Waiver registry
A repository's administrators can waive the fee for a named organisation. Every waiver is public, repository-scoped, and free — selling one is a delisting offence, because a private exemption is exactly the side-deal this movement exists to make impossible.
6 recorded 4 live 1 inside the cooling window
Every waiver ever recorded, including revoked and voided ones. Computed at 2026-09-03T16:17:53Z · evaluated as of 2026-11-20T09:00:00Z · updated within minutes.
| Organisation | Repository | Scope | Granted | Revocation | Cooling window |
|---|---|---|---|---|---|
| Larkspur Analytics no verified domain — reachable through the grant's company stub | helvetica-tools/sheet-diff | repository | 2026-09-14T10:00:00Z | not revoked | closed 2026-09-17T10:00:00Z — vested |
| Rivermouth Cooperative no verified domain — reachable through the grant's company stub | helvetica-tools/ledgerlint | repository | 2026-09-16T08:30:00Z | not revoked | closed 2026-09-19T08:30:00Z — vested |
| Harbourline Ports Authority no verified domain — reachable through the grant's company stub | northwind-labs/gale | repository | 2026-09-18T15:00:00Z | revoked 2026-09-28T09:00:00Z, prospectively: versions published on or before that date stay usable by this organisation permanently | closed 2026-09-21T15:00:00Z — vested |
| Tessellate Cloud Inc tessellate-cloud.example | mossbank/tidewatch | repository | 2026-09-19T11:45:00Z | not revoked | closed 2026-09-22T11:45:00Z — vested |
| Kettleworth School Trust no verified domain — reachable through the grant's company stub | quietriver/quill-pdf | repository | 2026-11-19T13:00:00Z | not revoked | open until 2026-11-22T13:00:00Z — covered now, vesting attaches when it closes |
| Larkspur Analytics no verified domain — reachable through the grant's company stub | sample-collective/atlas-forms | repository | 2026-09-21T14:00:00Z | void ab initio — revoked 2026-09-22T09:30:00Z, inside the window, so nothing ever vested | closed by revocation inside the window |
How waivers behave
A waiver is the project steward's licence-vested power to exempt a named organisation from the Purpose Condition for their repository. The Association is registrar and witness: the administrators grant it, we record it and witness it, and the beneficiary receives a signed Waiver Certificate — never a licence from us, because we hold no rights in anyone's code and could not grant one.
- Public, always. Never per-organisation and never private. A private waiver would make coverage unanswerable, and an invisible exemption is the side-deal scandal vector this rule exists to close. Publicity also protects administrators: a corporation cannot lobby quietly for something that appears on this page.
- Gratis, always. An administrator who sells an exemption is delisted. There is no fee a waiver can carry, so there is nothing to negotiate.
- Repository-scoped. A waiver covers the repository that granted it and nothing else. Any verified administrator of that repository may grant or revoke one.
- Revocation is prospective. Versions published on or before the revocation stay usable by the beneficiary forever — the same vesting formula every Entitlement uses, with "term end" meaning the revocation or expiry date. Revocation cuts off future releases only.
- A 72-hour cooling window. A waiver is effective immediately — coverage answers yes from the moment of grant — but permanent vesting attaches only when the window closes. A revocation inside the window voids the waiver ab initio: nothing vested, because nothing had time to. That is the answer to a compromised administrator account, which live re-verification cannot detect: the window kills the permanence of the attack without making the ordinary case slow.
- Step-up re-authentication at grant, every co-administrator notified, one shared per-repository audit log, and an optional two-administrator approval for repositories that want it. Disputes between co-administrators are the project's own governance: we record outcomes and never arbitrate.
- Unclaimed repositories have no waivers. Waiving requires the claim, because a waiver has to be attributable to a verified administrator to mean anything.
- A waived organisation gets a licence-status certificate only — never a supporter or impact certificate. They funded nothing, and a certificate implying otherwise would be a misleading claim we handed them ourselves.
Machine access: /v1/waivers/all.json and
/v1/waivers/{node_id}.json, both ETagged; same-origin static copies
at /artifacts/waivers/all.json. See the API reference.