Licensing and content provenance
This page exists for one audience: someone deciding whether aurora-lint can enter a distribution archive. It answers what is in this source tree, who wrote it, and under what terms.
Summary
Material |
License |
Where it lives |
|---|---|---|
aurora-lint’s own source code and packaging |
|
everything not listed below |
aurora-lint’s own documentation |
|
|
SEI CERT C rule titles and rule prose |
|
|
SEI CERT C code examples |
|
the C snippets embedded in those |
Copyright in all of it is held by BISSELL Homecare, Inc. aurora-lint is company
work: it is written by BISSELL employees under BISSELL direction, so the
holder is the entity, not the individuals. Cargo.toml’s authors field
still names individuals, and correctly — authorship is a statement of who
wrote the code and is not the same as who owns it. CONTRIBUTORS.md is the
fuller record.
aurora-lint is licensed Apache-2.0. The CERT rows above are third-party material
carried in the tree, not a change to that: they keep their own upstream terms,
the way any vendored component does, and those terms are recorded in
NOTICE and thirdparty/cert/LICENSE rather than in LICENSE.
The attribution obligation reaches the binary, not only the source tarball:
each rule compiles its CERT title in as a &'static str, so a stripped
aurora-lint executable still carries CC BY 4.0 material. NOTICE ships in every
release artifact for that reason.
A packager describing the contents of a binary package will generally write
the union rather than the project’s own license — Apache-2.0 AND MIT AND
CC-BY-4.0 — which is why the DEP-5 stanzas below are split by path. That is
a packaging-metadata convention and is not what aurora-lint is licensed under.
The CERT terms
thirdparty/cert/LICENSE holds, verbatim and unedited, the notice published
by the SEI itself at
https://github.com/cmu-sei/secure-coding-standards/blob/main/LICENSE. Its
operative sentence:
The SEI CERT® Coding Standards are licensed under a Creative Commons BY 4.0 Attribution License […], and the code examples contained therein are licensed under a MIT license […]. Although the rights granted by the referenced licenses allow modification […]
Both are DFSG-free and Fedora-allowed, and both permit modification — which matters, because aurora-lint’s rule descriptions are modified (they are extracted from page markup and reflowed, and CC BY 4.0 section 3(a)(1)(B) requires that modification be indicated).
Warning
The SEI publishes a second, restrictive notice on its technical
reports — reproduce-in-entirety-only, no modification, commercial use by
permission. That notice is non-free and it does not govern the coding
standards. An adjudication that quotes the technical-report boilerplate at
this material has cited the wrong document and will reach the wrong answer.
The standards’ own LICENSE, mirrored in thirdparty/cert/, is the
governing text.
Trademark, which is separate from copyright
Carnegie Mellon and CERT are registered trademarks of Carnegie Mellon University. The copyright licenses above grant nothing here.
Nominative use in prose is fine: “aurora-lint checks C code against the SEI CERT C Coding Standard” describes what the tool does and is how the marks may be used.
Do not put CERT or Carnegie Mellon in the binary name, the package name, or any name that reads as a source identifier. The binary and the distribution package are both
aurora-lintdeliberately.src/rules/cert_c/is an internal path, not a published name.Do not imply endorsement, certification, or affiliation.
What a packager needs to write
Debian debian/copyright (DEP-5) needs three stanzas rather than one:
Files: *
Copyright: 2025-2026 BISSELL Homecare, Inc.
License: Apache-2.0
Files: docs/*
Copyright: 2025-2026 BISSELL Homecare, Inc.
License: CC-BY-4.0
Files: src/rules/cert_c/*/*/tests/*
Copyright: Carnegie Mellon University
Comment: Fixtures derived from the SEI CERT C Coding Standard's compliant
and non-compliant code examples. See thirdparty/cert/LICENSE.
License: Expat
Files: src/rules/cert_c/*/*/*-C.toml
Copyright: Carnegie Mellon University
Comment: metadata.title and metadata.description are lifted from the SEI
CERT C Coding Standard and reflowed. Embedded C snippets are Expat.
License: CC-BY-4.0 and Expat
The fixture stanza is deliberately broader than reality: most fixtures are
locally authored rather than wiki-derived, and each declares which it is in a
Source: header comment. Claiming CMU copyright over all of them is the
conservative direction to be wrong in — a packager who wants the tighter glob
can generate it from scripts/fixture_provenance.py --by-rule --json,
which reports the split per rule.
Fedora .spec: .github/workflows/release.yml emits
License: Apache-2.0, aurora-lint’s own license. A Fedora packager who prefers the
contents-union convention would write Apache-2.0 AND MIT AND CC-BY-4.0
instead; both describe the same package, and the NOTICE and
thirdparty/cert/LICENSE files shipped alongside carry the detail either
way.
Re-deriving the counts
Provenance is recorded in the files themselves, so the split can be recounted at any commit rather than trusted from prose:
# fixture corpus split by declared provenance, wiki vs local
python3 scripts/fixture_provenance.py
# rule manifests carrying CERT title/description text
find src/rules -name '*-C.toml' | wc -l
As of 2026-09-05: 313 rule manifests, every one carrying a CERT title and description, 310 citing their source wiki page, 33 embedding a CERT code example; and 1,337 fixtures declaring wiki provenance out of 3,577.
fixture_provenance.py reports what each header declares. The independent
check on that claim is scripts/audit_wiki_fixture_staleness.py, which
re-fetches each rule’s wiki page and measures how much of the original code
block still appears in the fixture — relevant here because a fixture rewritten
until it matched what the checker looks for is no longer meaningfully
CERT-derived, in evidence or in copyright.
Third-party Rust dependencies
Unrelated to the above and handled separately: cargo-about generates
THIRD_PARTY_LICENSES.txt and cargo-cyclonedx a CycloneDX SBOM on every
release build. Both ship in every release artifact. The allowlist of
acceptable dependency licenses is about.toml.