Licences
A public repository is not a grant.
The constructor classifies. It does not replace counsel. No record is marked public domain.
| Tier | Constructor rule |
|---|---|
| Green | MIT, BSD, or Apache-style terms where the grant was actually detected. Keep notices. Still not an audit. |
| Amber | LGPL, mixed files, dual licences with a carve-out, or a repository whose maintainer just moved. Legal review before you copy. |
| Red | GPL, or a custom licence such as the WalletConnect community agreement checked in this release. Reference only. |
| Grey | No single SPDX grant. Hardhat is the example: each package has its own file. |
The full matrix, including what this release will not export, is the export policy. GitHub’s licence API was the starting point. Where it returned NOASSERTION, the licence file was read. That is still not a finding that every dependency inside the repository is clean.
