From 5a531c70580202a990dfa1013dc6a89351e3cfe6 Mon Sep 17 00:00:00 2001 From: Chris Fuka Date: Thu, 6 Aug 2026 15:17:58 -0500 Subject: [PATCH 1/4] chore(legal): relicense to MIT and add PATENTS notice Replace the Microsoft Reference Source License with the unmodified MIT License, and update the README badge and License section accordingly. Add PATENTS, listing all 49 patent families licensed to Spice Solutions Inc. by CodeOn. MIT grants copyright permissions only and grants no patent rights, so the notice matters more here than in the source-available repositories: recipients should not read MIT as conferring patent peace. Ship PATENTS in the container image alongside the LICENSE, NOTICE and THIRD-PARTY-NOTICES.md that are already copied to /usr/share/doc/optimum-gateway/. --- Dockerfile | 4 +- LICENSE | 50 ++++++++++-------------- NOTICE | 3 ++ PATENTS | 112 +++++++++++++++++++++++++++++++++++++++++++++++++++++ README.md | 12 +++++- 5 files changed, 148 insertions(+), 33 deletions(-) create mode 100644 PATENTS diff --git a/Dockerfile b/Dockerfile index 8281d5f..e247af1 100644 --- a/Dockerfile +++ b/Dockerfile @@ -62,8 +62,8 @@ RUN mkdir -p /gateway/logs COPY --from=builder /gateway/optimum-gateway /optimum-gateway -# License and third-party attribution shipped alongside the binary. -COPY --from=builder /optimum-gateway/LICENSE /optimum-gateway/NOTICE /optimum-gateway/THIRD-PARTY-NOTICES.md /usr/share/doc/optimum-gateway/ +# License, patent marking and third-party attribution shipped with the binary. +COPY --from=builder /optimum-gateway/LICENSE /optimum-gateway/NOTICE /optimum-gateway/PATENTS /optimum-gateway/THIRD-PARTY-NOTICES.md /usr/share/doc/optimum-gateway/ # USER gateway diff --git a/LICENSE b/LICENSE index 0f00165..cae9e6f 100644 --- a/LICENSE +++ b/LICENSE @@ -1,29 +1,21 @@ -Microsoft Reference Source License (Ms-RSL) - -Copyright (c) 2025-2026 Spice Solutions Inc. ("Optimum") - -This license governs use of the accompanying software. If you use the software, you accept this license. If you do not accept the license, do not use the software. - -1. Definitions -The terms "reproduce," "reproduction" and "distribution" have the same meaning here as under U.S. copyright law. - -"You" means the licensee of the software. - -"Your company" means the company you worked for when you downloaded the software. - -"Reference use" means use of the software within your company as a reference, in read only form, for the sole purposes of debugging your products, maintaining your products, or enhancing the interoperability of your products with the software, and specifically excludes the right to distribute the software outside of your company. - -"Licensed patents" means any Licensor patent claims which read directly on the software as distributed by the Licensor under this license. - -2. Grant of Rights -(A) Copyright Grant- Subject to the terms of this license, the Licensor grants you a non-transferable, non-exclusive, worldwide, royalty-free copyright license to reproduce the software for reference use. - -(B) Patent Grant- Subject to the terms of this license, the Licensor grants you a non-transferable, non-exclusive, worldwide, royalty-free patent license under licensed patents for reference use. - -3. Limitations -(A) No Trademark License- This license does not grant you any rights to use the Licensor's name, - logo, or trademarks. - -(B) If you begin patent litigation against the Licensor over patents that you think may apply to the software (including a cross-claim or counterclaim in a lawsuit), your license to the software ends automatically. - -(C) The software is licensed "as-is." You bear the risk of using it. The Licensor gives no express warranties, guarantees or conditions. You may have additional consumer rights under your local laws which this