“Every open sourcelicense is a contract.Most teams treat it like a README.”

GPL dependencies don't announce themselves in pull requests. AGPL obligations don't appear in your sprint planning. By the time legal notices arrive, the clock is already running.

Counsel
Attribution Required●Copyleft Scope●Patent Grants●Distribution Triggers●SaaS Loophole●Derivative Works●License Compatibility●Contributor Agreements●SPDX Identifiers●Dual Licensing●Attribution Required●Copyleft Scope●Patent Grants●Distribution Triggers●SaaS Loophole●Derivative Works●License Compatibility●Contributor Agreements●SPDX Identifiers●Dual Licensing●

Four licenses. Thirty-seven distinct obligations.

Every cell below is written for engineers who need to make a decision today — not for attorneys who will argue about it in discovery.

High obligation
Moderate
Minimal
None
DimensionGPL v3MITApache 2.0AGPL v3⚠ High Risk
Attribution
Must you credit the original authors in your product or docs?

Yes — copyright notices must survive in all copies and modified files.

Yes — include the license text. That's it. No source required.

Yes — NOTICE file must be preserved and reproduced downstream.

Yes — same as GPL, plus network users must be able to see notices.

Copyleft Scope
Does using this code require you to open-source your own work?

Strong copyleft. Any distributed software linking to GPL code must ship as GPL.

↳ Linking = distributing in most courts.

None. MIT code can live inside proprietary software without triggering disclosure.

None for source. Modified Apache files must carry change notices, but your code stays private.

Strongest available. Network use counts as distribution — SaaS products are not exempt.

↳ The clause most acquirers' counsel will flag first.

Patent Grants
Does the license give you permission to use any patents held by contributors?

Implicit grant only. No explicit patent license — courts have interpreted this inconsistently.

None granted. MIT is copyright-only. Patent exposure is entirely unaddressed.

↳ Silent on patents — a known risk for hardware-adjacent code.

Explicit perpetual patent license from each contributor. Terminates if you sue for patent infringement.

Same implicit structure as GPL v3. No explicit grant beyond copyright.

Distribution Trigger
What action starts the clock on your compliance obligations?

Distributing compiled binaries or source to anyone outside your organization.

Distribution of any copy — but obligations are minimal. Include the license file.

Distribution of any copy or modified version triggers NOTICE and attribution requirements.

Distribution OR making the software available over a network. Offering a SaaS API counts.

↳ This is the clause that ends acquisition conversations.

SaaS Loophole
Can you run the software as a service without triggering copyleft?

Yes. GPL was written before SaaS existed. Running a service is not "distribution."

Yes, completely. No restriction on how you deploy or operate the software.

Yes. Apache 2.0 does not restrict use — only distribution of copies.

No. AGPL was written specifically to close this loophole. Network use = distribution.

Commercial Use
Can you build a commercial product on top of this license?

Yes — but your product becomes GPL. You can charge for it, but the source must be available.

Yes, without restriction. MIT imposes no limits on commercial exploitation.

Yes, without restriction. Apache is explicitly permissive for commercial use.

Yes — but your entire SaaS stack may become AGPL. Proceed only with a compliance plan in hand.

This table reflects general interpretations as of February 2026 and does not constitute legal advice. License obligations depend on how your software links, distributes, and deploys dependencies. Schedule a License Audit for analysis specific to your repository.

Three engagements. Anonymized. Annotated.

Each began with a version of the same sentence: “We didn't think this would be a problem.”

01
Cease & DesistSeries A · $2M funding round at risk

The Letter

A San Francisco-based devtools startup received a cease-and-desist from the original maintainer of a logging library they had incorporated eighteen months earlier. The library was licensed under GPL v3. Their product was distributed to enterprise clients as a compiled binary. They had shipped 6,000 installations.

The Legal Exposure

Under GPL v3 §6, any software that incorporates GPL-licensed code and is distributed in binary form must either ship corresponding source code or provide a written offer to do so. The startup had done neither. Their enterprise license agreements contained no disclosure of GPL dependencies.

