Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Source available licenses

← All articles

You can read the code. That is not the same as permission to use it any way you like. Source available is not open source.

What this license is

Source available is a family rather than a single license, and its members share one habit: they publish the code and then restrict what you may do with it. Four shapes cover nearly all of them. Time-delayed licenses convert to an open license later (BUSL-1.1 after about four years, the Functional Source License after two, to MIT or Apache-2.0). Competing-service prohibitions never convert (Elastic-2.0, Confluent Community). One takes network copyleft to an extreme (SSPL-1.0). Scope-of-use grants put the permitted scope in the license name itself, which is the PolyForm family: Noncommercial, Small Business, Internal Use, Perimeter, Shield, Strict and Free Trial.

Why it matters for your product

None of these licenses is open source, and the reason is precise rather than political. The Open Source Definition allows no restriction on the field of use, and every license here has one. What that means for you depends on how you ship. Internal use is permitted by most of them, so most of these dependencies are fine where they sit. The noncommercial PolyForm variants are the exception: there, a commercial company's internal use is the prohibited case. Offering the software itself to third parties as a service is the restriction they nearly all share. A library or SDK you hand to other developers is usually the blocker, because your customers inherit a restriction they never agreed to.

You are meeting the terms when

  • You have read that project's actual text rather than the family name. Most of these licenses have fill-in fields, so two projects under one identifier can grant different things.
  • You use the software inside your own systems. Internal production use is permitted by most of these licenses, but not by the noncommercial ones: under PolyForm Noncommercial, a commercial company's internal use is the prohibited case.
  • You are not offering the software itself to third parties as a hosted or managed service, which is the restriction almost every license in this family shares.
  • You have checked whether your customers would inherit the restriction before putting one of these in a library or an SDK you hand to other developers.
  • You have recorded the version and the terms you read. An upstream license change does not reach the version you already have, but your next upgrade is a new decision.

Where teams get it wrong

  • Teams call it open source because the source sits on GitHub. Published source and an open-source license are different things, and buyers increasingly know the difference.
  • Teams assume a relicensing announcement applies to the version already in their lockfile. It does not. The upgrade is where the decision actually happens.
  • Teams expect every license in this family to be flagged for them. Coverage is uneven, and the FSL and Confluent Community identifiers raise nothing at all.
  • Teams treat the family as uniform. A BUSL project converts to an open license on a date, while an Elastic-2.0 project never converts at all.

How SourceTrust handles this license

No license in this family ever lands on confirmed. The verifier refuses that outcome for all of them, so each one reaches a person with the extracted text attached. A filled-in template is labelled as the license with package-specific parameters rather than as a modification. Coverage past that point is uneven. BUSL-1.1, Elastic-2.0, SSPL-1.0 and two PolyForm variants have catalog rows, so a network distribution review item can appear on the checklist. The FSL and Confluent Community identifiers have none. Read Inventory and compliance overview.

  • Every templated identifier, from BUSL-1.1 and SSPL-1.0 through Elastic-2.0, Confluent Community and the FSL and PolyForm families, is kept out of the auto-fill lane on purpose.
  • No external obligation exists for a use restriction as such. The one checklist item that can fire here is the network distribution review, and only for a license the catalog marks as one a network deployment does not clear. The PolyForm, CC-BY-NC and CC-BY-ND identifiers do raise a restricted-use compatibility warning on the component page, in every deployment context.
  • Nothing in this family is decided for you. The review is yours, and the text stored on the component is what your attestation page carries.

Related guides

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Handle this license in SourceTrust

A source available dependency is a commercial decision hiding in a lockfile. SourceTrust puts the project's own wording in front of the person who has to make it, and keeps the answer with the component.

Importing, reviewing and drafting are free. Your first public attestation page is free too: one lifetime Community page per organization, plus open-source projects connected to a public GitHub repository (up to 10 activations a calendar month).

Free pages carry SourceTrust attribution and stay open to search engines. Paid plans start at $29 per active project a month and remove the attribution.

Use code LICENSEGUIDE at checkout for 90% off your first 3 months on the monthly plan.

See what is free and what is paid