Replace @webreflection/toml-j0.4
because it is a license-hazard
#2335
Replies: 3 comments 6 replies
-
I don't understand where's the license hazard when it's MIT, see https://github.com/WebReflection/toml-j0.4 |
Beta Was this translation helpful? Give feedback.
-
@iFreilicht to provide more context:
because it's MIT though, I don't understand what's the concern ... if you read "why we have that" you'll realize this is the most secure module you can bet on ... as it won't ever change over time. the day we'll change it, it'd be for something else either as dead or smaller/faster, not a full TOML parser for sure ... does this make sense? |
Beta Was this translation helpful? Give feedback.
-
We have deduced that the package is indeed MIT. I personally believe that the way licensing 3rd-party packages is currently handled is not compliant, but that is irrelevant to this discussion. |
Beta Was this translation helpful? Give feedback.
-
The package @webreflection/toml-j0.4 is currently used in the core library.
The last version was published 2 years ago, and the project has no license. Please consider removing it in favor of something more mainstream.
This can be particularly annoying when deploying pyscript in a restricted environment, see https://docs.pyscript.net/2024.3.2/user-guide/offline/. My workaround for now is to just not use any toml functionality and remove all files related to that library before deploying to a server.
Beta Was this translation helpful? Give feedback.
All reactions