Skip to content

[Legal Notices] Version and enforce third-party name, affiliation and DRM reviews #92

Description

@KeyffMS

Completed state

SightAdapt now treats third-party names, compatibility claims, public assets and DRM/access-control wording as versioned maintained material rather than informal copy.

PR #147 was merged as 9628546a4844c7e0a81b03fba9a23d2e9879ef49.

Authoritative controls

  • THIRD-PARTY-NAMES-AND-DRM-NOTICE.txt remains the package notice source of truth.
  • docs/legal/THIRD-PARTY-NAMES-AFFILIATION-AND-DRM.md defines identification-only use, no-affiliation wording, factual compatibility language, asset restrictions and protected-content boundaries.
  • docs/legal/PUBLIC-MATERIALS-REVIEW.md defines publication, screenshot, asset, compatibility-claim and rights-holder-objection procedures.
  • release/public-materials.json records exact reviewed Git blob evidence and separates maintained from planned surfaces.
  • tools/verify-public-materials.ps1 and tools/test-public-materials-negative.ps1 enforce the registry in CI.

Internal review is a maintainer risk control. It is not legal advice, trademark clearance, third-party permission or a professional audit.

Maintained reviewed surfaces

Six current surfaces are pinned by exact Git blob SHA and approved maintainer review:

  1. repository README;
  2. binary third-party-name and DRM notice;
  3. repository legal/trademark policies;
  4. release-description template;
  5. application About-window review;
  6. project-owned SightAdapt SVG brand assets.

Each maintained surface records its named third parties, factual compatibility claims, limitations and third-party assets. No reviewed maintained surface currently includes a third-party logo, certification badge or promotional asset.

Planned surfaces

The following remain inactive until their own implementation records final text, public URLs, dates, screenshots/assets and exact review evidence:

A planned surface cannot be marked active merely by changing its status in the registry; it must be moved into the maintained inventory with immutable evidence and pass CI.

Compatibility and asset rules

Approved factual forms include works with, tested with <product/version>, compatible with, uses and applies an overlay to. Named compatibility claims must include relevant limitations.

Unapproved relationship language such as official integration, partnered with, approved by, certified by, endorsed by or supported by is rejected unless an exact written relationship is separately documented.

A third-party logo, icon, screenshot, badge or trade dress requires recorded ownership/source, use basis, approved purpose, review date and immutable source evidence. Locally displayed application icons are identification data and are not reusable SightAdapt marketing assets.

Protected-content boundary

SightAdapt is not intended to decrypt, unlock, evade, bypass or interfere with DRM, authentication, licensing, encryption, capture prevention or another access control. Protected content may remain blank, unchanged, unavailable or unfilterable.

Negative validation

CI proves rejection of:

  • stale reviewed source hashes;
  • an official integration compatibility claim;
  • a third-party logo without complete ownership, use-basis, purpose, review and immutable evidence;
  • activation of the planned GitHub Release surface without a completed review.

Verified result

Final head 7c4bf73348d0101fc6e6a2b5c1ca4ebfc6882d9f passed:

  • DCO run 30648478483;
  • full Windows run 30648478474;
  • six maintained and nine planned public surfaces;
  • all four new negative cases;
  • 210 tests;
  • 452 published component mappings;
  • complete SBOM/license and final-package gates.

The verified portable ZIP SHA-256 was 25AD398276ADBB69B4523C44A2A1DC889D7346D4903EAC3441F1B5C8BC1AA85F. The GitHub Actions artifact digest was sha256:a50bac2c369f38cdc484188f902481610d45e425b9d63ad2d5d59926bc5f35b4.

Acceptance criteria

  • State ownership of third-party names and marks.
  • Limit names to identification of user-selected applications.
  • State no affiliation, sponsorship, certification or endorsement.
  • State the DRM/access-control and protected-content boundary.
  • Include the notice in README, legal documentation and the binary bundle.
  • Review and record the current About-window surface.
  • Prohibit unreviewed third-party logos, trade dress and branded assets.
  • Define factual compatibility wording and limitations.
  • Review the wording with the internal trademark-risk record.
  • Inventory maintained public surfaces with immutable evidence.
  • Keep future external channels inactive until exact final-material review.
  • Define and test a rights-holder objection and correction process.

Re-review triggers

Re-review when a public channel is activated, a named compatibility claim changes, a third-party asset is proposed, a relationship/certification is proposed, protected-content behavior changes, the trademark-risk decision changes or a third party objects.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions