# \[ANN\] Clojars now requires a license in the POM for new projects or projects that already specify a license

**URL:** https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347
**Category:** Watercooler
**Created:** [September 29, 2023, 11:36am UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347 "2023-09-29T11:36:01Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![tcrawley](https://clojureverse.org/user_avatar/clojureverse.org/tcrawley/32/2603_2.png) [@tcrawley](https://clojureverse.org/u/tcrawley)
#### Post date: [September 29, 2023, 11:36am UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/1 "2023-09-29T11:36:02Z")

</div>

Hi all!

Clojars ([https://clojars.org](https://clojars.org) - the community repository for open source Clojure  
libraries) will now require a license to be specified in the POM file for:

- newly uploaded versions for new projects
- newly uploaded versions for existing projects where the prior version had a license

We will then start requiring a license for _all_ newly uploaded versions on or  
after 2024-01-01. Note that this will not impact any _existing_ versions;  
existing versions that don’t have a license in the POM file will remain  
unchanged.

For more details, see [this issue](https://github.com/clojars/clojars-web/issues/873) for discussion of the change, and the  
[Deploying wiki entry](https://github.com/clojars/clojars-web/wiki/Pushing#licenses) for how to add a license to your POM.

## Why is Clojars making this change?

We are making this change:

- to better support auditing from java ecosystem tools that use the POM as the  
source of truth for the license
- enforce better hygiene; all open source projects should have a license

## How does this change impact me?

If you only consume projects from Clojars and do not release libraries, you  
don’t need to do anything.

If you publish projects to Clojars, you will need to:

- include a license with any new projects
- continue to include a license with new versions of projects where you already  
provide a license
- update any projects that don’t provide a license to provide one before the end  
of the year if you plan to release a new version

If Clojars rejects your deploy, you will see a message like:

```auto
Could not transfer metadata org.clojars.tcrawley:deploytest/maven-metadata.xml from/to clojars (https://repo.clojars.org/): authorization failed for https://repo.clojars.org/org/clojars/tcrawley/deploytest/maven-metadata.xml, status: 403 Forbidden - the POM file does not include a license. See https://bit.ly/3PQunZU

```

Most versions already have licenses in their POM files since [Leiningen](https://leiningen.org/)  
includes one by default, and prints a warning when you try to deploy without  
one. But newer tooling built on the [Clojure CLI tools](https://clojure.org/guides/deps_and_cli) doesn’t have this  
warning (however, [deps-new](https://github.com/seancorfield/deps-new) will generate a pom.xml that does include a license  
if you use it to template your project).

## Thank you

Thanks to Peter Monks for suggesting this change, and Daniel Compton for  
discussing a solution.

## Supporting this work

This work was done as part of an ongoing maintenance contract from [Clojurists  
Together](https://www.clojuriststogether.org/). You can also sponsor me directly on [GitHub Sponsors](https://github.com/sponsors/tobias) if you would  
like to directly fund my maintenance of Clojars.

Please reply here or on the issue if you have any concerns or questions.

- Toby

---

<div class="post-metadata">

### Author: ![Webdev\_Tory](https://clojureverse.org/user_avatar/clojureverse.org/webdev_tory/32/3781_2.png) [@Webdev\_Tory](https://clojureverse.org/u/Webdev_Tory)
#### Post date: [December 13, 2023, 6:09pm UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/2 "2023-12-13T18:09:09Z")

</div>

Ah! I didn’t know about deps-new , so it may give a nice entrypoint to deps.edn if I ever get off my WIP projects…

---

<div class="post-metadata">

### Author: ![seancorfield](https://clojureverse.org/user_avatar/clojureverse.org/seancorfield/32/195_2.png) [@seancorfield](https://clojureverse.org/u/seancorfield)
#### Post date: [December 13, 2023, 9:36pm UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/3 "2023-12-13T21:36:05Z")

</div>

And if you want to see how to handle license and other important parts of the POM, check out the `build.clj` file for `next.jdbc`: [next-jdbc/build.clj at develop · seancorfield/next-jdbc (github.com)](https://github.com/seancorfield/next-jdbc/blob/develop/build.clj#L35-L60)

---

<div class="post-metadata">

### Author: ![tcrawley](https://clojureverse.org/user_avatar/clojureverse.org/tcrawley/32/2603_2.png) [@tcrawley](https://clojureverse.org/u/tcrawley)
#### Post date: [December 29, 2023, 3:59pm UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/4 "2023-12-29T15:59:52Z")

</div>

I just deployed a change that requires licenses for _all_ releases (as promised above, though I did release it a few days early).

I also updated the [wiki](https://github.com/clojars/clojars-web/wiki/Pushing#licenses) to cover this change, and linked to @seancorfield’s `next-jdbc` `build.clj` example to show `tools.build` usage.

Let me know if you see any issues when deploying!

---

<div class="post-metadata">

### Author: ![seancorfield](https://clojureverse.org/user_avatar/clojureverse.org/seancorfield/32/195_2.png) [@seancorfield](https://clojureverse.org/u/seancorfield)
#### Post date: [December 29, 2023, 5:48pm UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/5 "2023-12-29T17:48:05Z")

</div>

The clojure-doc cookbook for `tools.build` covers this as well: [Clojure Guides: Building Projects: tools.build and the Clojure CLI (clojure-doc.org)](https://clojure-doc.org/articles/cookbooks/cli_build_projects/#the-generated-pomxml-file) (under \*\*The Generated `pom.xml` File).

---

<div class="post-metadata">

### Author: ![system](https://clojureverse.org/uploads/default/original/2X/5/51079bf9e4b7d9466242c06cf1e43b9f8bd6da14.png) [@system](https://clojureverse.org/u/system)
#### Post date: [June 29, 2024, 5:48am UTC](https://clojureverse.org/t/ann-clojars-now-requires-a-license-in-the-pom-for-new-projects-or-projects-that-already-specify-a-license/10347/6 "2024-06-29T05:48:31Z")

</div>

This topic was automatically closed 182 days after the last reply. New replies are no longer allowed.
