Re: Python-2.0.1 and CNRI-Python-GPL-Compatible
McCoy Smith <[email protected]> Tue, 17 Mar 2026 07:13:54 -0700
| Newsgroups | gmane.comp.licenses.open-source.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============3946896876793234027== Content-Type: multipart/alternative; boundary="------------r7VsYhvNu6Z2H6kDIfs6qSsw" Content-Language: en-US Content-Transfer-Encoding: 7bit This is a multi-part message in MIME format. --------------r7VsYhvNu6Z2H6kDIfs6qSsw Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Max: If you think the newer version of the Python license ought to be approved by the OSI, someone needs to submit it through the license approval process, described here: https://opensource.org/licenses/review-process Given that it sounds like 2.0.1 is now being used by Python, and 2.0 is only a legacy of older versions, I'd suggest that if submitted, at the same time 2.0 be "Voluntarily Retired" as have many other licenses that have been superceded by newer versions (see the list here: https://opensource.org/licenses?categories=superseded%2Cvoluntarily-retired); if it is not, 2.0 will likely be tagged (if 2.0.1 is approved) as superseded, like these licenses: https://opensource.org/licenses?categories=superseded Same comment for the newer CNRI license versus the old one. I would suggest that someone from the Python community (if you aren't one already) do the submission, if that result is indeed desired. The review process requirements are in the link above. *This is no commentary on the approvability of the 2.0.1. or new CNRI license, which I haven't read, but just a general comment on how the result you want might be accomplished. McCoy Smith On 3/16/2026 5:46 PM, Pamela Chestek wrote: > > I don't see a reason. The OSI generally only reacts to requests for > license approval, it doesn't generally approve licenses without them > being submitted. I'm assuming it hasn't be approved just because no > one has asked for it before. > > Pam > > Pamela S. Chestek > Chestek Legal > 4641 Post St. > Unit 4316 > El Dorado Hills, CA 95762 > +1 919-800-8033 > [email protected] > www.chesteklegal.com > > > On 3/6/2026 5:47 AM, Max Mehl wrote: >> Hi everyone, >> >> As requested by Nick, I would like point to an ongoing discussion on >> Python licenses, affecting both OSI's and SPDX’s realms, and request >> OSI’s approval of two licenses. >> >> As you know, the licensing history of Python is quite complex, and >> the current license consists of multiple other licenses representing >> the long history and the different “ownerships” of the project (CWI, >> CNRI, BeOpen, PSF). spdx/license-list-XML#2197 >> <https://github.com/spdx/license-list-XML/issues/2197> and an email >> to spdx-legal@ >> <https://lists.spdx.org/g/Spdx-legal/topic/107252308> describe a >> bunch of intertwined problems around the identifiers of components of >> Python licenses. Recently, OSI fixed some of those already, thanks! >> >> Now, I wonder about the status of the license SPDX describes as >> Python-2.0.1 <https://spdx.org/licenses/Python-2.0.1.html>. IIRC, the >> main difference between Python-2.0 >> <https://spdx.org/licenses/Python-2.0.html> and Python-2.0.1 is in >> the CNRI part, making it GPL compatible (the “Virginia clause”). SPDX >> lists this updated sub-part as CNRI-Python-GPL-Compatible >> <https://spdx.org/licenses/CNRI-Python-GPL-Compatible.html>, a >> successor of CNRI-Python <https://spdx.org/licenses/CNRI-Python.html>. >> >> Since Python 1.6.1 and 2.0.1, Python releases have been licensed >> under Python-2.0.1 (and recently additionally 0BSD for its >> documentation), while Python-2.0 has only been used for Python 1.6 >> and 2.0. So modern CPython releases would probably be best described >> as being licensed under "Python-2.0.1 AND 0BSD". >> >> But OSI only approved Python-2.0 as an Open Source license, as well >> as the old CNRI-Python part. This is why I suggest OSI to approve >> *Python-2.0.1* and *CNRI-Python-GPL-Compatible* as Open Source >> licenses, and mark Python-2.0 and CNRI-Python as superseded. Is there >> any reason not to? >> >> Best, >> Max >> >> -- >> >> *Max Mehl* >> >> Open Source / Supply Chain >> >> Enterprise-Team Chief Technology Office (CTO) >> >> DB Systel GmbH / Deutsche Bahn >> >> >> Schedule a meeting: cal.com/mxmehl <https://cal.com/mxmehl> >> >> >> >> ------------------------------------------------------------------------ >> >> Pflichtangaben anzeigen >> <https://www.deutschebahn.com/pflichtangaben/20260305> >> >> Nähere Informationen zur Datenverarbeitung im DB-Konzern finden Sie >> hier: https://www.deutschebahn.com/de/konzern/datenschutz >> >> _______________________________________________ >> The opinions expressed in this email are those of the sender and not necessarily those of the Open Source Initiative. Official statements by