know.
> >>
> >> Feel free to reach out to us by replying to this mailing list or by
> commenting here:
> >>
> >> https://github.com/spdx/license-list-XML/issues/2959
> >>
> >> Thanks,
> >> Nick
> >
> > _______________________________________________
> > The opinions expressed in this email are those of the sender and not
> necessarily those of the Open Source Initiative. Official statements by t=
he
> Open Source Initiative will be sent from an opensource.org email address.
> >
> > License-discuss mailing list
> > [email protected]
> >
> http://lists.opensource.org/mailman/listinfo/license-discuss_lists.openso=
urce.org
>
>
> _______________________________________________
> The opinions expressed in this email are those of the sender and not
> necessarily those of the Open Source Initiative. Official statements by t=
he
> Open Source Initiative will be sent from an opensource.org email address.
>
> License-discuss mailing list
> [email protected]
>
> http://lists.opensource.org/mailman/listinfo/license-discuss_lists.openso=
urce.org
>

--000000000000c88644064cb302bf
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I agree with Richard here. The -only and -or-later variant=
s are all deployment options for the GPL licenses and do not reflect the li=
censes that OSI has actually approved, which embrace both variants.<div><br=
></div><div>Simon</div><div>(in a personal capacity)</div></div><br><div cl=
ass=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_a=
ttr">On Tue, Mar 10, 2026 at 9:00=E2=80=AFPM Richard Fontana via License-di=
scuss &lt;<a href=3D"mailto:[email protected]">license-d=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex">I agree with the comment. SPDX&#39;s replacement=
 of GPL-2.0/GPL-2.0+ with<br>
&quot;GPL-2.0-only&quot;/&quot;GPL-2.0-or-later&quot; (etc.) (at the instig=
ation of the<br>
FSF) has been pretty much a complete debacle IMO, but &quot;GPL-2.0&quot;<b=
r>
continues to be a valid SPDX identifier and I think it is usefully<br>
used for things like this where the license is one level of<br>
abstraction removed from its actual application to some sort of<br>
licensable material.<br>
<br>
Richard<br>
<br>
On Tue, Mar 10, 2026 at 11:19=E2=80=AFAM Nick Vidal &lt;<a href=3D"mailto:n=
[email protected]" target=3D"_blank">[email protected]</a>&g=
t; wrote:<br>
&gt;<br>
&gt; Cross posting comment from ferdnyc at <a href=3D"https://github.com/sp=
dx/license-list-XML/issues/2959#issuecomment-4018341555" rel=3D"noreferrer"=
 target=3D"_blank">https://github.com/spdx/license-list-XML/issues/2959#iss=
uecomment-4018341555</a><br>
&gt;<br>
&gt; I wanted to bring up the GPL specifically: I notice that OSI is listin=
g all of the GPL versions as &quot;GPL-X.Y-only&quot; (and in fact, URLs li=
ke <a href=3D"https://opensource.org/license/GPL-3.0-or-later" rel=3D"noref=
errer" target=3D"_blank">https://opensource.org/license/GPL-3.0-or-later</a=
> result in a 404 error), but the license text displayed at <a href=3D"http=
s://opensource.org/license/GPL-3.0-only" rel=3D"noreferrer" target=3D"_blan=
k">https://opensource.org/license/GPL-3.0-only</a> has a &quot;How to Apply=
 These Terms...&quot; section that includes the &quot;either version 3 of t=
he License, or (at your option) any later version.&quot; text, making it ap=
pear to be GPL-3.0-or-later.<br>
&gt;<br>
&gt; (In truth, AIUI the FSF doesn&#39;t differentiate between GPL-3.0-only=
 and GPL-3.0-or-later themselves, the difference is in how you choose to ap=
ply the license to your work. But in light of that, calling the license &qu=
ot;GPL-3.0-only&quot; doesn&#39;t appear to be correct... it&#39;s either j=
ust &quot;GPL-3.0&quot;, or it&#39;s &quot;GPL-3.0-or-later&quot; (as it al=
