• Ferk@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    10 hours ago

    Does the DCO really offer a real guarantee? it looks like it just adds a Signed-off-by John line at the end of the commit, with no actual signature checking that enforces any particular version of a particular document is being acknowledged. IANAL but it doesn’t look like something proven to work in court to give legal protection.

    Sure, it’s easier to simply add a sign-off-by line than actually accepting a legal agreement, so it reduces the barrier of entry, but if this were really enough to establish the conditions to shift liability then I don’t see why companies wouldn’t start using their own DCOs and extending them, essentially just being a more convenient CLA (which is a license agreement, not a copyright transfer, even if some might add terms that allow relicensing… which anyway is already possible given the project is already MIT licensed).