the Open Source Initiative will be sent from an opensource.org email address. >> >> License-discuss mailing list >> [email protected] >> http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org > > _______________________________________________ > The opinions expressed in this email are those of the sender and not necessarily those of the Open Source Initiative. Official statements by the Open Source Initiative will be sent from an opensource.org email address. > > License-discuss mailing list > [email protected] > http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org --------------r7VsYhvNu6Z2H6kDIfs6qSsw Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 8bit <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> <p>Max:</p> <p>If you think the newer version of the Python license ought to be approved by the OSI, someone needs to submit it through the license approval process, described here: <a class="moz-txt-link-freetext" href="https://opensource.org/licenses/review-process">https://opensource.org/licenses/review-process</a></p> <p>Given that it sounds like 2.0.1 is now being used by Python, and 2.0 is only a legacy of older versions, I'd suggest that if submitted, at the same time 2.0 be "Voluntarily Retired" as have many other licenses that have been superceded by newer versions (see the list here: <a class="moz-txt-link-freetext" href="https://opensource.org/licenses?categories=superseded%2Cvoluntarily-retired">https://opensource.org/licenses?categories=superseded%2Cvoluntarily-retired</a>); if it is not, 2.0 will likely be tagged (if 2.0.1 is approved) as superseded, like these licenses: <a class="moz-txt-link-freetext" href="https://opensource.org/licenses?categories=superseded">https://opensource.org/licenses?categories=superseded</a> Same comment for the newer CNRI license versus the old one.</p> <p>I would suggest that someone from the Python community (if you aren't one already) do the submission, if that result is indeed desired. The review process requirements are in the link above.</p> <p>*This is no commentary on the approvability of the 2.0.1. or new CNRI license, which I haven't read, but just a general comment on how the result you want might be accomplished.</p> <p>McCoy Smith</p> <div class="moz-cite-prefix">On 3/16/2026 5:46 PM, Pamela Chestek wrote:<br> </div> <blockquote type="cite" cite="mid:[email protected]"> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <p>I don't see a reason. The OSI generally only reacts to requests for license approval, it doesn't generally approve licenses without them being submitted. I'm assuming it hasn't be approved just because no one has asked for it before.</p> <p>Pam</p> <div class="moz-signature">Pamela S. Chestek<br> Chestek Legal<br> 4641 Post St.<br> Unit 4316<br> El Dorado Hills, CA 95762<br> +1 919-800-8033<br> <a class="moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:[email protected]" moz-do-not-send="true">[email protected]</a><br> <a class="moz-txt-link-abbreviated" href="http://www.chesteklegal.com" moz-do-not-send="true">www.chesteklegal.com</a><br> <br> <br> </div> <div class="moz-cite-prefix">On 3/6/2026 5:47 AM, Max Mehl wrote:<br> </div> <blockquote type="cite" cite="mid:AS8PR06MB75279CEF1A80B85B3707BCA5FB7AA@AS8PR06MB7527.eurprd06.prod.outlook.com"> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> Hi everyone,</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> As requested by Nick, I would like point to an ongoing discussion on Python licenses, affecting both OSI's and SPDX’s realms, and request OSI’s approval of two licenses.</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> As you know, the licensing history of Python is quite complex, and the current license consists of multiple other licenses representing the long history and the different “ownerships” of the project (CWI, CNRI, BeOpen, PSF). <a href="https://github.com/spdx/license-list-XML/issues/2197" data-outlook-id="c8d254e9-cda2-4b06-8db7-bce26d43e3bc" moz-do-not-send="true"> spdx/license-list-XML#2197</a> and an <a href="https://lists.spdx.org/g/Spdx-legal/topic/107252308" data-outlook-id="fe102278-b8de-497c-ada5-f66db752c1b7" moz-do-not-send="true"> email to spdx-legal@</a> describe a bunch of intertwined problems around the identifiers of components of Python licenses. Recently, OSI fixed some of those already, thanks!</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> Now, I wonder about the status of the license SPDX describes as <a href="https://spdx.org/licenses/Python-2.0.1.html" data-outlook-id="8715974d-cf48-4f8a-804a-70c055157f8c" moz-do-not-send="true"> Python-2.0.1</a>. IIRC, the main difference between <a href="https://spdx.org/licenses/Python-2.0.html" data-outlook-id="91fa97a6-11f5-41c0-87e0-e557e08fc45c" moz-do-not-send="true"> Python-2.0</a> and Python-2.0.1 is in the CNRI part, making it GPL compatible (the “Virginia clause”). SPDX lists this updated sub-part as <a href="https://spdx.org/licenses/CNRI-Python-GPL-Compatible.html" data-outlook-id="3567c9f9-2b49-47b0-81ea-244c5030e6b1" moz-do-not-send="true"> CNRI-Python-GPL-Compatible</a>, a successor of <a href="https://spdx.org/licenses/CNRI-Python.html" data-outlook-id="4e10b719-943a-4ba5-9168-f442c0eccf57" moz-do-not-send="true"> CNRI-Python</a>.