The 8 policies in the pack

This project is built and maintained by an automated agent system.

Not legal advice; verify with qualified counsel.

Policy pack version 1.0.0 (dated 2026-10-09). The rule sets reflect the maintainer's interpretation and may become outdated.

Each policy is one JSON file for the CLI. The table below is taken from those files and from the pack's matrix of 62 licences. Strong copyleft means GPL-2.0-only, GPL-2.0-or-later, GPL-3.0-only and GPL-3.0-or-later. Network copyleft means AGPL-3.0-only, AGPL-3.0-or-later, SSPL-1.0 and OSL-3.0. Proprietary means BUSL-1.1, Elastic-2.0, Commons-Clause, PolyForm-Noncommercial-1.0.0 and PolyForm-Small-Business-1.0.0.

PolicyIntended project typeStrong copyleftNetwork copyleftProprietary licences
saas-proprietary
Proprietary SaaS (no distribution)
A closed-source service that runs on your own servers and is never handed to customers as a download, installer or container image.All four: reviewAll four: denyCommons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review
proprietary-binary
Proprietary distributed binary (desktop or mobile app)
A closed-source app shipped to users as an installer, app-store package or executable, including the bundled third-party code.All four: denyAll four: denyCommons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review
proprietary-onprem
Proprietary on-premise delivered to customers
A closed-source product installed on the customer's own servers: packages, installers, virtual appliances or container images you hand over.All four: denyAll four: denyBUSL-1.1, Elastic-2.0, Commons-Clause and PolyForm-Noncommercial: deny; PolyForm-Small-Business: review
oss-permissive-library
MIT or Apache-2.0 open-source library
A permissively licensed library or tool that downstream users embed in their own code, open or closed.All four: denyAll four: denyAll five: deny
gpl3-project
GPL-3.0 project
A project released under GPL-3.0-only or GPL-3.0-or-later that wants every dependency to be compatible with that licence.GPL-2.0-only: deny; GPL-2.0-or-later, GPL-3.0-only and GPL-3.0-or-later: allowAGPL-3.0-only and AGPL-3.0-or-later: review; SSPL-1.0 and OSL-3.0: denyAll five: deny
agpl-averse-baseline
AGPL-averse company-wide baseline
One policy for every repository in a company that mixes services, apps and libraries, when the company wants network-copyleft and non-commercial licences kept out entirely.All four: reviewAll four: denyCommons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review
embedded-firmware
Embedded or firmware distribution
Firmware, RTOS-based or Linux-based device images that ship to customers on hardware, where users may not be able to replace the software.GPL-2.0-only and GPL-2.0-or-later: review; GPL-3.0-only and GPL-3.0-or-later: denyAll four: denyCommons-Clause and PolyForm-Noncommercial: deny; BUSL-1.1, Elastic-2.0 and PolyForm-Small-Business: review
internal-tooling
Internal tooling only
Scripts, dashboards and build tools used only by your own staff and never delivered to customers or exposed to outside users.All four: allowAll four: reviewElastic-2.0: allow; PolyForm-Noncommercial: deny; BUSL-1.1, Commons-Clause and PolyForm-Small-Business: review

Matrix preview: 8 of 62 rows

The full matrix in the pack lists every licence under all eight policies. These are 8 of its rows, unchanged.

SPDX idCategorysaas-proprietaryproprietary-binaryproprietary-onpremoss-permissive-librarygpl3-projectagpl-averse-baselineembedded-firmwareinternal-tooling
MITpermissiveallowallowallowallowallowallowallowallow
Apache-1.1permissiveallowreviewreviewreviewdenyreviewreviewallow
MPL-2.0weak-copyleftallowreviewreviewallowallowreviewreviewallow
LGPL-3.0-onlyweak-copyleftallowreviewreviewreviewallowreviewdenyallow
GPL-3.0-onlystrong-copyleftreviewdenydenydenyallowreviewdenyallow
AGPL-3.0-onlynetwork-copyleftdenydenydenydenyreviewdenydenyreview
BUSL-1.1proprietaryreviewreviewdenydenydenyreviewreviewreview
CC-BY-NC-4.0otherdenydenydenydenydenydenydenydeny

Where to get it

The CLI source: coming soon.

The pack (version 1.0.0, dated 2026-10-09): coming soon. The rule sets reflect the maintainer's interpretation and may become outdated.