MI Solutions
Insights/Audits and compliance
Audits and compliance

Open-Source License Compliance for Non-Developers

A plain-language guide to open-source licenses: permissive vs copyleft, what obligations they create, and how to manage open-source compliance.

By the MI Solutions SAM team9 min read2 exhibits

Open-source software is free to use, but it is not free of conditions. Every open-source component comes with a license, and those licenses range from "do almost anything, just keep the copyright notice" to "if you distribute software that includes this, you must share your source code too". For most organizations that use open source internally, obligations are light. For organizations that distribute software to customers, they matter a great deal.

The license spectrum

Exhibit 1
Open-source licenses range from permissive to network copyleftTypical obligations increase from left to right1PERMISSIVEMIT, BSD, Apache 2.0Keep notices; few otherconditions2WEAK COPYLEFTLGPL, MPLShare changes to thecomponent itself3STRONG COPYLEFTGPLShare source of combinedworks you distribute4NETWORK COPYLEFTAGPLObligations can apply tosoftware used over anetwork

When obligations apply

How you use a component matters as much as which license it carries:

Exhibit 2
Obligations depend on the license and on how you use the softwareTypical level of obligation, illustrative and simplifiedInternal useDistributed productOffered as a servicePermissive (MIT, BSD,Apache)MinimalNoticesMinimalWeak copyleft (LGPL, MPL)MinimalShare changesMinimalStrong copyleft (GPL)MinimalShare sourceLowNetwork copyleft (AGPL)LowShare sourceShare sourceSimplified for illustration; exact obligations depend on the license version and how the software is combined.Not legal advice.
01Internal use only

Most licenses impose few obligations.

02Distributing software

To customers, in products or devices, copyleft obligations may require sharing source code.

03Offering software as a service

Network copyleft licenses such as the AGPL can create obligations even without distribution.

A simple open-source policy

Where SAM fits

Open-source compliance usually sits with engineering and legal, but SAM teams help by including open-source components in the software inventory and by tracking commercial support subscriptions for open-source products. Some products also come in an open-source edition and a commercial edition; knowing which one is installed is a SAM question.

How MI One helps

Frequently asked questions

Is open-source software free for business use?

Usually yes, under its license terms. Check the license, especially before distributing software that includes it.

Who should own open-source compliance?

Typically engineering with legal support, using a written policy.

Do we need to track open source used only internally?

Track it lightly: it matters for security updates and for the day an internal tool becomes a customer-facing one.


Sources

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.