Licenses
Anatomy of a licence, families, compatibility, SPDX identifiers, how to choose and apply, and what enforcement looks like.
FOSS Licenses
A licence is the only thing that makes code reusable. Without one, copyright defaults to "all rights reserved" and nobody may copy, modify or distribute your work.
Nothing here is legal advice. Licence interactions — especially around patents, SaaS and distribution — are fact-specific. For anything contractual, use a lawyer who has read your actual dependency tree.
1. Anatomy of a licence
| Part | What it does | Why you care |
|---|---|---|
| Grant | Permits use, copying, modification, distribution | The whole point. Missing → unusable code |
| Conditions | Attribution, notice preservation, source disclosure | Your compliance workload |
| Copyleft scope | How far "share alike" reaches: file, library, whole work, network | Whether you must release your own source |
| Patent grant | Express (Apache-2.0 §3, GPLv3 §11) or absent (MIT, BSD) | Litigation risk from contributors |
| Trademark | Nearly always excluded; Apache-2.0 §6 says so explicitly | You may not use the project's name or logo |
| Warranty disclaimer | "AS IS", no liability | Why vendors sell indemnity |
| Termination | GPL: automatic on violation. GPLv3: cure periods (30/60 days) | Non-compliance can cost you the licence entirely |
| Version clause | -only vs -or-later | Determines future compatibility |
Copyleft triggers on distribution, not use. GPL obligations fire when you convey the software. Running modified GPL software internally is fine. AGPL additionally treats network interaction as distribution — that is the entire point of AGPL.
2. The families
| Licence | SPDX ID | Type | Patent grant | Notes |
|---|---|---|---|---|
| MIT | MIT | Permissive | No express grant | ~170 words; maximum adoption |
| ISC | ISC | Permissive | No | MIT without the warranty paragraph |
| BSD 2-Clause | BSD-2-Clause | Permissive | No | Notice only |
| BSD 3-Clause | BSD-3-Clause | Permissive | No | Adds no-endorsement. The old 4-clause advertising term is GPL-incompatible |
| Apache 2.0 | Apache-2.0 | Permissive | Yes — express + defensive termination | NOTICE propagation; the corporate default |
| MPL 2.0 | MPL-2.0 | File copyleft | Yes | Share changes to covered files; GPL-compatible by design (§3.3) |
| EPL 2.0 | EPL-2.0 | Weak copyleft | Yes | Eclipse/Jakarta; patent retaliation |
| LGPL 2.1 / 3.0 | LGPL-2.1-or-later, LGPL-3.0-or-later | Library copyleft | v3: yes | Proprietary programs may link |
| GPL 2.0 | GPL-2.0-only / GPL-2.0-or-later | Strong copyleft | Implied | The kernel's licence; incompatible with Apache-2.0 per the FSF |
| GPL 3.0 | GPL-3.0-only / GPL-3.0-or-later | Strong copyleft | Yes — express | Anti-tivoisation, install-info, cure periods |
| AGPL 3.0 | AGPL-3.0-only / AGPL-3.0-or-later | Network copyleft | Yes | Network users get a source offer (§13) |
| CC0 1.0 | CC0-1.0 | Public domain | No express | For data and docs, not recommended for code |
The canonical registry is the SPDX License List (3.29.0, 2026-09-16) with 700+ identifiers. The OSI's approved list is a much smaller curated subset (~100 licences).
3. Compatibility
| Combining | Result | Reason |
|---|---|---|
| MIT / BSD-2 / BSD-3 / ISC → GPLv2 or v3 | OK | No additional restrictions |
| Apache-2.0 → GPLv3 | OK | GPLv3 §7 accepts Apache's additional terms |
| Apache-2.0 → GPLv2-only | No | Apache's patent-termination clause is an added restriction |
| MPL-2.0 → GPL / AGPL | OK | MPL 2.0 §3.3 has an explicit compatibility clause |
| GPLv2-only → GPLv3 | No | Different terms; -or-later solves it |
| LGPL → GPL | OK | LGPL permits "upgrading" the copyleft |
| GPLv3 → AGPLv3 | OK | AGPLv3 §13 permits combination |
| CC-BY-4.0 / CC-BY-SA-4.0 → GPLv3 | One-way | 4.0 added GPLv3 compatibility; CC 1.0–3.0 did not |
| Permissive → proprietary product | OK | Keep the notice |
| Copyleft → proprietary product | No | Unless you also disclose your source |
Linking is the hard question. Whether dynamically linking your code to a GPL library creates a derivative work is unsettled; the FSF says yes, and the LGPL exists to remove the doubt. Do not build a product strategy on the assumption that a shared-library boundary protects you.
