On Sat, Aug 22, 2026 at 05:18:41PM -0000, andrew.lelechenko--- via ghc-devs wrote:
Interesting. I thought about possible applications of CLAs when writing the previous message, but could not find a convincing case, where they would provide any additional guarantees for an open-source project. I wonder what's the reason behind OpenSSL doing it this way. Is it perhaps to prevent a malicious committer, who introduced a security vulnerability, from avoiding legal responsibility by saying "it was not me, it was all LLM's doing"?..
My perhaps naïve understanding of the purpose of the CLA is that it makes it possible for the project to adjust the copyright conditions as needed (just once so far in ~26 years) without having to seek the consent of every past contributor. Contributors backed by an employer need to file both an individual CLA and a corporate CLA. Copyright and liability are I would conjecture separate concerns, and in any case not the motivation for CLAs. -- Viktor. 🇺🇦 Слава Україні!