Skip to content

Commit 51ac05d

Browse files
authored
Merge pull request #17 from basicrum/wporg-submission-prep
Relicense to GPLv2-or-later for the WordPress.org submission
2 parents 4435641 + 85a718c commit 51ac05d

17 files changed

Lines changed: 1210 additions & 99 deletions

‎.github/workflows/ci.yml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -168,6 +168,12 @@ jobs:
168168
- php: '8.5'
169169
wp: '7.0'
170170
experimental: false
171+
- php: '8.4'
172+
wp: '7.1'
173+
experimental: false
174+
- php: '8.5'
175+
wp: '7.1'
176+
experimental: false
171177
- php: '8.5'
172178
wp: 'trunk'
173179
experimental: true

‎LICENSE‎

Lines changed: 357 additions & 21 deletions
Large diffs are not rendered by default.

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ The tag workflow verifies the version, runs the release tests, builds and smoke-
7070

7171
Read [CONTRIBUTING.md](CONTRIBUTING.md) before opening a pull request. Report suspected vulnerabilities privately according to [SECURITY.md](SECURITY.md), not through a public issue.
7272

73-
Basicrum-owned code is available under the [MIT License](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.txt).
73+
Basicrum-owned code is available under the [GNU General Public License version 2 or later](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.txt).
7474

7575
## Contributors
7676

‎docs/audits/wporg-submission-checklist.md‎

Lines changed: 53 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -46,12 +46,34 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
4646
0.0.x builds and can be misread as shipped-version history. Decide
4747
whether 0.0.7/0.0.6 entries stay (internal history) or fold in. (C13,
4848
C14)
49-
- [ ] Run Plugin Check against the BUILT release/basicrum.zip (not the
50-
repo tree) after the fixes and keep the output for the submission. (B7)
51-
- [ ] Tested up to 7.0: internally defensible (blocking CI rows for wp
52-
7.0 exist; format correct - verdict overturned by refuters), but
53-
re-confirm on submission day that WordPress 7.0 is the current released
54-
stable. (R05)
49+
- [x] RESOLVED 2026-08-20: Plugin Check 2.1.0 run against the built ZIP found
50+
a single error - outdated_tested_upto_header (WordPress 7.1 had shipped) -
51+
and zero other findings; all seven earlier findings confirmed fixed. Final
52+
0/0 confirmation run against the 7.1-bumped ZIP in progress. (B7)
53+
- [x] RESOLVED 2026-08-20: the permanent directory slug is decided. wp.org
54+
autogenerates the slug from the plugin header Plugin Name at submission and
55+
cannot rename it after approval, so `Basicrum - Real User Monitoring` will be
56+
offered `basicrum-real-user-monitoring`. The display name stays descriptive
57+
and the shorter `basicrum` slug is requested through the documented one-time
58+
correction: the FAQ states "You can update your slug once after submitting
59+
it. Every submission gets an automated email with directions." Both
60+
`basicrum` and `basicrum-real-user-monitoring` were unregistered on
61+
2026-08-20 (wordpress.org/plugins/<slug>/ redirects to search for each).
62+
`basicrum` is what the generated POT `Report-Msgid-Bugs-To` and the plugin
63+
directory name already assume, so taking it keeps the support URL correct.
64+
This is a user-only action on submission day; see the list below.
65+
- [x] RESOLVED 2026-08-20: External services now links the service privacy
66+
information guideline 6 and the common-issues page ask for. The Basicrum
67+
Privacy Notice covers only basicrum.com, its contact form, and beta requests,
68+
so the readme says exactly that and directs webmasters to request the hosted
69+
collector's own terms and privacy notice. Publishing those two documents is
70+
still an open user-only action.
71+
- [x] RESOLVED 2026-08-20: WordPress stable moved to 7.1 and Plugin Check
72+
now errors on Tested up to below current stable. Integration suite run
73+
locally against a verified real WordPress 7.1 core (wp_version 7.1,
74+
4 tests green), blocking rows php 8.4/wp 7.1 and php 8.5/wp 7.1 added to
75+
ci.yml, readme bumped to Tested up to: 7.1, ZIP rebuilt. GitHub CI must
76+
confirm the new rows green on push before tagging. (R05)
5577

