FOSS Wiki StationFOSS Wiki Station
Licensing

Licenses

Anatomy of a licence, families, compatibility, SPDX identifiers, how to choose and apply, and what enforcement looks like.

FOSS Licenses

A licence is the only thing that makes code reusable. Without one, copyright defaults to "all rights reserved" and nobody may copy, modify or distribute your work.

Nothing here is legal advice. Licence interactions — especially around patents, SaaS and distribution — are fact-specific. For anything contractual, use a lawyer who has read your actual dependency tree.


1. Anatomy of a licence

PartWhat it doesWhy you care
GrantPermits use, copying, modification, distributionThe whole point. Missing → unusable code
ConditionsAttribution, notice preservation, source disclosureYour compliance workload
Copyleft scopeHow far "share alike" reaches: file, library, whole work, networkWhether you must release your own source
Patent grantExpress (Apache-2.0 §3, GPLv3 §11) or absent (MIT, BSD)Litigation risk from contributors
TrademarkNearly always excluded; Apache-2.0 §6 says so explicitlyYou may not use the project's name or logo
Warranty disclaimer"AS IS", no liabilityWhy vendors sell indemnity
TerminationGPL: automatic on violation. GPLv3: cure periods (30/60 days)Non-compliance can cost you the licence entirely
Version clause-only vs -or-laterDetermines future compatibility

Copyleft triggers on distribution, not use. GPL obligations fire when you convey the software. Running modified GPL software internally is fine. AGPL additionally treats network interaction as distribution — that is the entire point of AGPL.

2. The families

LicenceSPDX IDTypePatent grantNotes
MITMITPermissiveNo express grant~170 words; maximum adoption
ISCISCPermissiveNoMIT without the warranty paragraph
BSD 2-ClauseBSD-2-ClausePermissiveNoNotice only
BSD 3-ClauseBSD-3-ClausePermissiveNoAdds no-endorsement. The old 4-clause advertising term is GPL-incompatible
Apache 2.0Apache-2.0PermissiveYes — express + defensive terminationNOTICE propagation; the corporate default
MPL 2.0MPL-2.0File copyleftYesShare changes to covered files; GPL-compatible by design (§3.3)
EPL 2.0EPL-2.0Weak copyleftYesEclipse/Jakarta; patent retaliation
LGPL 2.1 / 3.0LGPL-2.1-or-later, LGPL-3.0-or-laterLibrary copyleftv3: yesProprietary programs may link
GPL 2.0GPL-2.0-only / GPL-2.0-or-laterStrong copyleftImpliedThe kernel's licence; incompatible with Apache-2.0 per the FSF
GPL 3.0GPL-3.0-only / GPL-3.0-or-laterStrong copyleftYes — expressAnti-tivoisation, install-info, cure periods
AGPL 3.0AGPL-3.0-only / AGPL-3.0-or-laterNetwork copyleftYesNetwork users get a source offer (§13)
CC0 1.0CC0-1.0Public domainNo expressFor data and docs, not recommended for code

The canonical registry is the SPDX License List (3.29.0, 2026-09-16) with 700+ identifiers. The OSI's approved list is a much smaller curated subset (~100 licences).

3. Compatibility

CombiningResultReason
MIT / BSD-2 / BSD-3 / ISC → GPLv2 or v3OKNo additional restrictions
Apache-2.0 → GPLv3OKGPLv3 §7 accepts Apache's additional terms
Apache-2.0 → GPLv2-onlyNoApache's patent-termination clause is an added restriction
MPL-2.0 → GPL / AGPLOKMPL 2.0 §3.3 has an explicit compatibility clause
GPLv2-only → GPLv3NoDifferent terms; -or-later solves it
LGPL → GPLOKLGPL permits "upgrading" the copyleft
GPLv3 → AGPLv3OKAGPLv3 §13 permits combination
CC-BY-4.0 / CC-BY-SA-4.0 → GPLv3One-way4.0 added GPLv3 compatibility; CC 1.0–3.0 did not
Permissive → proprietary productOKKeep the notice
Copyleft → proprietary productNoUnless you also disclose your source

Linking is the hard question. Whether dynamically linking your code to a GPL library creates a derivative work is unsettled; the FSF says yes, and the LGPL exists to remove the doubt. Do not build a product strategy on the assumption that a shared-library boundary protects you.

