Skip to content

RFC 86 Phase 2: Contributor Outreach & Consent #3

Description

@jjgao

Phase 2: Contributor Outreach & Consent

Part of: #8
Blocked by: Phase 0 (#1) — scope sets the consent denominator
Feeds: Pre-Switch Sign-off Gate (#5)

Target windows (hard project deadline 2026-09-30, see epic #8):

  • Team lead consent launched Jul 31, 2026, deadline Aug 31, 2026. Consent collected via cbioportal#12282 at the team-lead level rather than through formal legal/tech-transfer review (see CLAUDE.md Decisions).
  • Individual contributor outreach launched Jul 28, 2026, deadline Sep 20, 2026 — runs in parallel with Phase 3's 30-day notice period (Aug 21 – Sep 20). Non-responders default to rewrite/remove.

Goal

Obtain consent from all copyright holders in the git history to relicense their contributions under Apache 2.0, across every in-scope repo from the Phase 0 manifest (#1). No prior CLA exists, so explicit consent is required.

Rights-holder identification

Git authors are not always the copyright holders, especially for employment or sponsored work. Build a contributor → probable rights-holder matrix for all retained code, docs, assets, and tests — including co-authors and AI-assisted PRs.

Outreach Strategy

Team Lead Consent
Secure consent from the team lead of the cBioPortal team at each contributing organization — not from a formal legal or tech-transfer office — for the work of individuals who account for the largest share of the codebase: MSKCC, DFCI, PMCC, CHOP, The Hyve, SE4BIO, Bilkent University.

Consent is collected via cbioportal#12282. The consent statement explicitly invites the lead to redirect to the appropriate authority if required, and includes an attestation of the signer's role and good-faith basis — a deliberate, documented trade-off (speed vs. formal legal certainty); see CLAUDE.md Decisions and the sign-off gate (#5).

Individual Contributor Outreach
Send a standardized outreach message to every unique contributor identified in git history (across all in-scope repos) via cbioportal#12271. Outreach template: docs/relicensing/outreach-individual-template.md. Deadline Sep 20, 2026 (runs in parallel with Phase 3); non-responders default to rewrite/removal.

Public Consent Status Board

Precedent: mpv's LGPL relicensing maintained a public page listing every contributor's agree/pending status.

Published: docs/relicensing/contributor-consent-status.md (2026-07-10) — 209 contributors across all 5 in-scope repos, includes team annotations and consent status.

Pre-license-era check (2026-07-10): AGPL LICENSE added 2015-03-18, but root commit dates to 2011-06-17. Recommendation: do not exclude pre-license contributors — copyright exists regardless of licensing. Only 6 of 209 fall in this bucket; none excluded.

  • Publish public status board with agreed / pending / declined / unreachable per contributor
  • Board contains no raw contact info (no emails, no Slack IDs)
  • Merge in cbioportal-core and session-service contributors (done 2026-07-10; 209 total)
  • Public individual consent issue created: cbioportal#12271
  • Team lead consent issue created: cbioportal#12282
  • Update the board as responses come in; link from this issue and sign-off gate (RFC 86 Pre-Switch Sign-off Gate (blocks Phase 4) #5)
  • The Vanish List becomes a filtered view of the board (unreachable rows only)

Tasks

  • Extract full contributor list from git history for all in-scope repos
  • Build contributor → probable rights-holder matrix (incl. co-authors and AI-assisted PRs)
  • Draft individual contributor outreach template — docs/relicensing/outreach-individual-template.md
  • Run team lead outreach and track responses — deadline Aug 31
  • Run individual contributor outreach and track responses — deadline Sep 20
  • Track raw contact details privately; publish only names/handles/status on the public board
  • Once 95% of codebase by volume is covered: identify files/functions owned by remaining contributors
  • Rewrite or remove remaining <5% if consent cannot be obtained — complete by Sep 20

Definition of Done

95% coverage is an operational milestone, not final sufficiency. The final switch requires consent for all retained contributions, or documented rewrite/removal of every uncovered contribution. Public status board complete and linked. The ≥95% / <5% reconciliation recorded for sign-off gate (#5) by Sep 20.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions