Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Creative Commons Attribution-ShareAlike 4.0

← All articles

Use it commercially, but anything you build on it stays under the same license. This is where Stack Overflow snippets bite.

What this license is

Creative Commons Attribution-ShareAlike 4.0 is copyleft for creative works: you may use the work commercially, and anything you adapt from it has to carry the same license. Copyleft means the license requires your version to stay under those terms instead of becoming proprietary. It covers Wikipedia text, Wikimedia media, community icon sets and diagrams, and Stack Overflow answers, code snippets included, which have been on version 4.0 since 2018. The duty attaches to Adapted Material, the license's term for a work built on the original.

Why it matters for your product

Unchanged use is the easy case. Put the image in your interface, credit the creator, and nothing else follows. Placing a work next to your own content is usually a collection rather than an adaptation. The risk lives entirely on the modification axis. Recolour an icon set to match your brand, redraw a diagram, or paste a Stack Overflow snippet into your source, and you have Adapted Material that has to be offered under CC BY-SA 4.0. A plain crop may or may not clear that bar, because Creative Commons ties adaptation to new creative input. That is a licensing decision about your own product, not a piece of paperwork.

You are meeting the terms when

  • You are covered for unchanged use when you credit the creator and keep the copyright notice, the license notice and the link, somewhere a user can reasonably find.
  • You stay in a collection when you place the work alongside your own material without changing it, which does not trigger share-alike.
  • You handle Adapted Material when you release your changed version under CC BY-SA 4.0, or under a license Creative Commons lists as compatible.
  • You keep the GPL route open when you fold the material into a GPLv3 work, which Creative Commons allows in that direction only.
  • You stay inside the grant when you add no technical measure that stops a recipient doing what the license permits.

Where teams get it wrong

  • Teams paste a Stack Overflow answer into the codebase. The site's content is share-alike and code snippets are covered, so it is not a free copy.
  • Teams recolour a CC BY-SA icon set to match the brand and ship it as proprietary art. The recoloured set is Adapted Material and keeps the license.
  • Teams read Creative Commons as meaning no conditions. This member of the family is copyleft, and it is the one that reaches into your own work.
  • Teams assume compatibility with GPLv3 runs both ways. It runs one way only, into the GPLv3 work, and there is no route back.

How SourceTrust handles this license

The catalog marks CC-BY-SA-4.0 as copyleft, so two items can appear. The attribution item appears in every deployment context, and a source offer item appears when the project ships binaries or uses a mixed context. On a hosted SaaS project you see the attribution item only. Neither is ticked for you: a person on your team confirms each one, and publishing stays blocked until every applicable item is confirmed. SourceTrust does not judge whether your asset is an adaptation. Read Reviewing a component for the review flow.

Related guides

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Handle this license in SourceTrust

Share-alike on a creative asset reaches into your own work, and it usually arrives through a snippet or a recoloured icon. SourceTrust lists every component carrying it and holds publishing until a person has confirmed the checklist.

Importing, reviewing and drafting are free. Your first public attestation page is free too: one lifetime Community page per organization, plus open-source projects connected to a public GitHub repository (up to 10 activations a calendar month).

Free pages carry SourceTrust attribution and stay open to search engines. Paid plans start at $29 per active project a month and remove the attribution.

Use code LICENSEGUIDE at checkout for 90% off your first 3 months on the monthly plan.

See what is free and what is paid