License risks
See the different levels of open-source license risks.
To grade the potential compliance risks involved with different licenses, we assess them using a grading system. Keep in mind that the color grading simply represents the estimated amount and complexity of the compliance concerns. This does not mean that some licenses are riskier than others - if you understand all the compliance requirements of a license and are able to fulfill them, then the license is practically risk-free regardless of our grading.
The risk levels are created under the assumption that the installed dependency is not affected by external factors, including, but not limited to, interactions with other dependencies and effects of compilation. We advise you to adjust the risk levels based on your own internal policies, risk tolerance and use case.
Banned license, high compliance risk, not allowed
This grading is used for a license that is not allowed use, e.g. in company or project context, or for a use-case reason (such as with GPLv3 in consumer electronics) because it will likely cause a breach of the license terms, exposing you to possible legal challenges.
To read more about license families, license risks, use cases, and compliance - check out our blog.
Last updated