Safeguard
Tag

license-compliance

Safeguard articles tagged "license-compliance" — guides, analysis, and best practices for software supply chain and application security.

91 articles

Security

GPL Meaning Explained: What the GNU General Public License Requires

GPL means GNU General Public License, a copyleft license that grants broad freedoms but requires you to share source under the same terms. Here is what that means for your code.

May 7, 20256 min read
Licensing

What Is License Contamination?

One GPL dependency in the wrong place can put your proprietary source code under copyleft obligations. How license contamination happens and how to prevent it.

May 7, 20256 min read
Compliance

BSD 3-Clause License Explained

The BSD 3-clause license is one of the most permissive open source licenses in wide use — here's what its three conditions actually require and how it differs from MIT and Apache 2.0.

May 6, 20256 min read
Compliance

OSS Licenses Explained: Compliance and Risk Management

OSS licenses govern how you can use open-source dependencies, and ignoring them creates real legal and business risk. Here is how the main license types work and how to stay compliant.

Apr 30, 20256 min read
Compliance

The MIT Software License: What It Permits and What to Watch For

The MIT software license is short, permissive, and lets you do almost anything as long as you keep the copyright notice. Here is what it actually requires and where teams still get tripped up.

Apr 22, 20255 min read
Security

Copyleft Meaning Explained: How Reciprocal Licenses Work

The meaning of copyleft, in plain terms: how reciprocal licenses keep software free, how strong and weak copyleft differ, and why it changes how you use open source dependencies.

Apr 15, 20256 min read
Licensing

MIT License and Commercial Use: What You Can and Cannot Do

The MIT License lets you use, modify, and sell software commercially with almost no restrictions — as long as you keep the copyright notice. Here is exactly what that permits and requires.

Apr 15, 20256 min read
Compliance

Node.js Licensing Explained: The MIT Core and Its Bundled Dependencies

Node.js licensing looks simple until you count the bundled components. Here is what the MIT-licensed runtime actually obligates you to, and where the real compliance work hides.

Apr 9, 20255 min read
Compliance

How Does Software Licensing Work? A Practical Guide for Developers

Software licensing works by granting usage rights under specific terms. Here is how open-source and commercial licenses differ, and how to stay compliant in your dependency tree.

Apr 7, 20256 min read
Security

Apache v2: What the Apache License 2.0 Actually Requires

A plain-English guide to Apache v2 — what the Apache License 2.0 permits, the obligations it puts on you, its patent grant, and how it affects your open-source compliance.

Mar 18, 20256 min read
AppSec

What a WhiteSource Scan Actually Checks (and How Mend Changed It)

A WhiteSource scan is a software composition analysis run that inventories your open source dependencies and flags known vulnerabilities and license risks. Here is what it looks at and how the Mend rebrand affects your pipeline.

Mar 12, 20256 min read
Compliance

What Are the Different Types of Licenses in Software? A Security View

The different types of licenses in software fall into a few families - permissive, copyleft, weak copyleft, and proprietary - and each carries distinct legal and supply chain obligations.

Feb 20, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

license-compliance (Page 6) — Safeguard Blog