Skip to main content

The Art of CTO License Compliance Checker checks up to 20 manually entered dependencies for licence compatibility, GPL and AGPL conflicts, and commercial risk against your own project licence and distribution model.

Can we ship with these open-source licences?

GPL conflicts, commercial compatibility, and the licences to swap.

About 10 min · Calculator · Free

About this toolWhy it matters, common mistakes, FAQ

Can You Legally Ship What You Have Already Built?

Copyleft obligations attach at distribution, so the problem surfaces at the worst possible moment — a release, an acquisition, or a customer's legal review. Unwinding a GPL dependency woven through a core module is a rewrite, not a patch.

License checks run on direct dependencies. The risk lives transitively, several levels down, where nobody chose the package and nobody read its terms.

Questions CTOs ask

What open source licenses are safe for commercial use?
Permissive licenses like MIT, BSD (2-clause and 3-clause), Apache 2.0, and ISC are generally safe for commercial use with minimal obligations — typically just attribution. Copyleft licenses like GPL require distributing your source code if you distribute the software, which can be problematic for proprietary products. LGPL allows dynamic linking without copyleft obligations. AGPL extends copyleft to network use, meaning even SaaS deployments trigger source code disclosure requirements.
What is GPL contamination and how do you prevent it?
GPL contamination occurs when GPL-licensed code is combined with proprietary code in a way that triggers the GPL's copyleft requirement, potentially forcing you to open-source your entire codebase. Prevent it by maintaining a license inventory of all dependencies, using automated scanning tools in your CI/CD pipeline, establishing clear policies about acceptable licenses, and keeping GPL components isolated behind well-defined API boundaries when usage is necessary.

Related Reading