diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..78c9b89 --- /dev/null +++ b/.env.example @@ -0,0 +1,4 @@ +# BotScope environment placeholders — never put real secrets here. +# CLOUDFLARE_API_TOKEN= +# BOTSCOPE_CLOUDFLARE_RADAR_TOKEN= +# BOTSCOPE_RDNS=0 diff --git a/ACQUISITION.md b/ACQUISITION.md new file mode 100644 index 0000000..e3fd103 --- /dev/null +++ b/ACQUISITION.md @@ -0,0 +1,53 @@ +# Acquisition Brief — BotScope + +**Date:** 2026-09-21 +**Status:** Briefing document only. **No acquisition has occurred** by virtue of this file. + +## What the project does + +Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory. + +## Problem + +Operators lack a transparent, evidence-gated picture of automation traffic vs human traffic. + +## What is included in a transaction (typical) + +- Git repository and original BotScope source/docs (subject to agreement) +- Asserted copyright in original works (subject to counsel / chain of title) +- Branding assets created for BotScope (registration status UNKNOWN) +- Acquisition data room under `docs/acquisition/` + +## What is NOT included + +- Historical Apache-2.0 grants already received by third parties +- Operator-published IP range data / Cloudflare Radar data +- Third-party dependency source +- Buyer cloud accounts or secrets +- Fabricated user/revenue metrics (none claimed) + +## Maturity + +v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot. + +## Deployment model + +pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token. + +## Technical differentiation + +Evidence-gated classification with UNKNOWN-first posture; federated public panels; optional local GUI Observatory. + +## Transferable IP / third-party / limitations + +See `docs/acquisition/IP_AUDIT.md`, `TRANSFER_MANIFEST.md`, `BOTSCOPE_DILIGENCE.md`. + +## Handoff / evaluation + +See `docs/acquisition/HANDOFF_PLAN.md` and `BUYER_DEMO.md`. + +## Acquisition contact + +GitHub [@theworker02](https://github.com/theworker02) · https://github.com/theworker02/botscope + +No valuation is stated in this document. diff --git a/CITATION.cff b/CITATION.cff index f34fda0..a866be9 100644 --- a/CITATION.cff +++ b/CITATION.cff @@ -6,6 +6,6 @@ authors: - name: "BotScope Contributors" repository-code: "https://github.com/theworker02/botscope" url: "https://github.com/theworker02/botscope" -license: Apache-2.0 +license: "SEE LICENSE" version: 2.0.0 # DOI: not assigned — do not invent one diff --git a/docs/DEPLOYMENT.md b/docs/DEPLOYMENT.md new file mode 100644 index 0000000..3231591 --- /dev/null +++ b/docs/DEPLOYMENT.md @@ -0,0 +1,12 @@ +# Deployment — BotScope + +pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token. + +## Minimal path + +See [`acquisition/BUYER_DEMO.md`](./acquisition/BUYER_DEMO.md). + +## Rollback + +- Application projects: redeploy previous release tag / prior container digest. +- Documentation corpora (ETW): revert git tag; do not delete historical license tags. diff --git a/docs/HANDOFF.md b/docs/HANDOFF.md new file mode 100644 index 0000000..9bb8c00 --- /dev/null +++ b/docs/HANDOFF.md @@ -0,0 +1,5 @@ +# Handoff — BotScope + +See [`acquisition/HANDOFF_PLAN.md`](./acquisition/HANDOFF_PLAN.md) for Day 0 → Day 30. + +Buyer evaluation: [`acquisition/BUYER_DEMO.md`](./acquisition/BUYER_DEMO.md). diff --git a/docs/OPERATIONS.md b/docs/OPERATIONS.md new file mode 100644 index 0000000..fb2e979 --- /dev/null +++ b/docs/OPERATIONS.md @@ -0,0 +1,15 @@ +# Operations — BotScope + +## Health + +- Run buyer demo / doctor commands from README where present. +- Monitor CI on GitHub Actions. + +## Incidents + +- Security: SECURITY.md +- License misuse: docs/legal/RIGHTS_AND_ENFORCEMENT.md (**REQUIRES_LEGAL_REVIEW**) + +## Secrets + +- Store only in platform secret stores. Rotate on handoff. diff --git a/docs/acquisition/ARCHITECTURE.md b/docs/acquisition/ARCHITECTURE.md new file mode 100644 index 0000000..a5342af --- /dev/null +++ b/docs/acquisition/ARCHITECTURE.md @@ -0,0 +1,22 @@ +# Architecture — BotScope + +See also repository root architecture docs where present (`ARCHITECTURE.md`, `docs/`, `README.md`). + +## Stack + +Python >=3.10 (Hatchling); optional PySide6 GUI + +## Deployment + +pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token. + +## Summary + +Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory. + +## Boundaries + +- Third-party runtimes, cloud providers, and SDKs are **dependencies**, not owned assets. +- Project-specific diligence: [`BOTSCOPE_DILIGENCE.md`](./BOTSCOPE_DILIGENCE.md). + +Buyer should walk architecture with the handoff plan ([HANDOFF_PLAN.md](./HANDOFF_PLAN.md)). diff --git a/docs/acquisition/ASSET_REGISTER.md b/docs/acquisition/ASSET_REGISTER.md new file mode 100644 index 0000000..c4ec6df --- /dev/null +++ b/docs/acquisition/ASSET_REGISTER.md @@ -0,0 +1,29 @@ +# Asset Register — BotScope + +**Date:** 2026-09-21 + +Classification legend: `OWNED` (asserted original work) · `THIRD_PARTY_PERMISSIVE` · `THIRD_PARTY_COPYLEFT` · `PUBLIC_DATA` · `PUBLIC_STANDARD` · `UNKNOWN` · `REQUIRES_PERMISSION` · `REQUIRES_LEGAL_REVIEW` + +| Asset | Classification | Notes | +|-------|----------------|-------| +| Git repository | OWNED / REQUIRES_LEGAL_REVIEW | Hosted at https://github.com/theworker02/botscope; copyright chain see IP_AUDIT | +| Original source / docs authored for this project | OWNED / REQUIRES_LEGAL_REVIEW | Subject to contributor/AI issues | +| Root LICENSE / NOTICE | OWNED (text) | Current terms proprietary | +| Historical open-source grants already given | PUBLIC/THIRD-PARTY (grants) | Cannot be clawed back by LICENSE change alone | +| Dependencies | See DEPENDENCY_AUDIT | click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, httpx. No lockfile. No G… | +| Third-party content | See THIRD_PARTY_NOTICES | Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; syntheti… | +| Brand / name | UNKNOWN registration | Asserted use by holder; no registration docs in repo | +| Secrets | N/A | Never transferable as committed assets | + +## Transfer-oriented inventory + +| Asset | Transfer class | Notes | +|-------|----------------|-------| +| repository | TRANSFERABLE | github.com/theworker02/botscope | +| source code (original) | TRANSFERABLE | Subject to historical Apache grants | +| PyPI package botscope | TRANSFERABLE_WITH_CONSENT | Trusted Publishing / PyPI ownership transfer | +| datasets/demo + fixtures | TRANSFERABLE | Synthetic/hand-labeled; still confirm intent | +| operator IP list caches | PUBLIC/THIRD-PARTY | Not BotScope-owned; operator terms apply | +| Cloudflare Radar derived metrics | REQUIRES_PERMISSION | API/terms; token is buyer's | +| brand BotScope | TRANSFERABLE_WITH_CONSENT | Registration UNKNOWN | +| secrets | NONTRANSFERABLE | Rotate only | diff --git a/docs/acquisition/BOTSCOPE_DILIGENCE.md b/docs/acquisition/BOTSCOPE_DILIGENCE.md new file mode 100644 index 0000000..d38757f --- /dev/null +++ b/docs/acquisition/BOTSCOPE_DILIGENCE.md @@ -0,0 +1,46 @@ +# BotScope — Project-Specific Diligence + +**Date:** 2026-09-21 + +## Traffic-data sources + +Catalogued in `src/botscope/sources/registry/catalog.py` and `docs/sources/`: +Common Crawl collinfo, Google/Bing/OpenAI/Anthropic/Perplexity/Apple bot IP ranges, +optional Cloudflare Radar, cloud IP ranges, local sensor. + +## Source licensing + +- Operator-published JSON: review each operator’s terms — **REQUIRES_PERMISSION** / **REQUIRES_LEGAL_REVIEW** for commercial redistribution of cached copies. +- Cloudflare Radar: API token + Cloudflare terms; not transferable as BotScope-owned data. + +## API dependencies + +- Optional `httpx` network extra; Radar token via env/settings. +- Network contribution off by default per docs. + +## Provenance + +- Demo logs synthetic (`datasets/demo`). +- Fixtures hand-labeled (`datasets/fixtures`) — not vendor ground truth. + +## Bot classification methodology + +- Pipeline: ingest → privacy → rules + identity + optional ML → evidence → aggregates. +- UNKNOWN is first-class; ML must not override verified identity. +- Global headline gated on multiple independent traffic-share sources. + +## False-positive limitations + +- Confidence scores are heuristics, not calibrated prevalence. +- FAQ vs GLOBAL_ESTIMATION messaging conflict noted in audit — treat estimation claims carefully. + +## Dataset transferability + +- Synthetic/hand-labeled fixtures: likely transferable as original compilation — confirm. +- Operator data: **PUBLIC/THIRD-PARTY** / **REQUIRES_PERMISSION**. +- No MaxMind DB shipped. + +## Reproducibility of metrics + +- Local demo/doctor path reproducible without tokens. +- Radar-dependent metrics require buyer credentials and are environment-specific. diff --git a/docs/acquisition/BUILD_REPRODUCIBILITY.md b/docs/acquisition/BUILD_REPRODUCIBILITY.md new file mode 100644 index 0000000..6e732b0 --- /dev/null +++ b/docs/acquisition/BUILD_REPRODUCIBILITY.md @@ -0,0 +1,24 @@ +# Build Reproducibility — BotScope + +**Date:** 2026-09-21 + +## Fresh machine path + +``` +git clone https://github.com/theworker02/botscope.git && cd botscope +python3 -m venv .venv && source .venv/bin/activate +pip install -e '.[dev]' +botscope doctor +botscope demo +pytest -q +``` + +## Assumptions + +- Stack: Python >=3.10 (Hatchling); optional PySide6 GUI +- No machine-specific absolute paths should be required. +- Cloud credentials are optional unless exercising live provider features. + +## Known reproducibility limits + +Documented in KNOWN_LIMITATIONS.md and project-specific diligence. diff --git a/docs/acquisition/BUYER_DEMO.md b/docs/acquisition/BUYER_DEMO.md new file mode 100644 index 0000000..77136f8 --- /dev/null +++ b/docs/acquisition/BUYER_DEMO.md @@ -0,0 +1,26 @@ +# Buyer Demo — BotScope + +**Target:** fresh machine → clone → install → run → verify (≈10–15 minutes where realistic). + +## Exact commands + +```bash +git clone https://github.com/theworker02/botscope.git && cd botscope +python3 -m venv .venv && source .venv/bin/activate +pip install -e '.