Skip to content

Commit 046be65

Browse files
ceckoslabclaude
andcommitted
Relicense to GPLv2-or-later for the WordPress.org submission
Relicense Basicrum-owned code from MIT to GPLv2-or-later, the license the plugin directory recommends. MIT was already GPL-compatible and acceptable, so this removes doubt rather than a blocker. The GPLv2 text ships in LICENSE and plugins/basicrum/LICENSE.md, and the plugin header, readme.txt, composer.json, THIRD-PARTY-NOTICES.txt, the root README, and the generated POT all declare it. Bundled Boomerang keeps its BSD license and stays scoped out of the Basicrum license. Link the service privacy information the directory's external-services guidance asks for. The Basicrum Privacy Notice covers only basicrum.com, its contact form, and beta requests, so the readme says exactly that instead of implying it covers the hosted collector, and points webmasters at the collector operator's own terms. Drop composer/installers from the release package. It only positions this package when a Composer project installs it as a dependency and has no role inside an installed plugin, so the build removes it from the staged tree and then restores the repository manifest, leaving the shipped vendor directory, class map, and Composer metadata in agreement. The archive goes from 146 files to 44 and the authoritative class map from 110 entries to 11. verify-release.sh now guards both. Also carries the pending working-tree changes for the same submission: the Tested up to 7.1 bump with its blocking CI rows, the immediate-mode privacy wording, and the submission and privacy-policy checklists. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 4435641 commit 046be65

16 files changed

Lines changed: 1187 additions & 76 deletions

‎.github/workflows/ci.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -168,6 +168,12 @@ jobs:
168168
- php: '8.5'
169169
wp: '7.0'
170170
experimental: false
171+
- php: '8.4'
172+
wp: '7.1'
173+
experimental: false
174+
- php: '8.5'
175+
wp: '7.1'
176+
experimental: false
171177
- php: '8.5'
172178
wp: 'trunk'
173179
experimental: true

‎LICENSE‎

Lines changed: 357 additions & 21 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ The tag workflow verifies the version, runs the release tests, builds and smoke-
7070

7171
Read [CONTRIBUTING.md](CONTRIBUTING.md) before opening a pull request. Report suspected vulnerabilities privately according to [SECURITY.md](SECURITY.md), not through a public issue.
7272

73-
Basicrum-owned code is available under the [MIT License](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.txt).
73+
Basicrum-owned code is available under the [GNU General Public License version 2 or later](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.txt).
7474

7575
## Contributors
7676

‎docs/audits/wporg-submission-checklist.md‎

Lines changed: 53 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -46,12 +46,34 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
4646
0.0.x builds and can be misread as shipped-version history. Decide
4747
whether 0.0.7/0.0.6 entries stay (internal history) or fold in. (C13,
4848
C14)
49-
- [ ] Run Plugin Check against the BUILT release/basicrum.zip (not the
50-
repo tree) after the fixes and keep the output for the submission. (B7)
51-
- [ ] Tested up to 7.0: internally defensible (blocking CI rows for wp
52-
7.0 exist; format correct - verdict overturned by refuters), but
53-
re-confirm on submission day that WordPress 7.0 is the current released
54-
stable. (R05)
49+
- [x] RESOLVED 2026-08-20: Plugin Check 2.1.0 run against the built ZIP found
50+
a single error - outdated_tested_upto_header (WordPress 7.1 had shipped) -
51+
and zero other findings; all seven earlier findings confirmed fixed. Final
52+
0/0 confirmation run against the 7.1-bumped ZIP in progress. (B7)
53+
- [x] RESOLVED 2026-08-20: the permanent directory slug is decided. wp.org
54+
autogenerates the slug from the plugin header Plugin Name at submission and
55+
cannot rename it after approval, so `Basicrum - Real User Monitoring` will be
56+
offered `basicrum-real-user-monitoring`. The display name stays descriptive
57+
and the shorter `basicrum` slug is requested through the documented one-time
58+
correction: the FAQ states "You can update your slug once after submitting
59+
it. Every submission gets an automated email with directions." Both
60+
`basicrum` and `basicrum-real-user-monitoring` were unregistered on
61+
2026-08-20 (wordpress.org/plugins/<slug>/ redirects to search for each).
62+
`basicrum` is what the generated POT `Report-Msgid-Bugs-To` and the plugin
63+
directory name already assume, so taking it keeps the support URL correct.
64+
This is a user-only action on submission day; see the list below.
65+
- [x] RESOLVED 2026-08-20: External services now links the service privacy
66+
information guideline 6 and the common-issues page ask for. The Basicrum
67+
Privacy Notice covers only basicrum.com, its contact form, and beta requests,
68+
so the readme says exactly that and directs webmasters to request the hosted
69+
collector's own terms and privacy notice. Publishing those two documents is
70+
still an open user-only action.
71+
- [x] RESOLVED 2026-08-20: WordPress stable moved to 7.1 and Plugin Check
72+
now errors on Tested up to below current stable. Integration suite run
73+
locally against a verified real WordPress 7.1 core (wp_version 7.1,
74+
4 tests green), blocking rows php 8.4/wp 7.1 and php 8.5/wp 7.1 added to
75+
ci.yml, readme bumped to Tested up to: 7.1, ZIP rebuilt. GitHub CI must
76+
confirm the new rows green on push before tagging. (R05)
5577