  • GPL v3 §6 violation across all distributed builds
  • Enterprise client contracts lacked required GPL pass-through clauses
  • No SPDX identifiers in their dependency manifest
  • Six months of undisclosed modifications to the GPL library

The Path Forward

We negotiated a dual-licensing agreement with the maintainer, retroactively covering existing installations for a one-time fee. The startup rebuilt their dependency manifest with full SPDX compliance, replaced the GPL library with an Apache 2.0 alternative in new builds, and added GPL disclosure to all enterprise agreements.

Series A closed on schedule. Due diligence cleared.

02
Acquisition Due DiligenceSeries B · $14M deal structure affected

The Discovery

A growth-stage infrastructure company was twelve days from closing a $14M acquisition when the acquiring firm's legal team flagged three AGPL v3 dependencies embedded in the target's core API layer. The acquiring company was a publicly traded SaaS vendor. AGPL exposure in their production stack was a non-starter.

The Legal Exposure

AGPL v3 §13 extends copyleft obligations to network use — meaning any user accessing the software over a network has the right to receive the corresponding source. For a SaaS company, this effectively means the entire application stack must be open-sourced or the AGPL components must be removed.

  • Three AGPL dependencies in core API routing layer
  • One dependency modified internally — triggering immediate disclosure obligations
  • No CLA covering the internal modifications
  • Acquirer's legal team estimated 90-day remediation minimum

The Path Forward

We produced a 72-hour remediation analysis identifying which AGPL components could be swapped for compatible alternatives and which required negotiated commercial licenses. Two of three libraries had commercial license options available. The third required a clean-room reimplementation of 340 lines of code.

Deal restructured with 45-day escrow holdback. Closed at original valuation.

03
M&A FalloutLate Stage · $85M acquisition collapsed

The Collapse

A late-stage enterprise data platform had been in acquisition negotiations for eight months with a strategic acquirer. The deal was structured at $85M. During final due diligence, the acquirer's IP counsel discovered that the target's core differentiating algorithm had been derived from a GPL v2-licensed research implementation published in 2017. The original code had been substantially modified but remained legally traceable.

The Legal Exposure

GPL v2 contains no "or later" clause — unlike GPL v3, it cannot be upgraded to a more permissive version without the original copyright holders' consent. The research implementation had 23 named contributors. Twelve were at academic institutions with technology transfer offices. The algorithm was the target's primary patent application basis.

  • GPL v2-only dependency embedded in core proprietary algorithm
  • Patent application based on derivative GPL v2 work — potentially unenforceable
  • 23 contributors across 11 institutions required for license upgrade
  • Acquirer's counsel flagged potential ownership dispute on 4 of 7 patent claims
  • No contributor license agreement existed for any modifications

The Outcome

The $85M deal did not close. We worked with the target to pursue a contributor outreach program, securing license upgrades from 19 of 23 contributors over fourteen months. The four remaining contributors — all at a single institution — declined. The company ultimately rebuilt the affected algorithm independently, filed amended patent claims, and closed a separate transaction eighteen months later.

$85M deal collapsed. Rebuilt and closed at $61M — 18 months later.

The checklist we run before every audit.

Forty-seven line items. Covers GPL, MIT, Apache, AGPL, LGPL, MPL, and EUPL. Used internally on every engagement since 2019.

  • ✓Dependency SPDX audit checklist (47 items)
  • ✓GPL v2 vs v3 compatibility matrix
  • ✓AGPL SaaS exposure assessment framework
  • ✓Contributor License Agreement template
  • ✓M&A due diligence license disclosure template
  • ✓Cease-and-desist response protocol
Download the Compliance Checklist

PDF · 14 pages · No follow-up sequence. One email, one document.

No sales calls. No newsletter. Just the PDF.

Book a License Audit.

A structured review of your dependency tree, distribution practices, and contributor agreements. Delivered as a written opinion within ten business days.

  • 01Full SPDX dependency manifest review
  • 02Distribution and network-use trigger analysis
  • 03CLA coverage gap assessment
  • 04M&A readiness report (if applicable)
  • 05Remediation priority matrix
  • 06Written legal opinion — signed by counsel

Optional but accelerates the initial review.

Initial consultation is complimentary. Engagements are billed at a flat project rate, disclosed before any work begins.