Pick a license before you publish. Code with no license is "all rights reserved" by default — people can look, but legally can't use, modify, or share it.
License families¶
| Family | Requirement | Examples | Good for |
|---|---|---|---|
| Permissive | Keep the copyright notice and license text. That's about it. | MIT, BSD-2/3-Clause, Apache 2.0, ISC | Libraries you want adopted as widely as possible, including in proprietary software |
| Weak copyleft | Changes to this code must be shared; code that merely links to it can be proprietary | LGPL, MPL 2.0, EPL 2.0 | Libraries where you want fixes returned but don't want to scare off adopters |
| Strong copyleft | Distributing a derivative work requires releasing it under the same license, with source | GPL v2, GPL v3 | Applications and systems you want to stay free forever |
| Network copyleft | Like the GPL, but also triggered by offering the software over a network | AGPL v3 | Server software; closes the "SaaS loophole" |
| Public domain-ish | No conditions | CC0, Unlicense, 0BSD | Snippets, examples, data |
| Source-available (not open source) | Restricts use, usually commercial or competing services | BSL, SSPL, Elastic License, Commons Clause | Not open source — don't call it that |
Notes that bite people¶
- Apache 2.0 vs MIT: Apache 2.0 includes an explicit patent grant and patent-retaliation clause. MIT doesn't mention patents. For anything a company might use, Apache 2.0 is the safer permissive choice. The Rust ecosystem convention is to dual-license
MIT OR Apache-2.0, getting the simplicity of MIT plus the patent protection of Apache, and GPLv2 compatibility via MIT. - GPLv2 and Apache 2.0 are incompatible. GPLv3 and Apache 2.0 are compatible (one way).
- "GPLv2-only" vs "GPLv2-or-later" matters. The kernel is GPLv2-only, which is why it never moved to v3.
- Creative Commons licenses (except CC0) are not for code. Use them for documentation or artwork.
- Use SPDX identifiers so tools can read your license automatically:
// SPDX-License-Identifier: MIT OR Apache-2.0
# Cargo.toml
[package]
license = "MIT OR Apache-2.0"
- Check your dependencies' licenses. A GPL dependency can change the obligations of your whole binary. In Rust,
cargo deny check licensesenforces an allowlist in CI.
Contributor agreements: DCO vs CLA¶
When outsiders contribute, they own the copyright on their changes. Projects handle this two ways:
- Developer Certificate of Origin (DCO) — introduced by the Linux kernel in 2004. Contributors add a
Signed-off-by:line to each commit (git commit -s), certifying they have the right to submit it under the project's license. Lightweight and community-friendly. - Contributor License Agreement (CLA) — a legal document contributors sign granting the project (often a company) broad rights, sometimes including the right to relicense. Required by many corporate projects. Be aware: a CLA that allows relicensing is exactly what made several of the license changes covered in History of Open Source possible. Many contributors treat a CLA as a red flag for that reason.
For a personal project, use the DCO or nothing.