Skip to content

[Legal/.NET] Document and implement Microsoft .NET redistribution obligations #84

Description

@KeyffMS

Decision

SightAdapt documents and implements its Microsoft .NET redistribution approach through maintainer-owned technical and business-risk controls. No external legal audit is required or planned.

This is an internal project decision. It does not claim legal clearance or outside-counsel review.

Implemented state

  • exact SDK/runtime/TFM/RID/publish configuration is recorded in release/dotnet-redistribution-review.json;
  • the reviewed redistribution wording is stored as a checksum-protected template;
  • MICROSOFT-DOTNET-REDISTRIBUTION.txt is generated from canonical release metadata;
  • exact Microsoft license and third-party notice material is imported from a hash-verified official SDK package;
  • Microsoft terms remain separate from SightAdapt's MIT License;
  • final packages preserve the complete notice bundle;
  • configuration or template drift fails before packaging;
  • deliberately stale redistribution wording is rejected by CI;
  • the compliance report records the maintainer decision and generated-notice checksum.

Acceptance criteria

  • Identify Microsoft-origin component families included in the self-contained output.
  • Identify authoritative license/redistribution sources for the pinned release train.
  • Record redistribution conditions and project treatment.
  • Confirm that Microsoft components are distributed only as part of SightAdapt.
  • Include required notices, warranty/support boundaries and attribution language.
  • Keep Microsoft terms separate from SightAdapt's MIT License.
  • Record review date, configuration, sources and template checksum.
  • Require a new maintainer review when SDK/runtime/TFM/RID/publish mode, component inventory or notice wording changes.
  • Record an explicit maintainer decision for the current distribution scope.
  • Do not claim external legal clearance or professional audit.

Implementation

Re-review triggers

Reopen or update the review record when the runtime/toolchain, publish configuration, Microsoft components, distribution channels, compatibility claims or Microsoft terms materially change.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions