Skip to content
CodeDD Logo

Licences

Can this product be shipped — and sold — as it is?

Every open-source licence comes with obligations. CodeDD resolves the licence of every package across the estate — every repository in scope — and flags what could touch the IP.

Start for FreeBook a Demo

Trusted by

Beyond a licence list

A licence list does not tell you what is owed.

Every dependency carries terms. What matters is which of those terms reach the shipped product — and which ones were never identified at all.

  1. One answer per licence, not forty spellings

    Registries return messy licence text. Each package resolves to one standard SPDX identifier, so the estate reads as a posture, not a spreadsheet.

  2. Know which terms threaten the IP

    Permissive, weak copyleft, strong copyleft, or not identified. Copyleft is what can force source disclosure once the product is distributed.

  3. Know which repositories carry it

    Exposure is only real where the code ships. Every licence traces to the repositories and packages that carry it.

The posture

The posture, not the catalogue.

How the estate splits across permissive, copyleft, and not identified — the level counsel needs before going line by line.

The follow-up

Every claim traces to a package.

Apache-2.0 on billing-api is not the conversation. An unidentified licence on legacy-etl is. Open the row and see the exact package and repository.

Across the investment cycle

Where licences change the deal

  1. Pre-deal tech DD

    Know whether copyleft reaches the product before the IP representations are drafted — and which unknowns still need counsel.

  2. Hold period

    Catch a new copyleft or unidentified dependency when it arrives, not in the next diligence.

  3. Pre-sale preparation

    Clear the unknowns and replace risky packages before a buyer's counsel asks — and export the licence list as a CSV.

FAQ

Questions

How do you classify licences?

Registry and manifest strings are resolved to SPDX, then placed in one of four buckets: permissive, weak copyleft, strong copyleft, or unidentified. Dual expressions such as MIT OR Apache-2.0 collapse to one row. AND expressions take the most restrictive part, so the posture is never flattered.

Which bucket should worry me?

Copyleft and unidentified. Weak copyleft (LGPL, MPL) can require source disclosure for modified components. Strong copyleft (GPL and similar) can impose reciprocal obligations on the product itself. Permissive licences rarely change the picture. The dashboard groups weak and strong copyleft as Restrictive, and lists both separately.

What does UNKNOWN mean?

The terms could not be resolved to an SPDX id — empty metadata, a full-text dump, or a non-standard string. It is a review flag, not a copyleft hit. A clean Restrictive card is not a clean posture while unidentified rows remain.

Direct or transitive — which matters?

Start with direct: the packages imported in scanned source or declared in the shipped manifest. That is the exposure reviewers ask about first. Open transitive or all when the rest of the tree matters.

Is this a legal opinion?

No. It shows where the risk sits and what still needs a human, which keeps counsel time short and focused. It does not replace IP counsel or a compatibility analysis of how the product is distributed.

How is this different from SBOM & dependencies?

That view answers whether a package is vulnerable. This one answers whether it can be shipped. Same inventory, different risk. A package can be CVE-clean and still be the IP problem.

See the licence exposure in an estate you care about

We will walk Licences on a repository set you choose — direct vs transitive, SPDX rows, and the unknown packages that still need a human.