4. SPDX identifiers and expressions
// Source file header (REUSE-compatible)
// SPDX-FileCopyrightText: 2026 Ada Lovelace <ada@example.org>
// SPDX-License-Identifier: Apache-2.0
# package.json / Cargo.toml / pyproject.toml
"license": "(MIT OR Apache-2.0)"
# Dual licensing: recipient chooses
"Apache-2.0 OR MIT"
# Copyleft with an exception
"GPL-3.0-or-later WITH Classpath-exception-2.0"
# Internal use: not a licence, but machine-readable
"LicenseRef-Proprietary"Operators: AND (both apply to different parts), OR (recipient chooses), WITH (exception). Deprecated
IDs like bare GPL-2.0 are ambiguous — always use -only or -or-later.
5. Choosing a licence
Pick permissive (MIT / Apache-2.0) when…
- You want maximum adoption, including by companies that cannot ship copyleft.
- It is a library, a small tool, or a standard implementation.
- Apache-2.0 if contributors hold patents and you want an express grant.
- You accept that others can fork and close your code.
Pick copyleft (MPL / GPL / AGPL) when…
- You want improvements to flow back (MPL-2.0 file-level, GPL whole-work).
- You are worried about a cloud vendor reselling your work (AGPL-3.0).
- You accept slower enterprise adoption and longer legal review.
A working decision procedure
- Do you want to allow closed-source derivatives? No → copyleft. Yes → permissive.
- Do you care about patents? Yes → Apache-2.0 (permissive) or GPLv3 / MPL (copyleft).
- Do you need to allow linking from proprietary code? Yes → LGPL or MPL-2.0.
- Will it be run as a hosted service, and do you want reciprocation? → AGPL-3.0 (or a source-available licence if you specifically want to block competitors).
- Documentation and data? CC-BY-4.0 or CC0-1.0 — never a software licence.
- Match the ecosystem norm (Go/Rust: MIT+Apache; Java/Jakarta: Apache-2.0/EPL; kernel-adjacent: GPLv2).
6. Applying a licence
- LICENSE file at the repository root, full unmodified text, named
LICENSEorCOPYING. - Copyright notice with year and holder.
- Per-file headers for copyleft, and for Apache-2.0 to make provenance unambiguous. The
REUSE spec standardises this;
reuse lintchecks it in CI. - NOTICE file if you are Apache-2.0, or if you redistribute Apache-licensed code.
- Declare it in package metadata as an SPDX expression, so registries and SBOM tooling pick it up.
- Set inbound = outbound: a CLA or DCO so you can enforce or relicense later.
- Record third-party licences of anything you vendor or bundle. Generate an SBOM.
# REUSE: bulk-license files without headers via .reuse/dep5
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: my-project
Upstream-Contact: Ada Lovelace <ada@example.org>
Source: https://example.org/my-project
Files: assets/*
Copyright: 2026 Ada Lovelace
License: CC-BY-4.07. Source-available and non-OSI licences
| Licence | Mechanism | Used by |
|---|---|---|
| SSPL 1.0 | AGPL plus: offering the software as a service means opening your whole service stack | MongoDB (from Oct 2018), Elastic |
| BUSL 1.1 | Free for most uses; restricted "Competing Use"; converts to an open licence on a stated Change Date | HashiCorp (Aug 2023) |
| Elastic License 2.0 | No managed service, no circumventing the licence key | Elastic (Jan 2021) |
| FSL 1.1 | Two-year delay before the full open grant | Sentry, MariaDB (MaxScale) |
| Commons Clause | An addendum prohibiting sale of the software | Various; widely criticised |
| Fair Core / "fair-code" | Source visible, internal business use free, competing/hosted resale restricted | n8n and similar |
If your procurement policy or an SBOM consumer requires "open source", these do not qualify. They also break compatibility: SSPL is a modified AGPL and is incompatible with GPL.
8. Enforcement
- gpl-violations.org — Harald Welte's long-running European enforcement project.
- Software Freedom Conservancy — BusyBox-era GPL suits, and its 2021 suit against Vizio testing whether a downstream recipient can demand source.
- FSF — brought the first GPL enforcement actions in the 1990s–2000s.
- Practical outcome: almost every case ends in compliance — publish the complete corresponding source, fix the shipping process, avoid recurrence — rather than damages.
"Complete corresponding source" means everything needed to build and install the modified version, including build scripts. Offering a download link for three years (GPLv2 §3(b)) is a recognised alternative to shipping source with the product.
9. Common mistakes
- No licence at all. Public repositories are not public domain.
- "MIT, but no commercial use." That is not MIT.
- Mixing GPLv2-only and Apache-2.0 in one distributed work.
- Using CC licences for code. They do not address patents or source distribution.
- Forgetting dependencies. Bundled third-party code keeps its own licence.
- Relicensing later without consent — you need every contributor's permission without a CLA/DCO.
- Stripping licence headers from vendored files — it destroys the audit trail an SBOM depends on.
See also: History · Governance · Business models · SPDX