You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 1d915db
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: LICENSE.md
+96-80Lines changed: 96 additions & 80 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,133 +19,149 @@ This GitHub AI Scan License (the **"License"**) governs the limited right to dow
19
19
20
20
## 2. **LICENSE GRANT**
21
21
22
-
### 1. **Grant.** Subject to the Agreement and the License, GitHub grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the period of Authorized Access to:
22
+
### 2.1. **Grant.** Subject to the Agreement and the License, GitHub grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license during the period of Authorized Access to:
23
23
24
-
- (a) permit an approved GitHub Actions workflow associated with an Authorized Codebase to download the unmodified Runtime from the GitHub-designated distribution location;
25
-
- (b) make temporary or cached copies of the Runtime that are technically required to execute the workflow;
26
-
- (c) execute the unmodified Runtime on an Approved Runner;
27
-
- (d) invoke the Runtime only through an Approved Invocation;
28
-
- (e) use the Runtime only to scan Authorized Codebases; and
29
-
- (f) receive and use security findings generated by AI Scan for the Customer's internal security purposes.
24
+
<oltype="a">
25
+
<li>permit an approved GitHub Actions workflow associated with an Authorized Codebase to download the unmodified Runtime from the GitHub-designated distribution location;</li>
26
+
<li>make temporary or cached copies of the Runtime that are technically required to execute the workflow;</li>
27
+
<li>execute the unmodified Runtime on an Approved Runner;</li>
28
+
<li>invoke the Runtime only through an Approved Invocation;</li>
29
+
<li>use the Runtime only to scan Authorized Codebases; and</li>
30
+
<li>receive and use security findings generated by AI Scan for the Customer's internal security purposes.</li>
31
+
</ol>
30
32
31
-
### 1. **Automated Copying and Execution.** The license in Section 2.1 expressly permits the automated download, caching, and execution of the Runtime that occurs when a GitHub Actions workflow runs AI Scan on an Approved Runner.
33
+
### 2.2. **Automated Copying and Execution.** The license in Section 2.1 expressly permits the automated download, caching, and execution of the Runtime that occurs when a GitHub Actions workflow runs AI Scan on an Approved Runner.
32
34
33
-
### 2. **License Conditions.** The license is conditioned on and continues only while the Customer maintains:
35
+
### 2.3.**License Conditions.** The license is conditioned on and continues only while the Customer maintains:
34
36
35
-
- (a) a valid Agreement;
36
-
- (b) Authorized Access;
37
-
- (c) applicable enterprise, organization, and repository enablement of AI Scan;
38
-
- (d) payment of applicable AI consumption charges;
39
-
- (e) compliance with the Customer's model policies and GitHub's approved-model list; and
40
-
- (f) compliance with GitHub's Acceptable Use Policies and applicable law.
37
+
<oltype="a">
38
+
<li>a valid Agreement;</li>
39
+
<li>Authorized Access;</li>
40
+
<li>applicable enterprise, organization, and repository enablement of AI Scan;</li>
41
+
<li>payment of applicable AI consumption charges;</li>
42
+
<li>compliance with the Customer's model policies and GitHub's approved-model list; and</li>
43
+
<li>compliance with GitHub's Acceptable Use Policies and applicable law.</li>
44
+
</ol>
41
45
42
-
### 1. **No Source or Internal Materials.** No rights are granted to source code, system prompts, scanning logic, build instructions, tests, evaluation materials, model weights, query logic, or other internal materials of GitHub.
46
+
### 2.4. **No Source or Internal Materials.** No rights are granted to source code, system prompts, scanning logic, build instructions, tests, evaluation materials, model weights, query logic, or other internal materials of GitHub.
