Re: My suggestions on auditing that services are running free software
Konstantin Ryabitsev <[email protected]> Fri, 22 Mar 2024 11:57:38 -0400
| Newsgroups | org.linuxfoundation.lists.cti-tac |
|---|---|
| Message-ID | <20240322-bipedal-nostalgic-adder-fec630@lemur> |
On Fri, Mar 22, 2024 at 04:35:13AM -0400, Ian Kelling wrote: > I suggest that CTI come up with a proposal/plan for how to implement the > audit. Eg, checking what software is being run and that users are able > to download a copy and that it is free software. The FSF will be > available to review the proposal. Before we go down that route, please note that LF IT does not provide backend access to third parties, so any audit plans will be limited to auditing documentation. We, of course, comply with licensing terms, so any AGPL-licensed software (such as public-inbox) is available for download (we run the upstream version without any modifications). Any free software without such requirement may have basic version info, not necessarily down to the exact patch level. For example, I doubt anyone benefits from knowing the exact version of Postfix used to send this mailing list message. Best regards, Konstantin