4. SPDX identifiers and expressions

// Source file header (REUSE-compatible)
// SPDX-FileCopyrightText: 2026 Ada Lovelace <ada@example.org>
// SPDX-License-Identifier: Apache-2.0

# package.json / Cargo.toml / pyproject.toml
"license": "(MIT OR Apache-2.0)"

# Dual licensing: recipient chooses
"Apache-2.0 OR MIT"

# Copyleft with an exception
"GPL-3.0-or-later WITH Classpath-exception-2.0"

# Internal use: not a licence, but machine-readable
"LicenseRef-Proprietary"

Operators: AND (both apply to different parts), OR (recipient chooses), WITH (exception). Deprecated IDs like bare GPL-2.0 are ambiguous — always use -only or -or-later.

5. Choosing a licence

Pick permissive (MIT / Apache-2.0) when…

  • You want maximum adoption, including by companies that cannot ship copyleft.
  • It is a library, a small tool, or a standard implementation.
  • Apache-2.0 if contributors hold patents and you want an express grant.
  • You accept that others can fork and close your code.

Pick copyleft (MPL / GPL / AGPL) when…

  • You want improvements to flow back (MPL-2.0 file-level, GPL whole-work).
  • You are worried about a cloud vendor reselling your work (AGPL-3.0).
  • You accept slower enterprise adoption and longer legal review.

A working decision procedure

  1. Do you want to allow closed-source derivatives? No → copyleft. Yes → permissive.
  2. Do you care about patents? Yes → Apache-2.0 (permissive) or GPLv3 / MPL (copyleft).
  3. Do you need to allow linking from proprietary code? Yes → LGPL or MPL-2.0.
  4. Will it be run as a hosted service, and do you want reciprocation? → AGPL-3.0 (or a source-available licence if you specifically want to block competitors).
  5. Documentation and data? CC-BY-4.0 or CC0-1.0 — never a software licence.
  6. Match the ecosystem norm (Go/Rust: MIT+Apache; Java/Jakarta: Apache-2.0/EPL; kernel-adjacent: GPLv2).

6. Applying a licence

  1. LICENSE file at the repository root, full unmodified text, named LICENSE or COPYING.
  2. Copyright notice with year and holder.
  3. Per-file headers for copyleft, and for Apache-2.0 to make provenance unambiguous. The REUSE spec standardises this; reuse lint checks it in CI.
  4. NOTICE file if you are Apache-2.0, or if you redistribute Apache-licensed code.
  5. Declare it in package metadata as an SPDX expression, so registries and SBOM tooling pick it up.
  6. Set inbound = outbound: a CLA or DCO so you can enforce or relicense later.
  7. Record third-party licences of anything you vendor or bundle. Generate an SBOM.
# REUSE: bulk-license files without headers via .reuse/dep5
Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/
Upstream-Name: my-project
Upstream-Contact: Ada Lovelace <ada@example.org>
Source: https://example.org/my-project

Files: assets/*
Copyright: 2026 Ada Lovelace
License: CC-BY-4.0

7. Source-available and non-OSI licences

LicenceMechanismUsed by
SSPL 1.0AGPL plus: offering the software as a service means opening your whole service stackMongoDB (from Oct 2018), Elastic
BUSL 1.1Free for most uses; restricted "Competing Use"; converts to an open licence on a stated Change DateHashiCorp (Aug 2023)
Elastic License 2.0No managed service, no circumventing the licence keyElastic (Jan 2021)
FSL 1.1Two-year delay before the full open grantSentry, MariaDB (MaxScale)
Commons ClauseAn addendum prohibiting sale of the softwareVarious; widely criticised
Fair Core / "fair-code"Source visible, internal business use free, competing/hosted resale restrictedn8n and similar

If your procurement policy or an SBOM consumer requires "open source", these do not qualify. They also break compatibility: SSPL is a modified AGPL and is incompatible with GPL.

8. Enforcement

  • gpl-violations.org — Harald Welte's long-running European enforcement project.
  • Software Freedom Conservancy — BusyBox-era GPL suits, and its 2021 suit against Vizio testing whether a downstream recipient can demand source.
  • FSF — brought the first GPL enforcement actions in the 1990s–2000s.
  • Practical outcome: almost every case ends in compliance — publish the complete corresponding source, fix the shipping process, avoid recurrence — rather than damages.

"Complete corresponding source" means everything needed to build and install the modified version, including build scripts. Offering a download link for three years (GPLv2 §3(b)) is a recognised alternative to shipping source with the product.

9. Common mistakes

  • No licence at all. Public repositories are not public domain.
  • "MIT, but no commercial use." That is not MIT.
  • Mixing GPLv2-only and Apache-2.0 in one distributed work.
  • Using CC licences for code. They do not address patents or source distribution.
  • Forgetting dependencies. Bundled third-party code keeps its own licence.
  • Relicensing later without consent — you need every contributor's permission without a CLA/DCO.
  • Stripping licence headers from vendored files — it destroys the audit trail an SBOM depends on.

See also: History · Governance · Business models · SPDX

On this page