ARSVIN GitHub

External IP and Provenance Review — 2026-07-14

This is a repository-evidence and process review. It is not a legal opinion and cannot establish every off-repository fact or contractual obligation.

Scope

The review covers the current ARSVIN repository, Publisher and Subscriber applications, shared engine, tests, samples, release automation, documentation, website, screenshots, and public claims.

Repository evidence

At the review date, the tracked project presents ARSVIN as an independently developed IEC 61850 Sampled Values engineering suite. The current source uses project-owned architecture and application assets together with separately identified dependencies listed in THIRD_PARTY_NOTICES.md.

Repository inspection can identify tracked source, dependencies, notices, assets, wording, and contribution records. It cannot prove the absence of undisclosed private material, establish employer ownership, or resolve invention-assignment, confidentiality, customer, equipment-use, or working-time obligations.

Git account and commit attribution identify repository activity; they are not by themselves conclusive proof of legal ownership.

External implementation boundary

External software may be used only as a lawfully licensed black-box interoperability endpoint within the applicable license, organizational policy, and authorization boundary.

The following must not be used as ARSVIN implementation design material unless the project has documented redistribution and relicensing rights:

Observed behavior must be reduced to neutral protocol facts and independently implemented and tested.

Fixtures and evidence

Public fixtures should be synthetic or contributor-owned. A real SCL, COMTRADE, PCAP, screenshot, or diagnostic sample requires documented authority to share, sanitization, and a clear provenance record.

Do not publish credentials, customer or employer identifiers, station names, restricted addressing, production network plans, private support material, or captures whose redistribution rights are uncertain.

Licensing transition

The historical Apache-2.0 boundary is commit 9440f08b6909ef2dc93dd483cfdcb4e1e86077d0, retained on archive/apache-2.0-final. Later community revisions are offered under GPL-3.0-or-later.

A separate commercial path may cover only rights controlled by the relevant copyright holder. Third-party and historical material remains subject to its applicable license.

Controls

Remaining manual checks

Before a significant commercial agreement, review:

Conclusion

The repository controls support a defensible independent-development and dual-channel licensing process. They reduce, but do not eliminate, copyright, license, trademark, confidentiality, contractual, or ownership risk.

GPL-3.0-or-later community documentation. Commercial terms require a separate agreement.Review this page on GitHub →