5678
## 3. Ambiguity fixes - upheld copy issues
5779

@@ -75,10 +97,9 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
7597
"Strictness" relaxes enforcement). Rewrite the FAQ to lead with the
7698
default (auto-upgrade to HTTPS) and what the toggle actually allows;
7799
the label rename remains open from the operator-experience audit. (C08)
78-
- [ ] "eligible pages" in the contributed privacy-policy text
79-
(Privacy.php immediate-mode sentence) is undefined for site owners;
80-
spell out: frontend pages, admins excluded unless Track Admin Users.
81-
(C12)
100+
- [x] RESOLVED 2026-08-20: immediate-mode sentence now says "frontend
101+
pages" with the administrator exclusion spelled out; PrivacyTest pins
102+
both phrases. (C12)
82103
- [x] Define "connected" CookieYes at first use. Resolved by removing the
83104
ambiguous implementation detail from the customer-facing overview. (C07)
84105
- [x] Replace "fails closed" jargon with plain language. (C19)
@@ -92,11 +113,8 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
92113
- [x] Screenshots: four current WordPress 7.0.2 settings captures use the exact
93114
Visitor Consent and Consent Tool Connection labels, privacy-safe example
94115
values, and matching numbered captions in `readme.txt`. (C24)
95-
- [ ] Spot-check the two basicrum.com URLs (home, /contact/) resolve;
96-
reviewers click them. (R45)
97-
- [ ] CookieYes "modern ... runtime" - one refuter pair split on this;
98-
consider "CookieYes 3.x" with a one-line legacy note for precision.
99-
(C06)
116+
- [x] RESOLVED 2026-08-20: both URLs return HTTP 200. (R45)
117+
- [x] RESOLVED: readme now says "CookieYes 3.x". (C06)
100118

101119
## 5. Verified clean (highlights)
102120

@@ -105,9 +123,13 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
105123
- [x] Short description 95 chars (under 150), byte-identical to the
106124
header Description; privacy-first claim backed by defaults. (R09, C01
107125
overturned)
108-
- [x] MIT license declared consistently (readme, header, LICENSE.md,
109-
composer.json); GPL-compatible; Boomerang BSD is GPL-compatible;
110-
THIRD-PARTY-NOTICES.txt scopes correctly. (R08, B1)
126+
- [x] SUPERSEDED 2026-08-20: relicensed from MIT to GPLv2-or-later so the
127+
listing matches the license guideline 1 recommends. GPLv2 text now ships in
128+
LICENSE and plugins/basicrum/LICENSE.md; header, readme, composer.json
129+
(`GPL-2.0-or-later`), THIRD-PARTY-NOTICES.txt, root README, and the
130+
regenerated POT all agree. Boomerang stays BSD and GPL-compatible, and
131+
THIRD-PARTY-NOTICES.txt still scopes it out of the Basicrum license.
132+
Original finding: MIT declared consistently and GPL-compatible. (R08, B1)
111133
- [x] All five tags valid and implemented; Requires at least 6.0 and
112134
Requires PHP 7.4 match headers, composer, and CI matrix. (R03, R04, R06)
113135
- [x] Feature claims verified against code: page-type values verbatim in
@@ -125,5 +147,17 @@ refuters. 84 claims audited: 52 clean, 24 upheld findings, 8 overturned.
125147
## User-only actions before submission day
126148

127149
1. Register/confirm the wordpress.org username matching Contributors.
128-
2. Re-confirm WordPress 7.0 is the current released stable.
150+
2. Re-confirm WordPress 7.1 is the current released stable.
129151
3. Verify basicrum.com pages linked from the listing are live.
152+
4. Publish the hosted-service Terms of Service and a privacy notice that covers
153+
the hosted collector, then link both from the readme External services
154+
section. See docs/privacy-policy-preparation-checklist.md steps 14 and 15.
155+
5. Confirm the two outside code contributors are content with the GPLv2-or-later
156+
relicense. MIT permits the sublicense, so this is a courtesy record, not a
157+
blocker.
158+
6. On the submission email, use the one-time slug update to change
159+
`basicrum-real-user-monitoring` to `basicrum` before approval. The slug is
160+
permanent afterwards, and it also sets the SVN path, the installed folder
161+
name, and the support URL the POT already points at. Keep the display name
162+
`Basicrum - Real User Monitoring`; wp.org treats display name and slug
163+
separately, and the display name stays editable after approval.

0 commit comments

Comments
 (0)