[dev]' +botscope doctor +botscope demo +pytest -q +``` + +## Expected results + +- Commands exit 0 (or documented skip for optional live-cloud steps). +- No secrets required for the minimal path. +- See TEST_EVIDENCE.md for recorded exit codes from this program’s verification runs. + +## Out of scope for minimal demo + +- Live production cloud credentials +- Shipping malware / real vehicle bus hardware (OpenDashCAN) +- Paid API quotas diff --git a/docs/acquisition/BUYER_DUE_DILIGENCE_CHECKLIST.md b/docs/acquisition/BUYER_DUE_DILIGENCE_CHECKLIST.md new file mode 100644 index 0000000..ed1fd7e --- /dev/null +++ b/docs/acquisition/BUYER_DUE_DILIGENCE_CHECKLIST.md @@ -0,0 +1,13 @@ +# Buyer Due Diligence Checklist — BotScope + +- [ ] Read LICENSE, LICENSE_TRANSITION_NOTICE, NOTICE +- [ ] Read IP_AUDIT + LICENSE_HISTORY + LICENSE_TRANSITION_ANALYSIS +- [ ] Confirm historical Apache License, Version 2.0 (Apache-2.0) exposure acceptable +- [ ] Review DEPENDENCY_AUDIT + regenerate SBOM +- [ ] Review project-specific diligence (BOTSCOPE_DILIGENCE.md) +- [ ] Run BUYER_DEMO.md on a clean machine +- [ ] Review SECURITY_POSTURE + secret rotation plan +- [ ] Review KNOWN_LIMITATIONS + DISCLOSURE_SCHEDULE +- [ ] Counsel review of contributor/AI chain of title — **REQUIRES_LEGAL_REVIEW** +- [ ] Confirm what is excluded (third-party, trademarks, accounts) +- [ ] Validate commercial license pipeline (COMMERCIAL.md) diff --git a/docs/acquisition/CHANGE_OF_CONTROL_CHECKLIST.md b/docs/acquisition/CHANGE_OF_CONTROL_CHECKLIST.md new file mode 100644 index 0000000..4b97ea1 --- /dev/null +++ b/docs/acquisition/CHANGE_OF_CONTROL_CHECKLIST.md @@ -0,0 +1,22 @@ +# Change-of-Control Checklist — BotScope + +**STATUS: DORMANT.** Do not execute until a transaction actually closes. + +- [ ] Execute signed asset/IP agreement +- [ ] Confirm assets actually transferred match the agreement schedule +- [ ] Transfer GitHub repository +- [ ] Transfer domains (if any) +- [ ] Transfer package namespaces where supported +- [ ] Rotate credentials +- [ ] Update copyright notices where appropriate (counsel-directed) +- [ ] Update commercial contact +- [ ] Publish change-of-control notice (from docs/legal template) +- [ ] Update SECURITY.md +- [ ] Update SUPPORT.md +- [ ] Update acquisition status docs +- [ ] Archive superseded commercial documentation +- [ ] Preserve historical license notices / tags +- [ ] Notify commercial licensees where required +- [ ] Migrate infrastructure +- [ ] Verify production operation +- [ ] Produce final transfer receipt diff --git a/docs/acquisition/DEPENDENCY_AUDIT.md b/docs/acquisition/DEPENDENCY_AUDIT.md new file mode 100644 index 0000000..fcea26e --- /dev/null +++ b/docs/acquisition/DEPENDENCY_AUDIT.md @@ -0,0 +1,26 @@ +# Dependency Audit — BotScope + +**Date:** 2026-09-21 + +## Summary + +click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, httpx. No lockfile. No GPL/AGPL declared in core deps. + +## Third-party content (non-package) + +Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only. + +## Copyleft + +No GPL/AGPL/LGPL **declared as core direct dependencies** in the audits performed. +Optional GUI stacks (e.g. PySide6/Qt) may introduce LGPL obligations if redistributed — **REQUIRES_LEGAL_REVIEW** where applicable (OpenDashCAN/BotScope GUI extras). + +## SBOM status + +Formal CycloneDX/SPDX SBOM may be partial or absent. Buyer should regenerate SBOM at transfer. + +## Obligations + +- Retain dependency license notices on redistribution. +- Do not relicense third-party code. +- Cloudflare / operator / vendor terms are separate contracts — **REQUIRES_PERMISSION** for some commercial redistributions of derived data. diff --git a/docs/acquisition/DISCLOSURE_SCHEDULE.md b/docs/acquisition/DISCLOSURE_SCHEDULE.md new file mode 100644 index 0000000..2442213 --- /dev/null +++ b/docs/acquisition/DISCLOSURE_SCHEDULE.md @@ -0,0 +1,16 @@ +# Disclosure Schedule — BotScope + +**Date:** 2026-09-21 + +## Material disclosures + +1. **License transition:** Apache License, Version 2.0 (Apache-2.0) → proprietary (48437fe / merge da22ed8 (2026-09-20)). Historical grants remain for historical copies. +2. **Ownership uncertainties:** LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO. +3. **Third-party obligations:** Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only. +4. **Security:** No SECRET_FOUND. Test placeholders for Cloudflare tokens only. +5. **Maturity:** v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot. +6. **Blockers before diligence:** Operator data redistribution rights for commercial sale; Apache→proprietary transition; Dataset fixture license clarity + +## No claims + +This schedule does **not** claim revenue, user counts, exclusivity, or completed acquisition. diff --git a/docs/acquisition/EXECUTIVE_SUMMARY.md b/docs/acquisition/EXECUTIVE_SUMMARY.md new file mode 100644 index 0000000..10be21e --- /dev/null +++ b/docs/acquisition/EXECUTIVE_SUMMARY.md @@ -0,0 +1,51 @@ +# Executive Summary — BotScope + +**Date:** 2026-09-21 +**Current license:** botscope Source-Available Evaluation License (proprietary source-available) +**Prior license (historical distributions):** Apache License, Version 2.0 (Apache-2.0) +**Transition marker:** 48437fe / merge da22ed8 (2026-09-20) + +## What this is + +Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory. + +## Problem addressed + +Operators lack a transparent, evidence-gated picture of automation traffic vs human traffic. + +## Maturity + +v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot. + +## Deployment model + +pip install; CLI `botscope`; optional GUI; optional Cloudflare Radar token. + +## Language / stack + +Python >=3.10 (Hatchling); optional PySide6 GUI · Version metadata: **2.0.0** + +## Licensing posture (factual) + +- Current tree: proprietary / source-available terms in root `LICENSE` (see exact text). +- Historical