Open Source Licensing Traps in Enterprise Software: Mapping the Hidden Risks
54 questions
54 questions on open source licensing traps in enterprise software, answered and cited by the UpLaw editorial team.
- Can a single individual contributor enforce the GPL?
- Does merely using open source make proprietary code open source?
- Does static linking create a derivative work?
- How does open source exposure typically enter an enterprise codebase?
- How do strong, weak, and network copyleft differ?
- How have competitors weaponized open source noncompliance?
- How should an enterprise handle AI-generated code pending real answers?
- How should an enterprise policy treat the AGPL?
- How should an SCA tool be evaluated?
- How should code exposure during diligence be managed?
- Is a cloud-only business safe from copyleft?
- Is the dynamic-linking question settled?
- Is the GPL a bare license or a contract?
- What are a company's options when a copyleft violation surfaces?
- What are the common open source compliance failure modes?
- What are the seven phases of an open source audit?
- What are the SSPL and the BSL?
- What are the technical ways programs are combined, and why does the method matter?
- What are the three software composition analysis scanning techniques?
- What did the Neo4j litigation decide about adding restrictions to a copyleft license?
- What did the Orange decision establish in France?
- What do permissive licenses require?
- What early U.S. enforcement actions established that copyleft has teeth?
- What exactly is the covenant-condition distinction?
- What is an SBOM, and why did it become an industry expectation?
- What is a tiered open source license policy?
- What is copyleft, and how does it invert copyright?
- What is mere aggregation, and why is it safe?
- What is the AI-generated-code provenance problem?
- What is the "ASP loophole," and how does the AGPL close it?
- What is the central economic argument for continuous compliance tooling?
- What is the difference between "free software" and "open source"?
- What is the FSF's rule of thumb for combined works?
- What is the relicensing wave, and why does it matter?
- What is the remediation menu for a license incompatibility?
- What is the third-party-beneficiary theory in SFC v. Vizio?
- What is the throughline of open source compliance?
- What open source representations appear in modern deal documents?
- What should a company do when a dependency changes its license?
- What surprising obligations does the Apache License 2.0 carry?
- What three lessons does the relicensing wave teach an enterprise?
- What trade-secret risk does an open source audit itself create?
- What triggers the GPL's source-code obligation?
- What two foundational U.S. decisions drew boundaries around open source?
- What two lessons does Neo4j carry for an enterprise?
- What were the defining relicensing episodes?
- Where does the Vizio litigation stand, and what are the stakes?
- Why can two valid open source licenses be legally incompatible?
- Why do attribution failures matter even for MIT and BSD code?
- Why do financings and acquisitions expose open source risk so starkly?
- Why do transitive dependencies make incompatibility dangerous?
- Why is open source noncompliance no longer a hypothetical risk?
- Why is violating an open source license copyright infringement rather than mere contract breach?
- Why must counsel establish the facts of integration before choosing a remedy?