tag: Licensing · 4 items
- Platform/SRE — Skip
- CI/CD — Learn: GitHub’s dependency graph now pulls license data from npm and PyPI registries, improving accuracy of license visibility in repos — useful context if your supply-chain compliance workflow relies on GitHub’s license detection.
- Leader — Learn: More accurate license metadata in GitHub’s dependency graph reduces the risk of unknowingly shipping components with incompatible licenses — worth noting if the org uses GitHub for license compliance reviews.
- Platform/SRE — Plan: The updated ToS may restrict how the Terraform Registry can be consumed, particularly by tooling or automation that competes with or mirrors registry content. Review current Terraform and provider-download patterns against the new terms and evaluate whether a migration to OpenTofu or a self-hosted registry should be scoped this quarter.
- CI/CD — Learn: Pipelines that pull Terraform providers and modules via the public registry could be indirectly affected if the new ToS introduces usage restrictions on automated clients; worth monitoring, but no concrete pipeline action is required yet.
- Leader — Plan: A ToS change on a registry that most Terraform-standardized orgs depend on is a direct vendor-risk signal; evaluate whether current registry consumption falls under any newly restricted terms and assess OpenTofu as a contingency before any enforcement timeline is announced.
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Plan: Enterprises standardized on GitHub Enterprise Cloud can now automate VSS seat assignments via REST API, enabling programmatic license auditing and allocation at scale — worth scheduling into the licensing management workflow.
- Platform/SRE — Skip
- CI/CD — Skip
- Leader — Learn: Pre-GA feature that surfaces active-committer counts to estimate Code Quality licensing costs; worth monitoring as it approaches GA before making any GitHub Advanced Security / Code Quality budget decisions.
- Signals: pre-GA (alpha/beta/RC/preview)