distributions under **Apache License, Version 2.0 (Apache-2.0)** remain governed by those terms for copies received, where applicable. +- See [`LICENSE_TRANSITION_ANALYSIS.md`](./LICENSE_TRANSITION_ANALYSIS.md) and root `LICENSE_TRANSITION_NOTICE.md`. + +## Ownership (asserted, not adjudicated) + +Asserted holder: **theworker02 (https://github.com/theworker02)**. +LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO. + +**REQUIRES_LEGAL_REVIEW** before treating ownership as adjudicated or exclusive. + +## What a buyer can expect + +- Ability to evaluate and (after commercial license / acquisition) operate the project with documented handoff materials in this data room. +- Material third-party and historical-license limitations disclosed herein. +- No fabricated users, revenue, benchmarks, or exclusivity claims in this data room. + +## Top diligence risks + +- Operator data redistribution rights for commercial sale +- Apache→proprietary transition +- Dataset fixture license clarity diff --git a/docs/acquisition/HANDOFF_PLAN.md b/docs/acquisition/HANDOFF_PLAN.md new file mode 100644 index 0000000..45550ce --- /dev/null +++ b/docs/acquisition/HANDOFF_PLAN.md @@ -0,0 +1,31 @@ +# Handoff Plan — BotScope + +## Day 0 (closing) + +- Sign agreements; confirm asset schedule +- Transfer repo admin; escrow tags/releases +- Deliver this data room + +## Day 1 + +- Buyer runs BUYER_DEMO.md +- Rotate credentials (buyer-owned accounts) +- Walk ARCHITECTURE.md + project-specific diligence + +## Week 1 + +- CI ownership transfer; registry transfers +- Security.md / SUPPORT contacts updated +- Open issues triage + +## Week 2 + +- Deployment/ops dry run +- Commercial licensee notification if required +- Documentation gaps closed + +## Day 30 + +- Verify production/eval environment stable +- Final transfer receipt +- End of transitional support period (as contracted) diff --git a/docs/acquisition/IP_AUDIT.md b/docs/acquisition/IP_AUDIT.md new file mode 100644 index 0000000..c346513 --- /dev/null +++ b/docs/acquisition/IP_AUDIT.md @@ -0,0 +1,45 @@ +# IP Audit — BotScope + +**Date:** 2026-09-21 +**Method:** Repository inspection + git history. **Not legal advice.** + +## Copyright notices found + +- Asserted holder: **theworker02 (https://github.com/theworker02)** +- Current LICENSE: botscope Source-Available Evaluation License (proprietary source-available) +- Historical: Apache License, Version 2.0 (Apache-2.0) from 3845f65 (2026-09-18, Apache-2.0) until 48437fe / merge da22ed8 (2026-09-20) + +## Contributor / assignment status + +LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO. + +| Mechanism | Status | +|-----------|--------| +| CLA file | Not present | +| DCO requirement | Not present | +| LICENSE contribution assignment clause | Present in current proprietary LICENSE (where applicable) | +| GitHub ownership = copyright? | **Do not assume** — GitHub admin ≠ adjudicated copyright | + +## Ability to change licensing for FUTURE versions + +LIKELY for original code by theworker02 going forward, subject to REQUIRES_LEGAL_REVIEW. + +## What cannot be made exclusive + +Historical Apache-2.0 PyPI/git copies; operator-published IP lists; Cloudflare Radar data; dependency libraries. + +## Component classifications (high level) + +| Component | Class | +|-----------|-------| +| Original project code/docs | OWNED / REQUIRES_LEGAL_REVIEW | +| Package dependencies | THIRD_PARTY_PERMISSIVE (see DEPENDENCY_AUDIT) unless noted | +| Historical OSS distributions | Prior grants remain for those copies | +| Vendor / operator data | PUBLIC_DATA / REQUIRES_PERMISSION / REQUIRES_LEGAL_REVIEW as noted in project diligence | +| Trademarks of others | NONTRANSFERABLE / third-party | + +## Open issues marked for counsel + +- Chain of title including AI co-authorship trailers — **REQUIRES_LEGAL_REVIEW** +- Historical Apache License, Version 2.0 (Apache-2.0) → proprietary transition — **REQUIRES_LEGAL_REVIEW** +- Adequacy of LICENSE assignment clause vs signed CLA — **REQUIRES_LEGAL_REVIEW** diff --git a/docs/acquisition/KNOWN_LIMITATIONS.md b/docs/acquisition/KNOWN_LIMITATIONS.md new file mode 100644 index 0000000..9b0f6c4 --- /dev/null +++ b/docs/acquisition/KNOWN_LIMITATIONS.md @@ -0,0 +1,23 @@ +# Known Limitations — BotScope + +**Date:** 2026-09-21 + +## Product / technical + +- Maturity: v2.0.0 on PyPI; short git history (≈9 commits). Single human maintainer + Dependabot. +- Internet-wide bot traffic census / local analyzer: federates public crawler IP panels and optional CDN estimates; local log/session analysis and Qt Observatory. + +## Licensing / IP + +- Historical Apache License, Version 2.0 (Apache-2.0) copies cannot be exclusively clawed back by LICENSE edit alone. +- LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope Contributors'. CITATION.cff previously stale Apache-2.0 (fixed in this program). No CLA/DCO. + +## Third-party + +- Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only. + +## Do not assume + +- GitHub stars/users/revenue (not claimed here) +- Manufacturer or cloud-provider affiliation (disclaimed where documented) +- That optional extras are production-hardened diff --git a/docs/acquisition/LICENSE_HISTORY.md b/docs/acquisition/LICENSE_HISTORY.md new file mode 100644 index 0000000..1fde136 --- /dev/null +++ b/docs/acquisition/LICENSE_HISTORY.md @@ -0,0 +1,21 @@ +# License History — BotScope + +**Date:** 2026-09-21 + +| When | Event | Evidence | +|------|-------|----------| +| 3845f65 (2026-09-18, Apache-2.0) | Repository published under **Apache License, Version 2.0 (Apache-2.0)** | git history of `LICENSE` | +| 48437fe / merge da22ed8 (2026-09-20) | Transition to **botscope Source-Available Evaluation License (proprietary source-available)** | git history / PR merge | +| Ongoing | Current `LICENSE` governs new distributions from this tree | root LICENSE | + +## Last prior-license marker + +Tag v2.0.0 released under Apache era (commit 02d1de8 / 3845f65 lineage). Proprietary transition merged 2026-09-20 (PR #3). + +## Implications + +- Copies obtained under **Apache License, Version 2.0 (Apache-2.0)** remain under those terms for that material, where applicable. +- Current/future distributions from this repository are under the current LICENSE. +- Changing LICENSE does **not** automatically revoke valid prior grants. + +See root [`LICENSE_TRANSITION_NOTICE.md`](../../LICENSE_TRANSITION_NOTICE.md). diff --git a/docs/acquisition/LICENSE_TRANSITION_ANALYSIS.md b/docs/acquisition/LICENSE_TRANSITION_ANALYSIS.md new file mode 100644 index 0000000..78f6c8f --- /dev/null +++ b/docs/acquisition/LICENSE_TRANSITION_ANALYSIS.md @@ -0,0 +1,38 @@ +# License Transition Analysis — BotScope + +**Date:** 2026-09-21 +**REQUIRES_LEGAL_REVIEW** for legal conclusions. + +## Facts + +| Item | Value | +|------|-------| +| Original license | Apache License, Version 2.0 (Apache-2.0) | +| Current license | botscope Source-Available Evaluation License (proprietary source-available) | +| First OSS commit | 3845f65 (2026-09-18, Apache-2.0) | +| Transition | 48437fe / merge da22ed8 (2026-09-20) | +| Asserted copyright | theworker02 (https://github.com/theworker02) | + +## Is relicensing FUTURE versions straightforward? + +LIKELY for original code by theworker02 going forward, subject to REQUIRES_LEGAL_REVIEW. + +Technically, the repository already publishes proprietary terms for current tree contents. Legally, counsel must confirm chain of title and that no external contributor owns blocking rights. + +## What cannot be made exclusive + +Historical Apache-2.0 PyPI/git copies; operator-published IP lists; Cloudflare Radar data; dependency libraries. + +## What CAN remain proprietary going forward + +Original works for which the asserted holder (or assignee) exclusively owns copyright, distributed only under the proprietary LICENSE or commercial agreements — **subject to counsel confirmation**. + +## Forks and previously downloaded versions + +Forks and downloads of **Apache License, Version 2.0 (Apache-2.0)**-licensed snapshots generally retain rights under that license for that code. Post-transition code is not offered under Apache License, Version 2.0 (Apache-2.0). Mixing trees does not expand old rights onto new proprietary files. + +## Proposed future license name + +Existing evaluation / proprietary LICENSE already serves as a **Commercial Source / Evaluation** style license. A counsel-drafted **Commercial Source License** covering evaluation, commercial, modification, redistribution, internal, hosted/SaaS, transfer, termination, warranty, liability, third-party, and prior-release sections should replace or supplement the current text — **REQUIRES_LEGAL_REVIEW** (attorney drafting). + +Do **not** call the current license “open source.” diff --git a/docs/acquisition/PROPOSED_COMMERCIAL_SOURCE_LICENSE.md b/docs/acquisition/PROPOSED_COMMERCIAL_SOURCE_LICENSE.md new file mode 100644 index 0000000..91264df --- /dev/null +++ b/docs/acquisition/PROPOSED_COMMERCIAL_SOURCE_LICENSE.md @@ -0,0 +1,27 @@ +# Proposed Commercial Source License — Notes + +**Status:** The repository already publishes a proprietary / source-available +evaluation (or commercial) LICENSE at the root. + +A counsel-drafted **Commercial Source License** for FUTURE versions should +explicitly cover: + +- Evaluation rights +- Commercial-use rights +- Modification rights +- Redistribution rights +- Internal-use rights +- Hosted/SaaS rights +- Transfer rights +- Termination +- Warranty disclaimer +- Limitation of liability +- Third-party components +- Prior releases (historical open-source copies remain under their original terms) + +**Do not** call it open source unless it is OSI-approved. + +**REQUIRES_LEGAL_REVIEW** — attorney drafting required. Do not treat the current +custom LICENSE as a substitute for negotiated commercial agreements. + +See root `LICENSE`, `LICENSE_TRANSITION_NOTICE.md`, and `COMMERCIAL.md`. diff --git a/docs/acquisition/READINESS_REPORT.md b/docs/acquisition/READINESS_REPORT.md new file mode 100644 index 0000000..7787c9f --- /dev/null +++ b/docs/acquisition/READINESS_REPORT.md @@ -0,0 +1,41 @@ +# Acquisition Readiness Report — BotScope + +**Date:** 2026-09-21 +**No numeric score.