license cannot change. To the extent permitted under your local laws, the Licensor excludes the implied warranties of merchantability, fitness for a particular purpose and non-infringement. +MIT License + +Copyright (c) 2025-2026 Spice Solutions Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/NOTICE b/NOTICE index 63aebef..01cd478 100644 --- a/NOTICE +++ b/NOTICE @@ -6,6 +6,9 @@ dependencies and their licenses is in THIRD-PARTY-NOTICES.md. The attribution notices required by those dependencies (Apache-2.0 ยง4(d) and the NOTICE files it references) are reproduced below. +Patents applicable to this software are listed in the accompanying PATENTS file. +This software is licensed under the MIT License, which grants no patent rights. + ================================================================================ github.com/prometheus/client_golang (Apache-2.0) ================================================================================ diff --git a/PATENTS b/PATENTS new file mode 100644 index 0000000..a73605a --- /dev/null +++ b/PATENTS @@ -0,0 +1,112 @@ +PATENTS +======= + +The Software may be covered by one or more of the patents and patent +applications listed below, which are licensed to Spice Solutions Inc. (the +"Licensor") by CodeOn. This repository is distributed alongside that +technology. + +This list is published for notice purposes only. It is not an offer or grant +of any license, immunity or other right under any listed patent, and it is not +a representation that any listed right is in force or is necessarily practiced +in operating the Software. + + Patent licensor: CodeOn + Licensee: Spice Solutions Inc. (the "Licensor") + Last updated: 2026-08-06 + + +GRANTED PATENTS + +United States (US) + US 7,414,978 US 7,706,365 US 8,046,426 US 8,068,426 + US 8,102,837 US 8,130,776 US 8,279,781 US 8,451,756 + US 8,473,998 US 8,526,451 US 8,571,214 US 8,780,693 + US 8,918,902 US 9,019,643 US 9,025,607 US 9,130,742 + US 9,137,492 US 9,143,274 US 9,148,173 US 9,148,291 + US 9,160,440 US 9,160,687 US 9,185,529 US 9,191,371 + US 9,203,441 US 9,253,608 US 9,271,123 US 9,361,936 + US 9,369,255 US 9,369,275 US 9,369,541 US 9,531,780 + US 9,537,759 US 9,544,126 US 9,544,136 US 9,559,831 + US 9,607,003 US 9,632,829 US 9,647,800 US 9,699,104 + US 9,762,957 US 9,787,614 US 9,800,643 US 9,860,022 + US 9,877,265 US 9,923,669 US 9,923,714 US 9,979,666 + US 9,998,406 US 10,009,259 US 10,027,399 US 10,028,198 + US 10,243,692 US 10,311,243 US 10,452,621 US 10,530,574 + US 10,541,932 US 10,554,569 US 10,735,515 US 10,756,843 + US 10,872,072 US 11,025,600 US 11,063,878 US 11,070,484 + US 11,108,705 US 11,126,595 US 11,226,951 US 11,381,339 + US 11,418,449 US 11,424,861 US 11,463,113 US 11,463,372 + US 11,489,761 US 11,678,247 US 12,261,949 + +European Patent Office (EP) + A European patent takes effect as a national patent in each state where it + is validated. The states shown are those on the licensed schedule. + EP 2550806 B1 (DE, ES, FR, GB, NL) + EP 2774304 B1 (DE, ES, FR, GB, NL) + EP 2810180 B1 (DE, FR, GB, IT, NL) + EP 2873197 B1 (DE, ES, FR, GB, NL) + EP 2962428 B1 + EP 2972751 B1 (DE, FR, GB, IT, PL) + EP 2972864 B1 (DE, FR, GB, IT, PL) + EP 2972957 B1 (DE, ES, FR, GB, PL) + EP 2974087 B1 (DE, FR, GB, IT, NL) + EP 2974297 B1 (DE, FR, GB, IT, NL) + EP 3117546 B1 (DE, ES, FR, GB, NL) + EP 3257207 B1 (DE, ES, FR, GB, NL) + EP 3408956 B1 (DE, FR, GB, IT, NL) + EP 3602871 B1 + EP 3631641 B1 + EP 3794755 B1 + EP 3909160 B1 (DE, ES, FR, GB, NL) + EP 4140116 B1 + EP 4140117 B1 + +China (CN) + CN 105144075 B CN 105144722 B CN 105229624 B CN 106464432 B + CN 107210970 B CN 108432170 B CN 110651262 B CN 113728572 B + CN 115486042 B CN 115486043 B + +Japan (JP) + JP 6106327 B2 JP 6272451 B2 JP 6286019 B2 JP 6576324 B2 + JP 7850138 B2 + +Republic of Korea (KR) + KR 