43
47
44
-
## 1. **RESTRICTIONS**
48
+
## 3. **RESTRICTIONS**
45
49
46
-
### 1. **Restrictions.** Except to the extent required by mandatory law or by an applicable third-party license, Customer must not, and must not allow any third party to:
50
+
### 3.1. **Restrictions.** Except to the extent required by mandatory law or by an applicable third-party license, Customer must not, and must not allow any third party to:
47
51
48
-
- (a) directly invoke or operate the Runtime outside an Approved Invocation;
49
-
- (b) modify, adapt, translate, or create derivative works from the Runtime;
50
-
- (c) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, prompts, or internal operation of the Runtime;
51
-
- (d) redistribute, publish, transfer, lend, or sublicense the Runtime;
52
-
- (e) sell, lease, or commercially exploit the Runtime;
53
-
- (f) offer the Runtime as a standalone or integrated product or hosted scanning service;
54
-
- (g) use the Runtime to provide scanning services to third parties;
55
-
- (h) bypass authentication, entitlement checks, model policies, consumption meters, technical restrictions, or usage limits;
56
-
- (i) remove or alter copyright, trademark, attribution, or proprietary notices;
57
-
- (j) scan a repository or codebase that Customer is not authorized to test;
58
-
- (k) use the Runtime in violation of law, applicable sanctions, export controls, or the Agreement; or
59
-
- (l) use a copied or cached Runtime after Authorized Access ends, except as necessary for ordinary automated technical cleanup.
52
+
<oltype="a">
53
+
<li>directly invoke or operate the Runtime outside an Approved Invocation;</li>
54
+
<li>modify, adapt, translate, or create derivative works from the Runtime;</li>
55
+
<li>reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, prompts, or internal operation of the Runtime;</li>
56
+
<li>redistribute, publish, transfer, lend, or sublicense the Runtime;</li>
57
+
<li>sell, lease, or commercially exploit the Runtime;</li>
58
+
<li>offer the Runtime as a standalone or integrated product or hosted scanning service;</li>
59
+
<li>use the Runtime to provide scanning services to third parties;</li>
60
+
<li>bypass authentication, entitlement checks, model policies, consumption meters, technical restrictions, or usage limits;</li>
61
+
<li>remove or alter copyright, trademark, attribution, or proprietary notices;</li>
62
+
<li>scan a repository or codebase that Customer is not authorized to test;</li>
63
+
<li>use the Runtime in violation of law, applicable sanctions, export controls, or the Agreement; or</li>
64
+
<li>use a copied or cached Runtime after Authorized Access ends, except as necessary for ordinary automated technical cleanup.</li>
65
+
</ol>
60
66
61
-
### 1. **Mandatory-Law Exception.** The restrictions in Section 3.1(c) do not apply to the extent applicable law grants Customer non-waivable rights to reverse engineer for interoperability or similar purposes.
67
+
### 3.2. **Mandatory-Law Exception.** The restrictions in Section 3.1(c) do not apply to the extent applicable law grants Customer non-waivable rights to reverse engineer for interoperability or similar purposes.
### 1. **Distribution Mechanism Only.** GitHub may host the Runtime in a publicly accessible repository solely so that GitHub Actions workflows can download and execute it. Public accessibility is a distribution mechanism only.
71
+
### 4.1. **Distribution Mechanism Only.** GitHub may host the Runtime in a publicly accessible repository solely so that GitHub Actions workflows can download and execute it. Public accessibility is a distribution mechanism only.
66
72
67
-
### 2. **No Open Source; No Implied Grant.** Public availability of the Runtime:
73
+
### 4.2. **No Open Source; No Implied Grant.** Public availability of the Runtime:
68
74
69
-
- (a) does not make the Runtime open-source software;
70
-
- (b) does not grant any person access to AI Scan or GitHub's AI services;
71
-
- (c) does not grant any license to any person who does not have Authorized Access;
72
-
- (d) does not create any entitlement based on mere possession of a copy; and
73
-
- (e) does not limit GitHub's right to authenticate, authorize, meter, throttle, disable, or reject use of the Runtime or the AI service.