lows for the &quot;any later version&quot; stipulation, or it&#39;s BOTH.)<=
br>
&gt;<br>
&gt; On Tue, Mar 10, 2026 at 9:16=E2=80=AFAM Nick Vidal &lt;<a href=3D"mail=
to:[email protected]" target=3D"_blank">[email protected]</=
a>&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt; Hi everyone,<br>
&gt;&gt;<br>
&gt;&gt; The OSI is looking for feedback from the community about an import=
ant change to the OSI-Approved licenses listed on our website.<br>
&gt;&gt;<br>
&gt;&gt; We&#39;ve standardized OSI license URLs using SPDX identifiers, wh=
ile carefully preserving compatibility with the many links that already exi=
st across the web and tools.<br>
&gt;&gt;<br>
&gt;&gt; The full set of OSI-approved licenses continues to be available at=
:<br>
&gt;&gt;<br>
&gt;&gt; <a href=3D"https://opensource.org/licenses" rel=3D"noreferrer" tar=
get=3D"_blank">https://opensource.org/licenses</a><br>
&gt;&gt;<br>
&gt;&gt; More details about the update is available here:<br>
&gt;&gt;<br>
&gt;&gt; <a href=3D"https://opensource.org/blog/osi-adopts-spdx-ids-for-lic=
ense-urls" rel=3D"noreferrer" target=3D"_blank">https://opensource.org/blog=
/osi-adopts-spdx-ids-for-license-urls</a><br>
&gt;&gt;<br>
&gt;&gt; If you spot any broken links or odd behaviour, please let us know.=
<br>
&gt;&gt;<br>
&gt;&gt; Feel free to reach out to us by replying to this mailing list or b=
y commenting here:<br>
&gt;&gt;<br>
&gt;&gt; <a href=3D"https://github.com/spdx/license-list-XML/issues/2959" r=
el=3D"noreferrer" target=3D"_blank">https://github.com/spdx/license-list-XM=
L/issues/2959</a><br>
&gt;&gt;<br>
&gt;&gt; Thanks,<br>
&gt;&gt; Nick<br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; The opinions expressed in this email are those of the sender and not n=
ecessarily those of the Open Source Initiative. Official statements by the =
Open Source Initiative will be sent from an <a href=3D"http://opensource.or=
g" rel=3D"noreferrer" target=3D"_blank">opensource.org</a> email address.<b=
r>
&gt;<br>
&gt; License-discuss mailing list<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"_bla=
nk">[email protected]</a><br>
&gt; <a href=3D"http://lists.opensource.org/mailman/listinfo/license-discus=
s_lists.opensource.org" rel=3D"noreferrer" target=3D"_blank">http://lists.o=
pensource.org/mailman/listinfo/license-discuss_lists.opensource.org</a><br>
<br>
<br>
_______________________________________________<br>
The opinions expressed in this email are those of the sender and not necess=
arily those of the Open Source Initiative. Official statements by the Open =
Source Initiative will be sent from an <a href=3D"http://opensource.org" re=
l=3D"noreferrer" target=3D"_blank">opensource.org</a> email address.<br>
<br>
License-discuss mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">L=
[email protected]</a><br>
<a href=3D"http://lists.opensource.org/mailman/listinfo/license-discuss_lis=
ts.opensource.org" rel=3D"noreferrer" target=3D"_blank">http://lists.openso=
urce.org/mailman/listinfo/license-discuss_lists.opensource.org</a><br>
</blockquote></div>

--000000000000c88644064cb302bf--


--===============7612656747701667983==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVGhlIG9waW5p
b25zIGV4cHJlc3NlZCBpbiB0aGlzIGVtYWlsIGFyZSB0aG9zZSBvZiB0aGUgc2VuZGVyIGFuZCBu
b3QgbmVjZXNzYXJpbHkgdGhvc2Ugb2YgdGhlIE9wZW4gU291cmNlIEluaXRpYXRpdmUuIE9mZmlj
aWFsIHN0YXRlbWVudHMgYnkgdGhlIE9wZW4gU291cmNlIEluaXRpYXRpdmUgd2lsbCBiZSBzZW50
IGZyb20gYW4gb3BlbnNvdXJjZS5vcmcgZW1haWwgYWRkcmVzcy4KCkxpY2Vuc2UtZGlzY3VzcyBt
YWlsaW5nIGxpc3QKTGljZW5zZS1kaXNjdXNzQGxpc3RzLm9wZW5zb3VyY2Uub3JnCmh0dHA6Ly9s
aXN0cy5vcGVuc291cmNlLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2xpY2Vuc2UtZGlzY3Vzc19saXN0
cy5vcGVuc291cmNlLm9yZwo=

--===============7612656747701667983==--