5678
## 3. Ambiguity fixes - upheld copy issues
5779

@@ -75,10 +97,9 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
7597
"Strictness" relaxes enforcement). Rewrite the FAQ to lead with the
7698
default (auto-upgrade to HTTPS) and what the toggle actually allows;
7799
the label rename remains open from the operator-experience audit. (C08)
78-
- [ ] "eligible pages" in the contributed privacy-policy text
79-
(Privacy.php immediate-mode sentence) is undefined for site owners;
80-
spell out: frontend pages, admins excluded unless Track Admin Users.
81-
(C12)
100+
- [x] RESOLVED 2026-08-20: immediate-mode sentence now says "frontend
101+
pages" with the administrator exclusion spelled out; PrivacyTest pins
102+
both phrases. (C12)
82103
- [x] Define "connected" CookieYes at first use. Resolved by removing the
83104
ambiguous implementation detail from the customer-facing overview. (C07)
84105
- [x] Replace "fails closed" jargon with plain language. (C19)
@@ -92,11 +113,8 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
92113
- [x] Screenshots: four current WordPress 7.0.2 settings captures use the exact
93114
Visitor Consent and Consent Tool Connection labels, privacy-safe example
94115
values, and matching numbered captions in `readme.txt`. (C24)
95-
- [ ] Spot-check the two basicrum.com URLs (home, /contact/) resolve;
96-
reviewers click them. (R45)
97-
- [ ] CookieYes "modern ... runtime" - one refuter pair split on this;
98-
consider "CookieYes 3.x" with a one-line legacy note for precision.
99-
(C06)
116+
- [x] RESOLVED 2026-08-20: both URLs return HTTP 200. (R45)
117+
- [x] RESOLVED: readme now says "CookieYes 3.x". (C06)
100118

101119
## 5. Verified clean (highlights)
102120

@@ -105,9 +123,13 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
105123
- [x] Short description 95 chars (under 150), byte-identical to the
106124
header Description; privacy-first claim backed by defaults. (R09, C01
107125
overturned)
108-
- [x] MIT license declared consistently (readme, header, LICENSE.md,
109-
composer.json); GPL-compatible; Boomerang BSD is GPL-compatible;
110-
THIRD-PARTY-NOTICES.txt scopes correctly. (R08, B1)
126+
- [x] SUPERSEDED 2026-08-20: relicensed from MIT to GPLv2-or-later so the
127+
listing matches the license guideline 1 recommends. GPLv2 text now ships in
128+
LICENSE and plugins/basicrum/LICENSE.md; header, readme, composer.json
129+
(`GPL-2.0-or-later`), THIRD-PARTY-NOTICES.txt, root README, and the
130+
regenerated POT all agree. Boomerang stays BSD and GPL-compatible, and
131+
THIRD-PARTY-NOTICES.txt still scopes it out of the Basicrum license.
132+
Original finding: MIT declared consistently and GPL-compatible. (R08, B1)
111133
- [x] All five tags valid and implemented; Requires at least 6.0 and
112134
Requires PHP 7.4 match headers, composer, and CI matrix. (R03, R04, R06)
113135
- [x] Feature claims verified against code: page-type values verbatim in
@@ -125,5 +147,17 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
125147
## User-only actions before submission day
126148

127149
1. Register/confirm the wordpress.org username matching Contributors.
128-
2. Re-confirm WordPress 7.0 is the current released stable.
150+
2. Re-confirm WordPress 7.1 is the current released stable.
129151
3. Verify basicrum.com pages linked from the listing are live.
152+
4. Publish the hosted-service Terms of Service and a privacy notice that covers
153+
the hosted collector, then link both from the readme External services
154+
section. See docs/privacy-policy-preparation-checklist.md steps 14 and 15.
155+
5. Confirm the two outside code contributors are content with the GPLv2-or-later
156+
relicense. MIT permits the sublicense, so this is a courtesy record, not a
157+
blocker.
158+
6. On the submission email, use the one-time slug update to change
159+
`basicrum-real-user-monitoring` to `basicrum` before approval. The slug is
160+
permanent afterwards, and it also sets the SVN path, the installed folder
161+
name, and the support URL the POT already points at. Keep the display name
162+
`Basicrum - Real User Monitoring`; wp.org treats display name and slug
163+
separately, and the display name stays editable after approval.

0 commit comments

Comments
 (0)