** Statuses reflect evidence available in-repo and this program. + +| Section | Status | Notes | +|---------|--------|-------| +| BUILD | READY | Verified in TEST_EVIDENCE.md (this program) | +| TESTS | READY | Verified in TEST_EVIDENCE.md (this program) | +| SECURITY | READY_WITH_DISCLOSURE | No SECRET_FOUND. Test placeholders for Cloudflare tokens only. | +| DOCUMENTATION | READY_WITH_DISCLOSURE | Data room created this program | +| IP OWNERSHIP | REQUIRES_LEGAL_REVIEW | LICENSE: theworker02. Historical Apache: 'BotScope Contributors'. pyproject authors still 'BotScope … | +| LICENSE CLARITY | READY_WITH_DISCLOSURE | Current LICENSE clear; history documented; ETW revocation language corrected if applicable | +| DEPENDENCIES | READY_WITH_DISCLOSURE | click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, http… | +| THIRD-PARTY ASSETS | READY_WITH_DISCLOSURE / REQUIRES_LEGAL_REVIEW | See diligence | +| DATA RIGHTS | REQUIRES_LEGAL_REVIEW | Especially federated/operator/vendor data | +| REPRODUCIBILITY | READY_WITH_DISCLOSURE | BUYER_DEMO provided | +| TRANSFERABILITY | READY_WITH_DISCLOSURE | See TRANSFER_MANIFEST | +| OPERATIONS | READY_WITH_DISCLOSURE | Handoff + ops docs | +| BUYER DEMO | READY_WITH_DISCLOSURE | Commands verified where stack runnable; see TEST_EVIDENCE | +| KNOWN LIABILITIES | READY_WITH_DISCLOSURE | See DISCLOSURE_SCHEDULE | + +## Blockers + +### Before outreach +- Stale Apache references in CITATION/export (fixed this program) +- No dependency SBOM lockfile + +### Before diligence +- Operator data redistribution rights for commercial sale +- Apache→proprietary transition +- Dataset fixture license clarity + +### Before signing +- Formal IP assignment +- Data rights schedule for federated sources + +### Before closing +- PyPI project transfer +- Credential rotation for any Radar tokens +- SPA/APA diff --git a/docs/acquisition/README.md b/docs/acquisition/README.md new file mode 100644 index 0000000..dd94de0 --- /dev/null +++ b/docs/acquisition/README.md @@ -0,0 +1,40 @@ +# Acquisition Data Room — BotScope + +**Generated:** 2026-09-21 +**Repository:** https://github.com/theworker02/botscope +**Asserted copyright holder (from notices):** theworker02 (https://github.com/theworker02) + +This directory is a **technical and IP diligence data room**. It is factual, +evidence-based, and intentionally discloses defects. It is **not legal advice** +and does **not** assert that an acquisition has occurred. + +## Index + +| Document | Purpose | +|----------|---------| +| [EXECUTIVE_SUMMARY.md](./EXECUTIVE_SUMMARY.md) | Buyer-facing overview | +| [ASSET_REGISTER.md](./ASSET_REGISTER.md) | What exists in the tree | +| [ARCHITECTURE.md](./ARCHITECTURE.md) | Technical architecture pointer | +| [IP_AUDIT.md](./IP_AUDIT.md) | Ownership / classification | +| [DEPENDENCY_AUDIT.md](./DEPENDENCY_AUDIT.md) | Third-party code deps | +| [THIRD_PARTY_NOTICES.md](./THIRD_PARTY_NOTICES.md) | Attribution obligations | +| [LICENSE_HISTORY.md](./LICENSE_HISTORY.md) | Historical licensing | +| [LICENSE_TRANSITION_ANALYSIS.md](./LICENSE_TRANSITION_ANALYSIS.md) | Relicense analysis | +| [SECURITY_POSTURE.md](./SECURITY_POSTURE.md) | Security diligence | +| [TEST_EVIDENCE.md](./TEST_EVIDENCE.md) | Tests actually run | +| [BUILD_REPRODUCIBILITY.md](./BUILD_REPRODUCIBILITY.md) | Fresh-machine build | +| [KNOWN_LIMITATIONS.md](./KNOWN_LIMITATIONS.md) | Honest limitations | +| [TECHNICAL_DEBT.md](./TECHNICAL_DEBT.md) | Debt register | +| [TRANSFER_PLAN.md](./TRANSFER_PLAN.md) | How to transfer | +| [TRANSFER_MANIFEST.md](./TRANSFER_MANIFEST.md) | Transferability classes | +| [CHANGE_OF_CONTROL_CHECKLIST.md](./CHANGE_OF_CONTROL_CHECKLIST.md) | Dormant post-close checklist | +| [BUYER_DUE_DILIGENCE_CHECKLIST.md](./BUYER_DUE_DILIGENCE_CHECKLIST.md) | Buyer checklist | +| [DISCLOSURE_SCHEDULE.md](./DISCLOSURE_SCHEDULE.md) | Material disclosures | +| [BUYER_DEMO.md](./BUYER_DEMO.md) | Reproducible demo | +| [HANDOFF_PLAN.md](./HANDOFF_PLAN.md) | Day 0 → Day 30 | +| [READINESS_REPORT.md](./READINESS_REPORT.md) | Gate statuses | +| [BOTSCOPE_DILIGENCE.md](./BOTSCOPE_DILIGENCE.md) | Project-specific diligence | + +Root commercial docs: [`COMMERCIAL.md`](../../COMMERCIAL.md) (if present), [`ACQUISITION.md`](../../ACQUISITION.md) (if present), [`LICENSE_TRANSITION_NOTICE.md`](../../LICENSE_TRANSITION_NOTICE.md). + +Legal templates: [`../legal/`](../legal/). diff --git a/docs/acquisition/SECURITY_POSTURE.md b/docs/acquisition/SECURITY_POSTURE.md new file mode 100644 index 0000000..b523d28 --- /dev/null +++ b/docs/acquisition/SECURITY_POSTURE.md @@ -0,0 +1,18 @@ +# Security Posture — BotScope + +**Date:** 2026-09-21 + +## Secret scan (this program) + +No SECRET_FOUND. Test placeholders for Cloudflare tokens only. + +If any credential was ever committed historically, deletion from HEAD does **not** make it safe — **ROTATE_IMMEDIATELY**. + +## Reporting + +See root [`SECURITY.md`](../../SECURITY.md) where present. + +## Notes + +- Do not commit secrets. Use `.env.example` placeholders only. +- Buyer must rotate all credentials at handoff (see HANDOFF_PLAN). diff --git a/docs/acquisition/TECHNICAL_DEBT.md b/docs/acquisition/TECHNICAL_DEBT.md new file mode 100644 index 0000000..17c080c --- /dev/null +++ b/docs/acquisition/TECHNICAL_DEBT.md @@ -0,0 +1,11 @@ +# Technical Debt — BotScope + +**Date:** 2026-09-21 + +| Item | Severity | Notes | +|------|----------|-------| +| Short public history | Info | Easy for buyers to review; also means limited production evidence | +| License notice drift | Medium | Being corrected in this program | +| SBOM / lockfile gaps | Medium | click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/s | +| AI co-authorship trailers | Diligence | REQUIRES_LEGAL_REVIEW | +| Test/build verification | Process | Recorded in TEST_EVIDENCE as runs complete | diff --git a/docs/acquisition/TEST_EVIDENCE.md b/docs/acquisition/TEST_EVIDENCE.md new file mode 100644 index 0000000..8715879 --- /dev/null +++ b/docs/acquisition/TEST_EVIDENCE.md @@ -0,0 +1,22 @@ +# Test Evidence — BotScope + +**Date:** 2026-09-21 + +## Commands run + +``` +python3 -m venv .venv && . .venv/bin/activate +pip install -e '.