This project is built and maintained by an automated agent system.
Not legal advice; verify with qualified counsel.
Policy pack version 1.0.0 (dated 2026-10-09). The rule sets reflect the maintainer's interpretation and may become outdated.
Each policy is one JSON file for the CLI. The table below is taken from those files and from the pack's matrix of 62 licences. Strong copyleft means GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only and GPL-3.0-or-later. Network copyleft means AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0 and OSL-3.0. Proprietary means BUSL-1.1, Elastic-2.0, Commons-Clause, PolyForm-Noncommercial-1.0.0 and PolyForm-Small-Business-1.0.0.
| Policy | Intended project type | Strong copyleft | Network copyleft | Proprietary licences |
|---|---|---|---|---|
| saas-proprietary Proprietary SaaS (no distribution) | A closed-source service that runs on your own servers and is never handed to customers as a download, installer or container image. | All four: review | All four: deny | Commons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review |
| proprietary-binary Proprietary distributed binary (desktop or mobile app) | A closed-source app shipped to users as an installer, app-store package or executable, including the bundled third-party code. | All four: deny | All four: deny | Commons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review |
| proprietary-onprem Proprietary on-premise delivered to customers | A closed-source product installed on the customer's own servers: packages, installers, virtual appliances or container images you hand over. | All four: deny | All four: deny | BUSL-1.1, Elastic-2.0, Commons-Clause and PolyForm-Noncommercial: deny; PolyForm-Small-Business: review |
| oss-permissive-library MIT or Apache-2.0 open-source library | A permissively licensed library or tool that downstream users embed in their own code, open or closed. | All four: deny | All four: deny | All five: deny |
| gpl3-project GPL-3.0 project | A project released under GPL-3.0-only or GPL-3.0-or-later that wants every dependency to be compatible with that licence. | GPL-2.0-only: deny; GPL-2.0-or-later, GPL-3.0-only and GPL-3.0-or-later: allow | AGPL-3.0-only and AGPL-3.0-or-later: review; SSPL-1.0 and OSL-3.0: deny | All five: deny |
| agpl-averse-baseline AGPL-averse company-wide baseline | One policy for every repository in a company that mixes services, apps and libraries, when the company wants network-copyleft and non-commercial licences kept out entirely. | All four: review | All four: deny | Commons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review |
| embedded-firmware Embedded or firmware distribution | Firmware, RTOS-based or Linux-based device images that ship to customers on hardware, where users may not be able to replace the software. | GPL-2.0-only and GPL-2.0-or-later: review; GPL-3.0-only and GPL-3.0-or-later: deny | All four: deny | Commons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review |
| internal-tooling Internal tooling only | Scripts, dashboards and build tools used only by your own staff and never delivered to customers or exposed to outside users. | All four: allow | All four: review | Elastic-2.0: allow; PolyForm-Noncommercial: deny; BUSL-1.1, Commons-Clause and PolyForm-Small-Business: review |
The full matrix in the pack lists every licence under all eight policies. These are 8 of its rows, unchanged.
| SPDX id | Category | saas-proprietary | proprietary-binary | proprietary-onprem | oss-permissive-library | gpl3-project | agpl-averse-baseline | embedded-firmware | internal-tooling |
|---|---|---|---|---|---|---|---|---|---|
| MIT | permissive | allow | allow | allow | allow | allow | allow | allow | allow |
| Apache-1.1 | permissive | allow | review | review | review | deny | review | review | allow |
| MPL-2.0 | weak-copyleft | allow | review | review | allow | allow | review | review | allow |
| LGPL-3.0-only | weak-copyleft | allow | review | review | review | allow | review | deny | allow |
| GPL-3.0-only | strong-copyleft | review | deny | deny | deny | allow | review | deny | allow |
| AGPL-3.0-only | network-copyleft | deny | deny | deny | deny | review | deny | deny | review |
| BUSL-1.1 | proprietary | review | review | deny | deny | deny | review | review | review |
| CC-BY-NC-4.0 | other | deny | deny | deny | deny | deny | deny | deny | deny |
The CLI source: coming soon.
The pack (version 1.0.0, dated 2026-10-09): coming soon. The rule sets reflect the maintainer's interpretation and may become outdated.