75
+
<oltype="a">
76
+
<li>does not make the Runtime open-source software;</li>
77
+
<li>does not grant any person access to AI Scan or GitHub's AI services;</li>
78
+
<li>does not grant any license to any person who does not have Authorized Access;</li>
79
+
<li>does not create any entitlement based on mere possession of a copy; and</li>
80
+
<li>does not limit GitHub's right to authenticate, authorize, meter, throttle, disable, or reject use of the Runtime or the AI service.</li>
81
+
</ol>
82
+
83
+
### 4.3. **Access Controls.** Access to AI Scan services remains subject to authentication, product entitlement, customer model policy, and consumption controls. GitHub may technically block or reject unauthorized use.
74
84
75
-
### 1. **Access Controls.** Access to AI Scan services remains subject to authentication, product entitlement, customer model policy, and consumption controls. GitHub may technically block or reject unauthorized use.
85
+
##5. **THIRD-PARTY SOFTWARE**
76
86
77
-
##1. **THIRD-PARTY SOFTWARE**
87
+
### 5.1. **Third-Party Components.** The Runtime may include third-party or open-source components governed by their own license terms. Applicable notices are provided with the Runtime.
78
88
79
-
### 1.**Third-Party Components.**The Runtime may include third-party or open-source components governed by their own license terms. Applicable notices are provided with the Runtime.
89
+
### 5.2.**Precedence for Third-Party Components.**This License does not restrict rights granted to Customer directly under an applicable open-source or third-party license. If a third-party license conflicts with this License for a specific component, the third-party license controls for that component.
80
90
81
-
### 2. **Precedence for Third-Party Components.** This License does not restrict rights granted to Customer directly under an applicable open-source or third-party license. If a third-party license conflicts with this License for a specific component, the third-party license controls for that component.
91
+
##6. **AI SERVICES AND CUSTOMER DATA**
82
92
83
-
##2.**AI SERVICES AND CUSTOMER DATA**
93
+
### 6.1.**AI Services.** The Runtime invokes GitHub-hosted AI and related services. This License does not independently grant access to those services. Use of the services is governed by the Agreement and the applicable product, generative-AI, privacy, and data-protection terms.
84
94
85
-
### 3.**AI Services.**The Runtime invokes GitHub-hosted AI and related services. This License does not independently grant access to those services. Use of the services is governed by the Agreement and the applicable product, generative-AI, privacy, and data-protection terms.
95
+
### 6.2.**Models and Findings.**Model availability is subject to GitHub support and Customer model policies. Security findings may be AI-generated. Product documentation describes relevant processing, retention, and controls.
86
96
87
-
### 4. **Models and Findings.** Model availability is subject to GitHub support and Customer model policies. Security findings may be AI-generated. Product documentation describes relevant processing, retention, and controls.
### 7.1.**Separately Licensed Products.** GitHub products, services, or components that are separately licensed remain subject to their own terms. This License does not grant rights to any such product, service, or component.
90
100
91
-
### 5. **Separately Licensed Products.** GitHub products, services, or components that are separately licensed remain subject to their own terms. This License does not grant rights to any such product, service, or component.
101
+
##8. **OWNERSHIP**
92
102
93
-
##4.**OWNERSHIP**
103
+
### 8.1.**Ownership.** GitHub and its licensors retain all right, title, and interest in and to the Runtime. The Runtime is licensed, not sold.
94
104
95
-
### 6.**Ownership.**GitHub and its licensors retain all right, title, and interest in and to the Runtime. The Runtime is licensed, not sold.
105
+
### 8.2.**No Implied Licenses.**No licenses are granted by implication, estoppel, or otherwise. GitHub reserves all rights not expressly granted. No source-code rights and no trademark or branding rights are granted.
96
106
97
-
### 7.**No Implied Licenses.**No licenses are granted by implication, estoppel, or otherwise. GitHub reserves all rights not expressly granted. No source-code rights and no trademark or branding rights are granted.
