Breaking down the two main philosophies:
The Permissive and ‘Commercial-Friendly’ Licences
We breathe easy when I see these named; these are the licenses that businesses love – MIT License, Apache 2.0, or BSD. Properly permissive and give you maximum freedom.
Generally, what you can do:
- use,
- modify, and
- distribute the software, and
- most importantly, you can incorporate it into your own proprietary, closed-source commercial products.
Your main obligation on you is attribution. You just need to include the original copyright and license notice in your code. No need to share your code and you retain ownership.
These licenses are fantastic for commercial applications because they don’t compromise your business model or force you to give away your secret sauce.
The Copyleft and ‘Reciprocal’ Licences
The ones that keep me up at night and where things can get tricky – GPL (particularly GPLv3) etc.
The core idea is to keep software free. If you use a GPL-licensed component in your software and distribute that software, your entire “derivative work” must also be licensed under the GPL.
The bit that can sting is the ‘viral’ risk: the licence can spread to your own code. Using a single GPLv3 library can legally obligate you to make the entire source code of your application available to anyone who receives a copy. For a commercial company, this is often a non-starter – you can instantly lose your competitive advantage. Oops.
While you still technically own the copyright to your contributions, the GPLv3 dictates the terms under which you can license the combined work; designed to protect user freedom, but to the detriment of ‘closed’ commercial interests.
What’s Best?
There’s no “good” or “bad” license—it’s all about context and compatibility with your project’s goals and where you see your ‘value’.
The danger lies in ignorance – a junior dev could pull in a cool GPLv3 library without realising it could force your super pricey product to end up open-sourced.
Make sure to:
- Audit your dependencies: Know what’s in your codebase.
- Establish clear policies and train the team: Define which licenses are pre-approved for use.
- Be proactive, be informed, and protect your IP (saves us the headache too!).


