Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Business Source License 1.1

← All articles

Source available, not open source. Each version converts to an open license on its own Change Date, usually four years after release.

What this license is

The Business Source License 1.1 is a time-delayed license. It is not open source on the day it ships, and it becomes open source on a date the publisher picks. Four fields are filled in per project: the Licensor, the Change Date, the Change License the code converts to, and an Additional Use Grant that says what use is permitted in the meantime. HashiCorp moved Terraform, Vault, Consul and Nomad to it in August 2023. Sentry, CockroachDB, MariaDB MaxScale and Couchbase Server use it too.

Why it matters for your product

Two projects can carry the same BUSL-1.1 identifier and permit completely different things, because the Additional Use Grant is written per project. Running Terraform inside your own build is fine under the usual grant. Selling a hosted Terraform service is the exact thing the license exists to stop. The Change Date matters just as much: each version converts on a date of its own, so the version pinned in your lockfile may already be Apache-2.0 while the current release is not. Read the grant, then record the version and the date.

You are meeting the terms when

  • You have read that project's Additional Use Grant. It is the paragraph that says what you may do before the Change Date, and it differs from project to project.
  • You are not offering the software, or a service substantially similar to it, commercially to third parties before the Change Date, unless the Use Grant allows it.
  • You use it inside your own build or your own product. Development, testing and internal production use are permitted by the usual Use Grant.
  • You have recorded the version you depend on together with its Change Date and its Change License, because each version converts on a date of its own.
  • You keep the license file and the copyright notices intact in anything you pass on. The notice condition applies for the whole period before conversion.

Where teams get it wrong

  • Teams treat BUSL as one license with one set of terms. It is a template, so the Licensor, Change Date, Change License and Use Grant have to be read per project.
  • Teams expect the whole project to flip to open source on one day. It converts version by version, so an old release can be open while the newest one is not.
  • Teams pin a version from before the license change and stop thinking about it. The next upgrade is a fresh legal decision rather than a routine bump.
  • Teams read source available as no obligations. The notice condition still applies, and the limit on competing services is the whole point of the license.

How SourceTrust handles this license

The catalog records BUSL-1.1 as source available, and as a license a network deployment does not clear. So SourceTrust puts a network distribution review item on the checklist for SaaS and mixed projects, and holds publishing until a person confirms it. The fetch never lands BUSL on confirmed, even when the text matches a reference copy exactly. A filled-in template is package-specific terms, so the result is labelled as the license with package-specific parameters rather than as modified. The component page also shows a compatibility warning about competing commercial services in every deployment context except Library or SDK. Read Auto-fetch license text.

  • The stored text is that project's own filled-in copy, which is the one that governs you. A reference copy would not carry its Use Grant.
  • SourceTrust does not track Change Dates for you. Record the version and its date where the person who upgrades the dependency will see it.
  • The checklist item is not ticked for you. The tick is stored per obligation on the component, and publishing stays blocked until a person sets it. Who approved the component, and when, is recorded on the approval decision.

Related guides

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Handle this license in SourceTrust

A BUSL dependency is a commercial question hiding in a lockfile. SourceTrust puts the project's own filled-in terms in front of the person who has to answer it, and keeps the answer with the component.

Importing, reviewing and drafting are free. Your first public attestation page is free too: one lifetime Community page per organization, plus open-source projects connected to a public GitHub repository (up to 10 activations a calendar month).

Free pages carry SourceTrust attribution and stay open to search engines. Paid plans start at $29 per active project a month and remove the attribution.

Use code LICENSEGUIDE at checkout for 90% off your first 3 months on the monthly plan.

See what is free and what is paid