107
+
### 8.3.**Customer Content.**Customer retains its rights in its code and other content, subject to the Agreement.
98
108
99
-
### 8. **Customer Content.** Customer retains its rights in its code and other content, subject to the Agreement.
109
+
##9. **UPDATES AND TECHNICAL OPERATION**
100
110
101
-
##5.**UPDATES AND TECHNICAL OPERATION**
111
+
### 9.1.**Updates.** GitHub may issue automatic or required Runtime updates, and may replace, deprecate, or discontinue Runtime versions.
102
112
103
-
### 9. **Updates.** GitHub may issue automatic or required Runtime updates, and may replace, deprecate, or discontinue Runtime versions.
113
+
### 9.2.**Integrity.** GitHub may use checksums, signatures, or other integrity controls. Customer must not circumvent them.
104
114
105
-
### 10.**Integrity.** GitHub may use checksums, signatures, or other integrity controls. Customer must not circumvent them.
115
+
### 9.3.**Caching and Cleanup.** GitHub Actions may temporarily cache the Runtime. GitHub may remove or invalidate obsolete versions. Direct local use of the Runtime is not supported.
106
116
107
-
### 11.**Caching and Cleanup.** GitHub Actions may temporarily cache the Runtime. GitHub may remove or invalidate obsolete versions. Direct local use of the Runtime is not supported.
117
+
### 9.4.**No Compatibility Promise.** GitHub does not promise backward compatibility, a fixed model, continued availability of any version, or any specific feature except as required by the Agreement.
108
118
109
-
### 12. **No Compatibility Promise.** GitHub does not promise backward compatibility, a fixed model, continued availability of any version, or any specific feature except as required by the Agreement.
119
+
##10. **TERM AND TERMINATION**
110
120
111
-
##6.**TERM AND TERMINATION**
121
+
### 10.1.**Term.** This License is effective on the Effective Date and continues only while the Customer has Authorized Access.
112
122
113
-
### 13.**Term.** This License is effective on the Effective Date and continues only while the Customer has Authorized Access.
123
+
### 10.2.**Termination.** This License terminates automatically when Authorized Access ends and may be terminated by GitHub for breach or as permitted by the Agreement.
114
124
115
-
### 14.**Termination.**This License terminates automatically when Authorized Access ends and may be terminated by GitHub for breach or as permitted by the Agreement.
125
+
### 10.3.**Effect of Termination.**On termination or expiration:
116
126
117
-
### 15. **Effect of Termination.** On termination or expiration:
127
+
<oltype="a">
128
+
<li>Customer must stop using the Runtime;</li>
129
+
<li>all rights granted under this License end;</li>
130
+
<li>Customer must delete copies of the Runtime under its control, subject to ordinary automated backup and cache-cleanup processes;</li>
131
+
<li>GitHub may disable access to the AI service; and</li>
132
+
<li>accrued payment obligations and Sections 3, 4, 5, 7, 8, 10.3, 11, and 12 survive.</li>
133
+
</ol>
118
134
119
-
- (a) Customer must stop using the Runtime;
120
-
- (b) all rights granted under this License end;
121
-
- (c) Customer must delete copies of the Runtime under its control, subject to ordinary automated backup and cache-cleanup processes;
122
-
- (d) GitHub may disable access to the AI service; and
123
-
- (e) accrued payment obligations and Sections 3, 4, 5, 7, 8, 10.3, 11, and 12 survive.
135
+
### 10.4. **Public Availability After Termination.** The Runtime may remain technically downloadable from the public repository after termination. Continued public availability does not extend or revive any license.
124
136
125
-
### 1. **Public Availability After Termination.** The Runtime may remain technically downloadable from the public repository after termination. Continued public availability does not extend or revive any license.
137
+
##11. **WARRANTIES, LIABILITY, AND AGREEMENT HIERARCHY**
126
138
127
-
##1. **WARRANTIES, LIABILITY, AND AGREEMENT HIERARCHY**
139
+
### 11.1. **Agreement Controls.** Warranty disclaimers, liability limitations, indemnities, governing-law, dispute-resolution, export, and trade-compliance obligations are governed by the Agreement and incorporated by reference. Support and service levels are governed by the Agreement and applicable product documentation.
