Andrew Mercer
on this page

Pick a license before you publish. Code with no license is "all rights reserved" by default — people can look, but legally can't use, modify, or share it.

License families

Family Requirement Examples Good for
Permissive Keep the copyright notice and license text. That's about it. MIT, BSD-2/3-Clause, Apache 2.0, ISC Libraries you want adopted as widely as possible, including in proprietary software
Weak copyleft Changes to this code must be shared; code that merely links to it can be proprietary LGPL, MPL 2.0, EPL 2.0 Libraries where you want fixes returned but don't want to scare off adopters
Strong copyleft Distributing a derivative work requires releasing it under the same license, with source GPL v2, GPL v3 Applications and systems you want to stay free forever
Network copyleft Like the GPL, but also triggered by offering the software over a network AGPL v3 Server software; closes the "SaaS loophole"
Public domain-ish No conditions CC0, Unlicense, 0BSD Snippets, examples, data
Source-available (not open source) Restricts use, usually commercial or competing services BSL, SSPL, Elastic License, Commons Clause Not open source — don't call it that

Notes that bite people

  • Apache 2.0 vs MIT: Apache 2.0 includes an explicit patent grant and patent-retaliation clause. MIT doesn't mention patents. For anything a company might use, Apache 2.0 is the safer permissive choice. The Rust ecosystem convention is to dual-license MIT OR Apache-2.0, getting the simplicity of MIT plus the patent protection of Apache, and GPLv2 compatibility via MIT.
  • GPLv2 and Apache 2.0 are incompatible. GPLv3 and Apache 2.0 are compatible (one way).
  • "GPLv2-only" vs "GPLv2-or-later" matters. The kernel is GPLv2-only, which is why it never moved to v3.
  • Creative Commons licenses (except CC0) are not for code. Use them for documentation or artwork.
  • Use SPDX identifiers so tools can read your license automatically:
// SPDX-License-Identifier: MIT OR Apache-2.0
# Cargo.toml
[package]
license = "MIT OR Apache-2.0"
  • Check your dependencies' licenses. A GPL dependency can change the obligations of your whole binary. In Rust, cargo deny check licenses enforces an allowlist in CI.

Contributor agreements: DCO vs CLA

When outsiders contribute, they own the copyright on their changes. Projects handle this two ways:

  • Developer Certificate of Origin (DCO) — introduced by the Linux kernel in 2004. Contributors add a Signed-off-by: line to each commit (git commit -s), certifying they have the right to submit it under the project's license. Lightweight and community-friendly.
  • Contributor License Agreement (CLA) — a legal document contributors sign granting the project (often a company) broad rights, sometimes including the right to relicense. Required by many corporate projects. Be aware: a CLA that allows relicensing is exactly what made several of the license changes covered in History of Open Source possible. Many contributors treat a CLA as a red flag for that reason.

For a personal project, use the DCO or nothing.