[dev]' +botscope doctor +botscope demo +pytest -q +``` + +## Results + +| Check | Status | Detail | +|-------|--------|--------| +| Install | VERIFIED | botscope 2.0.0 | +| doctor | VERIFIED | core ok | +| demo | VERIFIED | DEMO DATA; 20 events | +| pytest | VERIFIED | **131 passed, 3 skipped** | diff --git a/docs/acquisition/THIRD_PARTY_NOTICES.md b/docs/acquisition/THIRD_PARTY_NOTICES.md new file mode 100644 index 0000000..e59e76e --- /dev/null +++ b/docs/acquisition/THIRD_PARTY_NOTICES.md @@ -0,0 +1,25 @@ +# Third-Party Notices — BotScope + +**Date:** 2026-09-21 + +This file summarizes third-party materials observed in-tree. It is **not** a complete SBOM. + +## Package dependencies + +click, pydantic, rich, platformdirs, packaging; optional PySide6, scapy, numpy/sklearn, duckdb, httpx. No lockfile. No GPL/AGPL declared in core deps. + +Retain upstream license texts when redistributing binaries or bundled node_modules/site-packages. + +## Non-package third-party materials + +Public operator IP range JSON (Google, Bing, OpenAI, etc.) under operator terms; optional Cloudflare Radar API; synthetic demo datasets only. + +## Trademarks + +Third-party marks referenced in docs remain owned by their respective owners. Project disclaimers (where present) should be preserved. + +## Action items + +- [ ] Regenerate machine-readable SBOM at closing +- [ ] Confirm Qt/PySide6 redistribution path if shipping GUI wheels — **REQUIRES_LEGAL_REVIEW** +- [ ] Confirm any vendored trees still carry upstream LICENSE/NOTICE diff --git a/docs/acquisition/TRANSFER_MANIFEST.md b/docs/acquisition/TRANSFER_MANIFEST.md new file mode 100644 index 0000000..9177bb0 --- /dev/null +++ b/docs/acquisition/TRANSFER_MANIFEST.md @@ -0,0 +1,25 @@ +# Transfer Manifest — BotScope + +**Date:** 2026-09-21 + +| Asset | Category | Notes | +|-------|----------|-------| +| repository | TRANSFERABLE | github.com/theworker02/botscope | +| source code (original) | TRANSFERABLE | Subject to historical Apache grants | +| PyPI package botscope | TRANSFERABLE_WITH_CONSENT | Trusted Publishing / PyPI ownership transfer | +| datasets/demo + fixtures | TRANSFERABLE | Synthetic/hand-labeled; still confirm intent | +| operator IP list caches | PUBLIC/THIRD-PARTY | Not BotScope-owned; operator terms apply | +| Cloudflare Radar derived metrics | REQUIRES_PERMISSION | API/terms; token is buyer's | +| brand BotScope | TRANSFERABLE_WITH_CONSENT | Registration UNKNOWN | +| secrets | NONTRANSFERABLE | Rotate only | + +## Credentials migration checklist (no secrets committed) + +- [ ] Inventory GitHub secrets / Actions secrets +- [ ] Inventory cloud API tokens (Cloudflare, etc.) +- [ ] Inventory package registry tokens +- [ ] Inventory signing keys +- [ ] Rotate all of the above at closing — **ROTATE_IMMEDIATELY** if any exposure suspected +- [ ] Buyer creates replacement secrets in buyer-controlled accounts + +**NEVER commit credentials.** diff --git a/docs/acquisition/TRANSFER_PLAN.md b/docs/acquisition/TRANSFER_PLAN.md new file mode 100644 index 0000000..eb2ae1e --- /dev/null +++ b/docs/acquisition/TRANSFER_PLAN.md @@ -0,0 +1,16 @@ +# Transfer Plan — BotScope + +**Date:** 2026-09-21 +**Do not execute until a transaction closes.** + +1. Execute signed asset/IP agreement defining [ACQUIRED ASSETS]. +2. Transfer GitHub repository / org permissions. +3. Transfer package registries (npm/PyPI/Go module) where applicable. +4. Rotate all credentials; buyer provisions new secrets. +5. Update copyright notices only as counsel directs. +6. Publish change-of-control notice from template (after close). +7. Preserve historical LICENSE notices in git tags. +8. Verify build using BUYER_DEMO.md. +9. Produce transfer receipt. + +See TRANSFER_MANIFEST.md and CHANGE_OF_CONTROL_CHECKLIST.md. diff --git a/docs/legal/CHANGE_OF_CONTROL_NOTICE_TEMPLATE.md b/docs/legal/CHANGE_OF_CONTROL_NOTICE_TEMPLATE.md new file mode 100644 index 0000000..b17e702 --- /dev/null +++ b/docs/legal/CHANGE_OF_CONTROL_NOTICE_TEMPLATE.md @@ -0,0 +1,59 @@ +# Change-of-Control Notice Template + +> **STATUS: DORMANT TEMPLATE.** Do **not** publish this notice until an acquisition +> or change of control has actually closed. Filling placeholders prematurely +> constitutes a false public statement. + +**REQUIRES_LEGAL_REVIEW** before publication. + +--- + +# Change of Control Notice — BotScope + +**Effective date:** [EFFECTIVE DATE] +**Acquirer:** [ACQUIRER] +**New copyright holder (if different):** [NEW COPYRIGHT HOLDER] + +## What happened + +On [EFFECTIVE DATE], [ACQUIRER] completed an acquisition or change-of-control +transaction covering the following assets: + +**[ACQUIRED ASSETS]** +*(List precisely: repository, copyright in original works, trademarks, domains, +package registry names, documentation, etc. Do not list third-party materials, +historical open-source grants already received by third parties, or assets not +in the signed agreement.)* + +## What this means for users + +1. **Historical releases.** Versions distributed before the change of control + remain governed by the license terms that accompanied the copy you received, + where applicable. This notice does **not** revoke rights legitimately obtained + under prior licenses. +2. **Current and future versions.** Distributions on or after [EFFECTIVE DATE] + may be governed by [NEW LICENSE TERMS IF APPLICABLE] as published by + [NEW COPYRIGHT HOLDER]. +3. **Support.** Support contact: [NEW SUPPORT CONTACT]. + Security contact: [NEW SECURITY CONTACT]. + Commercial contact: [NEW COMMERCIAL CONTACT]. +4. **Transition period.** [TRANSITION PERIOD] — describe any grace period for + commercial licensees, if any, as stated in the transaction documents. + +## What is unchanged + +- Third-party components remain under their own licenses. +- Trademarks of unrelated parties are unaffected. +- Nothing in this notice transfers ownership of assets excluded from the + signed agreement. + +## Contact + +Commercial: [NEW COMMERCIAL CONTACT] +Security: [NEW SECURITY CONTACT] +Support: [NEW SUPPORT CONTACT] + +--- + +*This template is not legal advice. Counsel for both parties should finalize +wording against the executed asset purchase / IP assignment agreement.* diff --git a/docs/legal/RIGHTS_AND_ENFORCEMENT.md b/docs/legal/RIGHTS_AND_ENFORCEMENT.md new file mode 100644 index 0000000..a74378e --- /dev/null +++ b/docs/legal/RIGHTS_AND_ENFORCEMENT.md @@ -0,0 +1,70 @@ +# Rights and Enforcement + +**Project:** BotScope +**Asserted copyright holder (from repo notices):** theworker02 (https://github.com/theworker02) +**Status:** Template diligence language — **REQUIRES_LEGAL_REVIEW** before use +as a formal demand letter or public enforcement notice. + +This document is **not legal advice**. It does **not** assert that an acquisition +has occurred. It does **not** cancel rights legitimately obtained under prior licenses. + +## Categories of use + +### A. Users operating under valid historical licenses + +If you lawfully received a prior distribution expressly licensed under +**Apache License, Version 2.0 (Apache-2.0)**, that historical copy remains governed by the license terms +that accompanied it, where applicable. Nothing in the current repository +[`LICENSE`](../../LICENSE) or this document purports to revoke those grants for +that historical material. + +### B. Users operating under the current license + +Current repository contents are governed by the terms in [`LICENSE`](../../LICENSE). +Use within the rights expressly granted (for example, evaluation-only use where +that is the grant) is authorized. Use outside those rights is not. + +### C. Users exceeding their license + +Use of versions governed by the current license outside the rights expressly +granted may constitute unauthorized use. The applicable rights holder may +enforce its copyright, contractual, trademark, or other rights as permitted by +applicable law. + +### D. Unauthorized redistribution + +Redistribution of post-transition proprietary materials without a commercial +license or other written authorization may constitute unauthorized use. The +applicable rights holder may enforce its rights as permitted by applicable law. + +### E. Trademark misuse + +Project names, logos, and brand assets (where owned by the rights holder) may +not be used in a manner that suggests sponsorship, endorsement, or affiliation +without permission. Third-party trademarks (for example, Cloudflare, Honda, +vendor names) remain owned by their respective owners and are not transferred +by this project. + +### F. Misappropriation of proprietary versions + +Copying, hosting, or commercially exploiting proprietary post-transition +versions without authorization may constitute unauthorized use. The applicable +rights holder may enforce its rights as permitted by applicable law. + +## What this notice does **not** do + +- It does **not** claim that changing the repository license automatically + revokes already-granted open-source rights in historical copies. +- It does **not** threaten lawful users of previously open-source releases for + continuing to use those historical copies under their original terms. +- It does **not** assert that an acquirer owns assets outside a completed + transaction. +- It does **not** create fake legal certainty where ownership or contributor + chain-of-title remains incomplete. + +## Contact + +Licensing / commercial inquiries: GitHub [@theworker02](https://github.com/theworker02) + +**REQUIRES_LEGAL_REVIEW** for jurisdiction-specific demand language, damages +claims, and any public enforcement campaign. diff --git a/src/botscope/research/export.py b/src/botscope/research/export.py index 38fdbb5..9923b3d 100644 --- a/src/botscope/research/export.py +++ b/src/botscope/research/export.py @@ -53,7 +53,7 @@ def citation_cff_snippet() -> str: f"title: BotScope\n" f"version: {__version__}\n" f"url: https://github.com/theworker02/botscope\n" - f"license: Apache-2.0\n" + f"license: SEE LICENSE\n" f"# DOI: not assigned — do not invent one\n" )