</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> Since Python 1.6.1 and 2.0.1, Python releases have been licensed under Python-2.0.1 (and recently additionally 0BSD for its documentation), while Python-2.0 has only been used for Python 1.6 and 2.0. So modern CPython releases would probably be best described as being licensed under "Python-2.0.1 AND 0BSD". </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> But OSI only approved Python-2.0 as an Open Source license, as well as the old CNRI-Python part. This is why I suggest OSI to approve <b>Python-2.0.1</b> and <b>CNRI-Python-GPL-Compatible</b> as Open Source licenses, and mark Python-2.0 and CNRI-Python as superseded. Is there any reason not to?</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> Best,</div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> Max </div> <div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);"> <br> </div> <div id="ms-outlook-mobile-signature" style="color: inherit; background-color: inherit;"> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;">-- </span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;"><b>Max Mehl</b></span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;">Open Source / Supply Chain</span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;">Enterprise-Team Chief Technology Office (CTO)</span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;">DB Systel GmbH / Deutsche Bahn</span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;"><br> </span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;">Schedule a meeting: <a href="https://cal.com/mxmehl" data-outlook-id="4bf758be-12c8-40e6-b18a-99718d15ab49" style="margin-top: 0px; margin-bottom: 0px;" moz-do-not-send="true"> cal.com/mxmehl</a></span></p> <p class="MsoNormal" style="margin: 0cm; font-family: Aptos, sans-serif; font-size: 11pt;"> <span style="color: black;"><br> </span></p> </div> <br> <hr> <br> <a href="https://www.deutschebahn.com/pflichtangaben/20260305" moz-do-not-send="true">Pflichtangaben anzeigen</a><br> <br> Nähere Informationen zur Datenverarbeitung im DB-Konzern finden Sie hier: <a href="https://www.deutschebahn.com/de/konzern/datenschutz" moz-do-not-send="true" class="moz-txt-link-freetext"> https://www.deutschebahn.com/de/konzern/datenschutz</a> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <pre wrap="" class="moz-quote-pre">_______________________________________________ The opinions expressed in this email are those of the sender and not necessarily those of the Open Source Initiative. Official statements by the Open Source Initiative will be sent from an opensource.org email address. License-discuss mailing list <a class="moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:[email protected]" moz-do-not-send="true">[email protected]</a> <a class="moz-txt-link-freetext" href="http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org" moz-do-not-send="true">http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org</a> </pre> </blockquote> <br> <fieldset class="moz-mime-attachment-header"></fieldset> <pre wrap="" class="moz-quote-pre">_______________________________________________ The opinions expressed in this email are those of the sender and not necessarily those of the Open Source Initiative. Official statements by the Open Source Initiative will be sent from an opensource.org email address. License-discuss mailing list <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> <a class="moz-txt-link-freetext" href="http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org">http://lists.opensource.org/mailman/listinfo/license-discuss_lists.opensource.org</a> </pre> </blockquote> </body> </html> --------------r7VsYhvNu6Z2H6kDIfs6qSsw-- --===============3946896876793234027== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KVGhlIG9waW5p b25zIGV4cHJlc3NlZCBpbiB0aGlzIGVtYWlsIGFyZSB0aG9zZSBvZiB0aGUgc2VuZGVyIGFuZCBu b3QgbmVjZXNzYXJpbHkgdGhvc2Ugb2YgdGhlIE9wZW4gU291cmNlIEluaXRpYXRpdmUuIE9mZmlj aWFsIHN0YXRlbWVudHMgYnkgdGhlIE9wZW4gU291cmNlIEluaXRpYXRpdmUgd2lsbCBiZSBzZW50 IGZyb20gYW4gb3BlbnNvdXJjZS5vcmcgZW1haWwgYWRkcmVzcy4KCkxpY2Vuc2UtZGlzY3VzcyBt YWlsaW5nIGxpc3QKTGljZW5zZS1kaXNjdXNzQGxpc3RzLm9wZW5zb3VyY2Uub3JnCmh0dHA6Ly9s aXN0cy5vcGVuc291cmNlLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2xpY2Vuc2UtZGlzY3Vzc19saXN0 cy5vcGVuc291cmNlLm9yZwo= --===============3946896876793234027==--