128
140
129
-
### 1.**Agreement Controls.**Warranty disclaimers, liability limitations, indemnities, governing-law, dispute-resolution, export, and trade-compliance obligations are governed by the Agreement and incorporated by reference. Support and service levels are governed by the Agreement and applicable product documentation.
141
+
### 11.2.**AI Output Disclaimer.**AI Scan findings may be inaccurate, incomplete, or fail to identify vulnerabilities. AI Scan supplements and does not replace Customer's own security testing, secure-development practices, and code review.
130
142
131
-
### 2.**AI Output Disclaimer.**AI Scan findings may be inaccurate, incomplete, or fail to identify vulnerabilities. AI Scan supplements and does not replace Customer's own security testing, secure-development practices, and code review.
143
+
### 11.3.**Mandatory Law.**Nothing in this License limits rights or remedies that cannot be limited under applicable mandatory law.
132
144
133
-
### 3.**Mandatory Law.**Nothing in this License limits rights or remedies that cannot be limited under applicable mandatory law.
145
+
### 11.4.**Fallback Standalone Terms.**If no Agreement supplies governing law, this License is governed by the laws of the State of California, excluding conflicts-of-law rules, with exclusive venue in the state and federal courts located in San Francisco County, California. [VERIFY]
134
146
135
-
### 4. **Fallback Standalone Terms.** If no Agreement supplies governing law, this License is governed by the laws of the State of California, excluding conflicts-of-law rules, with exclusive venue in the state and federal courts located in San Francisco County, California. [VERIFY]
147
+
##12. **ACCEPTANCE AND INCORPORATION**
136
148
137
-
##2.**ACCEPTANCE AND INCORPORATION**
149
+
### 12.1.**Acceptance.** This License is accepted by the earliest of:
138
150
139
-
### 5. **Acceptance.** This License is accepted by the earliest of: (a) the Customer's execution or acceptance of an Agreement that incorporates this License by reference; (b) the Customer's acceptance of a preview invitation that incorporates this License; or (c) the Customer's download, installation, or execution of the Runtime.
151
+
<oltype="a">
152
+
<li>the Customer's execution or acceptance of an Agreement that incorporates this License by reference;</li>
153
+
<li>the Customer's acceptance of a preview invitation that incorporates this License; or</li>
154
+
<li>the Customer's download, installation, or execution of the Runtime.</li>
155
+
</ol>
140
156
141
-
## 3. **GENERAL**
157
+
## 13. **GENERAL**
142
158
143
-
### 6. **Notices.** Notices are given as provided in the Agreement.
159
+
### 13.1. **Notices.** Notices are given as provided in the Agreement.
144
160
145
-
### 7. **Assignment.** Customer must not assign License except as permitted by the Agreement. GitHub may assign to an affiliate or successor.
161
+
### 13.2. **Assignment.** Customer must not assign License except as permitted by the Agreement. GitHub may assign to an affiliate or successor.
146
162
147
-
### 8. **Entire Agreement; Amendments.** Together with the Agreement and referenced documents, this License is the entire agreement regarding the Runtime. Amendments are governed by the Agreement.
163
+
### 13.3. **Entire Agreement; Amendments.** Together with the Agreement and referenced documents, this License is the entire agreement regarding the Runtime. Amendments are governed by the Agreement.
148
164
149
-
### 9. **Severability.** If a provision is unenforceable, the remainder remains in effect.
165
+
### 13.4. **Severability.** If a provision is unenforceable, the remainder remains in effect.
150
166
151
-
### 10. **Counterparts; Electronic Signatures.** This License may be accepted electronically and in counterparts.
167
+
### 13.5. **Counterparts; Electronic Signatures.** This License may be accepted electronically and in counterparts.
0 commit comments