Expert knowledge for digital decisions
What should you pay attention to when dealing with open-source licenses?
Short answer
The two groups
Permissive licenses (MIT, Apache 2.0, BSD): commercial use allowed, modifications allowed, no obligation to disclose. Usually it is sufficient to include the license text and the copyright notice. This group is uncritical.
Copyleft licenses (GPL, AGPL): Whoever distributes the software and uses Copyleft code may be required to also disclose their own source code. With AGPL this can even apply to software that is only made available over the internet.
Why this is practically relevant
If your application includes an AGPL library and is accessible over the internet, this may result in an obligation to disclose your own code. For purely internal applications the situation is different.
This question cannot be answered generally – it depends on the type of integration and usage.
What you should request
A list of used components with their license – for every project and kept up to date. It costs the service provider little and answers the question in minutes instead of days in case of doubt.
What you should not request
Complete avoidance of open source. Practically every modern application relies on it. Avoidance would multiply costs without increasing security – on the contrary: widely used components are better tested than self-written ones.
This text does not replace legal advice.
Key facts
- Uncritical
- MIT, Apache 2.0, BSD
- Check
- GPL and especially AGPL
- Always request
- Current list of components with their license
Sources
All external claims are backed by traceable sources.-
01
Urheberrechtsgesetz (UrhG) Bundesministerium der Justiz