Copyleft and Consequences: Open Source Licensing and the Software Supply Chain

By ·

Almost every modern software product is assembled rather than written, and the assembly is governed by licenses most engineering teams have never read. This article explains how open source licensing actually works as a legal matter - a copyright license with conditions, enforceable because a condition failed means the license never applied and the use is infringement. It covers the decision that established that framework, the copyleft licenses whose conditions reach the code you combine with them, the permissive licenses whose conditions are trivial to satisfy and are still violated constantly, and the compatibility problems that make some combinations impossible. It works through the enforcement landscape, including the Ninth Circuit's treatment of a license modified by a further restriction, and the contract-based theories that supplement copyright claims. It then covers the supply chain layer that regulators now care about: software bills of materials, the federal cybersecurity requirements that made them mandatory for suppliers, and the diligence that decides software acquisitions.

IP and Technology > Information Technology | Article | Published 23 May 2024 - Updated 29 May 2026 | Casey Scott McKay - marksy.us

Summary. Almost every modern software product is assembled rather than written, and the assembly is governed by licenses most engineering teams have never read. This article explains how open source licensing actually works as a legal matter — a copyright license with conditions, enforceable because a condition failed means the license never applied and the use is infringement. It covers the decision that established that framework, the copyleft licenses whose conditions reach the code you combine with them, the permissive licenses whose conditions are trivial to satisfy and are still violated constantly, and the compatibility problems that make some combinations impossible. It works through the enforcement landscape, including the Ninth Circuit's treatment of a license modified by a further restriction, and the contract-based theories that supplement copyright claims. It then covers the supply chain layer that regulators now care about: software bills of materials, the federal cybersecurity requirements that made them mandatory for suppliers, and the diligence that decides software acquisitions.

Keywords: open source licensing · copyleft · gpl compliance · jacobsen v katzer · conditions versus covenants · artifex v hancom · neo4j v purethink · commons clause · apache 2.0 patent grant · license compatibility · permissive licenses · agpl network use · software bill of materials · executive order 14028 · google v oracle api · source available licenses · contributor license agreement · m&a open source diligence · trademark carve-out

This is premium Marksy content — the full document is available to subscribers.

Read this article on Marksy