101777032 B1 KR 101813348 B1 + + +EXPIRED OR LAPSED + +These rights were granted but their term has ended, or they lapsed for +non-payment. They are listed for completeness because they remain on the +licensed schedule, and are separated here so that nothing above is taken as +marking with a right that is no longer in force. + +United States (US) + US 7,394,762 US 8,375,102 US 9,165,013 US 9,680,928 + +Republic of Korea (KR) + KR 101778424 B1 + + +FILINGS WITH NO CONFIRMED GRANT NUMBER + +These filings are on the licensed schedule but are not granted patents. Each +is identified by its publication number where one has issued, otherwise by +application number. + +United States (US) + US 16/832,660 + +European Patent Office (EP) + EP 18807805.9 EP 4205345 A1 + +China (CN) + CN 105359113 A CN 116018778 A CN 201880022130 CN 201880031064 + CN 201880068242 + +Republic of Korea (KR) + KR 10-2023-0058685 A + +India (IN) + IN 201947051525 A diff --git a/README.md b/README.md index e17ab08..3d51461 100644 --- a/README.md +++ b/README.md @@ -10,7 +10,7 @@ [![Coverage](https://img.shields.io/badge/coverage-%E2%89%A571%25-green)](Makefile) [![Docker image](https://img.shields.io/docker/v/getoptimum/gateway?label=docker&sort=semver)](https://hub.docker.com/r/getoptimum/gateway) [![Kurtosis Readiness](https://github.com/getoptimum/optimum-gateway/actions/workflows/optimum-package.yml/badge.svg)](https://github.com/getoptimum/optimum-gateway/actions/workflows/optimum-package.yml) -[![License](https://img.shields.io/badge/License-Ms--RSL-blue)](./LICENSE) +[![License](https://img.shields.io/badge/License-MIT-blue)](./LICENSE) # Optimum Gateway @@ -213,4 +213,12 @@ See [`docs/contributing.md`](docs/contributing.md). Please run `make lint` and ## License -Source is provided under the **Microsoft Reference Source License (Ms-RSL)** for reference use only: see [`LICENSE`](./LICENSE). +Source is provided under the **MIT License**: see [`LICENSE`](./LICENSE). + +The MIT License grants copyright permissions only and grants no rights under any +patent. [`PATENTS`](./PATENTS) lists patents and patent applications licensed to +Spice Solutions Inc. by CodeOn; operating this software may involve practicing +patented technology, and any patent rights you require must be obtained from the +relevant patent holder directly. Third-party dependencies are inventoried in +[`THIRD-PARTY-NOTICES.md`](./THIRD-PARTY-NOTICES.md) with attributions in +[`NOTICE`](./NOTICE). From ec956adf2f70d33c983a1d9756710b32a89eeab0 Mon Sep 17 00:00:00 2001 From: optimum-sbom-bot Date: Thu, 6 Aug 2026 23:22:30 +0000 Subject: [PATCH 2/4] chore: refresh generated artifacts --- docs/sbom-full.json | 11 ++++++++++- docs/sbom.json | 11 ++++++++++- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/docs/sbom-full.json b/docs/sbom-full.json index 20cfc16..dfc07a6 100644 --- a/docs/sbom-full.json +++ b/docs/sbom-full.json @@ -32,7 +32,16 @@ "url": "https://github.com/getoptimum/optimum-gateway", "type": "vcs" } - ] + ], + "evidence": { + "licenses": [ + { + "license": { + "id": "MIT" + } + } + ] + } } }, "components": [ diff --git a/docs/sbom.json b/docs/sbom.json index e64893e..59e0138 100644 --- a/docs/sbom.json +++ b/docs/sbom.json @@ -46,7 +46,16 @@ "name": "cdx:gomod:build:env:GOOS", "value": "linux" } - ] + ], + "evidence": { + "licenses": [ + { + "license": { + "id": "MIT" + } + } + ] + } } }, "components": [ From 1c067ed5addeb835a100bbc5ed54255b3ceddcdb Mon Sep 17 00:00:00 2001 From: Chris Fuka Date: Thu, 6 Aug 2026 18:35:43 -0500 Subject: [PATCH 3/4] chore(legal): drop expired and lapsed rights from PATENTS A marking notice advertises live rights. Listing rights whose term has ended, or that lapsed for non-payment, is the fact pattern false-marking claims are built on, so they are removed rather than shown in a separate section. --- PATENTS | 14 -------------- 1 file changed, 14 deletions(-) diff --git a/PATENTS b/PATENTS index a73605a..284534f 100644 --- a/PATENTS +++ b/PATENTS @@ -75,20 +75,6 @@ Republic of Korea (KR) KR 101777032 B1 KR 101813348 B1 -EXPIRED OR LAPSED - -These rights were granted but their term has ended, or they lapsed for -non-payment. They are listed for completeness because they remain on the -licensed schedule, and are separated here so that nothing above is taken as -marking with a right that is no longer in force. - -United States (US) - US 7,394,762 US 8,375,102 US 9,165,013 US 9,680,928 - -Republic of Korea (KR) - KR 101778424 B1 - - FILINGS WITH NO CONFIRMED GRANT NUMBER These filings are on the licensed schedule but are not granted patents. Each From ee8190f9ca4e8906e29a4a9be00551a730a14b26 Mon Sep 17 00:00:00 2001 From: Chris Fuka Date: Thu, 6 Aug 2026 22:30:45 -0500 Subject: [PATCH 4/4] docs(security): retarget safe harbor from Ms-RSL to MIT The safe harbor was written around Ms-RSL granting only read-only reference use, so it had to add permission to build and run the software. MIT already grants that, making the permission redundant. More importantly, the closing paragraph withheld the right to distribute, create derivative works, and use in production. MIT grants all three, so that text contradicted the LICENSE and read as clawing back rights. Reframed as what a safe harbor is actually for: an authorization and non-prosecution assurance for security testing, which no copyright license addresses. The good-faith conditions are unchanged. --- SECURITY.md | 22 +++++++++------------- 1 file changed, 9 insertions(+), 13 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index e3a47a6..75ca349 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -16,15 +16,13 @@ When reporting, include: ## Security research safe harbor -We welcome good-faith security research. The source in this repository is -licensed under the Microsoft Reference Source License (Ms-RSL), which by itself -grants only reference (read-only) use. This section adds a separate, limited -permission so that security testing is clearly authorized. +We welcome good-faith security research. The [`LICENSE`](./LICENSE) already +permits you to build, run and modify this software, so no extra permission is +needed for that. What this section does is define what we treat as good-faith +research, so the assurance below is unambiguous. -Notwithstanding the terms of the [`LICENSE`](./LICENSE), Spice Solutions Inc. -("Optimum") grants any person a non-exclusive, revocable permission to access, -reproduce, build, run, and test the software solely to identify and responsibly -report security vulnerabilities, provided that you: +We will treat security testing as authorized access, and Spice Solutions Inc. +("Optimum") will not pursue legal action for it, provided that you: - act in good faith and avoid privacy violations, data destruction, and degradation of others' services; @@ -36,11 +34,9 @@ report security vulnerabilities, provided that you: - give us a reasonable opportunity to remediate before any public disclosure (see below), and do not exploit a finding beyond what is needed to prove it. -This permission is limited to security research. It grants no right to -distribute the software, create or distribute derivative works, or use the -software in production, all of which remain governed by the `LICENSE` and any -commercial agreement with Optimum. Optimum may revoke this permission for -conduct outside its scope. +This assurance concerns security research only. It is not a waiver of any other +right, and Optimum may withdraw it for conduct outside the scope above. Your +rights in the software itself are governed by the [`LICENSE`](./LICENSE). ### Coordinated disclosure