Skip to content

chore: add SPDX copyright attribution and a NOTICE file - #317

Merged
re-gius merged 1 commit into
masterfrom
chore/spdx-copyright
Sep 23, 2026
Merged

re-gius merged 1 commit into
masterfrom
chore/spdx-copyright

Conversation

@re-gius

@re-gius re-gius commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Description

Aligns the repository with the legal guidelines for open source attribution.

  • Every Parity-authored contract gains one line under its SPDX identifier: SPDX-FileCopyrightText: © 2026 Parity Technologies. A contract file travels alone through explorers and vendoring, and carried a license identifier with no copyright holder to preserve; SPDX-FileCopyrightText is the REUSE-standard field for this, so coverage stays machine-checkable.
  • Vendored third-party code keeps its own notices: contracts/external/ (authoritative SPDX headers) and contracts/utils/Multicall3.sol (mds1/multicall3, MIT) carry no Parity line.
  • A NOTICE file records the project copyright, the MIT license pointer, and the third-party attributions; the README's license section now points at it.

Comment-only for the contracts: bytecode, ABIs, and storage layouts are unchanged.

Type

  • Bug fix
  • Feature
  • Breaking change
  • Documentation
  • Chore
  • Refactor
  • Security

Scope

  • Registration
  • Resolver
  • Store
  • Proof of Personhood
  • Deployment scripts
  • Tests

Related Issues

Fixes

Checklist

Code

  • Follows project style
  • forge build passes
  • forge test passes
  • No new compiler warnings

Testing

  • New tests added for changed behavior
  • Fuzz tests added where applicable
  • Invariant tests verified

Security

  • No new selfdestruct or delegatecall
  • Access control reviewed
  • No storage layout conflicts (for upgradeable contracts)

Documentation

  • NatSpec updated on changed interfaces
  • README updated if needed

Breaking Changes

  • No breaking changes
  • Breaking changes documented below

Breaking changes:

How to test

grep -rL "SPDX-FileCopyrightText" contracts --include='*.sol' | grep -v external

Prints only contracts/utils/Multicall3.sol, the vendored file that keeps its original authors' notice.

Notes

The added lines change each file's compiler metadata hash and nothing else. Release tooling strips metadata before comparing codehashes, so codehashes.json and the deployed-bytecode checks are unaffected.

@re-gius
re-gius requested a review from a team as a code owner September 22, 2026 13:16
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

CI Summary

Check Result
4naly3er Analysis Found 38 issues: 5 medium, 8 low, 13 gas, 12 informational - View Report
Slither Analysis Found 193 issues: 4 high, 40 medium, 90 low, 59 informational - View Report
Contract Tests (Unit + Fuzz) All tests passed (681 total) - View Report
Contract Tests (Invariant) All tests passed (58 total) - View Report
Gas Report 9 contracts analyzed - View Report
Coverage Failed - Tests failed, cannot compute coverage
Documentation Passed - 66 pages generated - View Docs
Format & Lint Passed - Code formatted correctly
File Validation Passed - All tracked files valid
Deploy Contracts Reproduces the expected address set; resume verified
PR Title PR Title Valid
Labels Unknown
Secret Scan Passed - No secrets detected

@re-gius
re-gius merged commit bcfec88 into master Sep 23, 2026
25 checks passed
@re-gius
re-gius deleted the chore/spdx-copyright branch September 23, 2026 06:31
github-actions Bot added a commit that referenced this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants