Popularize the law for Livzon Pharmaceuticals, open source "freeloading" and legal consequences

Written by
Jasper Cole
Updated on:July-09th-2025
Recommendation

Livzon Pharmaceutical's open source "freeloading" incident triggered a legal discussion, and the pharmaceutical giant is facing an infringement crisis.

Core content:
1. Livzon Pharmaceutical submitted a PR to change the open source project logo, infringing the open source agreement and copyright
2. Leaking sensitive information such as internal keys and certificates, and huge risks to business secrets and data security
3. Analysis of the possible infringement consequences and legal liabilities that Livzon Pharmaceutical may face from a legal perspective

Yang Fangxian
Founder of 53AI/Most Valuable Expert of Tencent Cloud (TVP)

 

Dear readers, the Internet circle has been very lively recently, especially the open source community, which has staged a "big drama". One of the protagonists is actually Livzon Pharmaceutical, a listed company in our pharmaceutical industry. The thing is that Livzon Pharmaceutical submitted a "bold" pull request (PR) in the GitHub repository of the well-known open source project dify, directly changing the logo of the open source work to its own! This operation is simply the "domineering president falls in love with me" in the pharmaceutical industry, but this time the way of "love" is a bit off.

What is even more ridiculous is that the developer of Livzon Pharmaceutical may have "slipped his hand" and not only wanted to change the logo, but also submitted some internal keys, certificates and other sensitive information to Dify's main warehouse. This is like visiting someone's house and not only wanting to change the host's photo wall to your own, but also "contributing" your own safe password. It's embarrassing.

Dify was not happy about this. After all, it was an open source project that they had worked so hard to maintain, and you took advantage of it and directly exported it. This was intolerable! A lawyer's letter was sent to Livzon Pharmaceutical, demanding that it stop infringing on the rights and apologize.

However, the story does not end here, and the plot has a more shocking twist! According to the latest news, after the "brand change" incident attracted widespread attention and criticism, the developers of Livzon Pharmaceuticals actually sent insulting emails to more than 400 code contributors to the Dify project! This is simply adding fuel to the fire. They keep making mistakes and have no remorse, not to mention that this is a listed pharmaceutical company!

So, from a legal perspective, as a listed company, what mistakes did Livzon Pharmaceutical make in this series of actions, and what possible consequences will it face? Let's talk about it today.

1. Knowingly committing the act of “changing the logo”: infringing on open source agreements and copyrights

Dify is an open source project based on the Apache protocol, and its license file explicitly adds two restrictions: prohibiting the sale of multi-tenant SaaS services based on Dify, and prohibiting the modification of the logo. This is like living in a residential community, where the property management stipulates that you cannot change the external environment without permission. If you insist on painting your neighbor's door in your favorite color, this is definitely not allowed.

Livzon Pharmaceuticals knew that Dify's open source agreement clearly prohibited changing the logo, but still submitted such a PR, which is undoubtedly a blatant violation of the open source agreement. The open source agreement is essentially a legal agreement. Although it is usually free, users must abide by its terms. Livzon Pharmaceuticals' behavior has constituted a breach of the Dify open source agreement.

Furthermore, Dify's logo itself is also protected by copyright law. Modifying and replacing someone else's logo without permission is a typical act of copyright infringement. This is like using someone else's logo on your own product without authorization, which will lead to a lawsuit.

2. Security risks behind “slip of the hand”: business secrets and data security

In addition to the "face" issue of changing the logo, Livzon Pharmaceutical's more serious mistake was that it actually submitted sensitive information such as internal keys and certificates to the public GitHub repository. This is simply hanging the key to its own safe directly on the street, and the risks can be imagined.

For a listed company, trade secrets and data security are extremely important. Keys and certificates often involve the company's core business systems, data interfaces, etc. Once leaked, it may lead to serious data security issues and the leakage of trade secrets.

3. Adding insult to injury: potential defamation and mental damage

If the previous behavior could be considered an "unintentional mistake," then after the incident fermented, the developers of Livzon Pharmaceutical actually sent abusive emails to hundreds of Dify contributors, which was a completely malicious and proactive attack.

From a legal perspective, this behavior is likely to constitute defamation. If the content of the email contains insults, defamation, or other information that degrades the personality and reputation of others, the victim can pursue legal liability against Livzon Pharmaceutical and its relevant responsible persons, and may demand compensation for mental damages. In addition, this behavior also seriously violates the collaborative spirit and basic ethical standards of the open source community.

IV. The “willfulness” of listed companies: lack of information disclosure and corporate governance

As a listed company, every move of Livzon Pharmaceutical is watched by the public and investors. Such blatant violation of the open source agreement, attempt to infringe others' intellectual property rights, and even taking such bad measures after the fact not only damages its own reputation, but also exposes its serious problems in corporate governance and information disclosure.

According to the information disclosure requirements of listed companies, Livzon Pharmaceutical may need to disclose to investors in a timely and accurate manner such events involving legal disputes, potential significant losses, and serious damage to the company's image. Failure to fulfill information disclosure obligations may result in penalties from regulatory authorities.

In addition, this series of events also reflects that Livzon Pharmaceutical has significant defects in corporate governance, such as insufficient understanding of open source culture, chaotic internal management, poor employee quality, and indifference to laws and intellectual property rights.

5. The “counterattack” of the open source community: maintaining rules and respecting innovation

As a member of the open source community, Dify's maintainers actively speak out and take legal measures to protect their own rights and interests, which is of great significance to the entire open source community. This series of actions by Livzon Pharmaceutical is undoubtedly a trampling on the spirit of open source, and it also sounded a wake-up call to other companies that try to "freeload" on open source results: open source is not a free lunch, and those who use open source projects must abide by their rules and respect the fruits of others' labor. Any attempt to gain benefits through improper means will face legal and moral condemnation.

Predicted consequences:

Bear multiple legal responsibilities: Livzon Pharmaceutical may bear legal responsibilities for multiple illegal acts such as violating open source agreements, infringing copyrights and defamation, and face penalties such as compensation and apology. Involvement of regulatory agencies: Securities regulatory agencies may investigate Livzon Pharmaceutical, hold it accountable for information disclosure, corporate governance and internal management, and may impose more severe penalties. Loss of business reputation: Such bad behavior will seriously damage Livzon Pharmaceutical's business reputation and affect its future cooperation and development. Investor confidence is frustrated: Investors may lose confidence in Livzon Pharmaceutical's management level and risk control capabilities, resulting in a drop in stock prices. Talent loss: A negative corporate image and poor community relations may lead to talent loss and affect the company's long-term development.



Legal advice to Livzon Pharmaceutical:

Immediately cease all infringement and unfair conduct:

Withdraw all PRs for changing the logo, and publicly and sincerely apologize to the Dify community and all victims, especially take responsibility for the bad behavior of sending abusive emails. Seriously deal with those involved: Seriously deal with the relevant responsible persons, including the developer who sent the abusive email, and make the results public to calm public anger.

Actively communicate with the Dify community and seek reconciliation:

Actively communicate with the Dify community, apologize to the developers, seek reasonable solutions, make up for the damage caused, and strive to gain forgiveness.

Comprehensively review and improve internal management and development processes:

Strengthen employees' legal awareness, intellectual property protection awareness and professional ethics education, establish a sound internal management and development process, and avoid similar incidents from happening again. Fulfill the information disclosure obligations of listed companies: Disclose the progress and possible impact of the incident to investors in a timely and accurate manner.

Hire a professional legal and public relations team: Actively respond to legal risks and public opinion crises, and strive to restore the company's image.

Conclusion:

Livzon Pharmaceutical's series of "confusing behaviors" in the open source community can be regarded as a living negative teaching material. As a well-known listed company, it should cherish its reputation, respect the intellectual property rights of others, and abide by basic business ethics and laws and regulations. It is hoped that Livzon Pharmaceutical can deeply reflect on this incident and take practical and effective measures to make up for its mistakes. Otherwise, it will face more serious legal consequences and market penalties. At the same time, this also warns all companies that when participating in open source projects, they must maintain awe, respect the rules and culture of the open source community, and jointly maintain a healthy, open, and cooperative innovation ecosystem.