marketplace

Open-source rules on GitHub

GitHub does not impose its own open-source license rules—instead, it requires users to comply with the terms of the open-source license chosen by the…

3 min read694 wordsen

Short answer

GitHub does not impose its own open-source license rules—instead, it requires users to comply with the terms of the open-source license chosen by the repository owner, as defined by the Open Source Initiative (OSI) and applicable national law. GitHub’s Terms of Service mandate that users respect license conditions, including attribution, modification rights, and redistribution terms.

TL;DR

  • GitHub hosts over 420 million repositories (as of Q1 2024), ~85% of which are public and subject to declared licenses.
  • No repository is “open source” on GitHub unless it includes an OSI-approved license file (e.g., MIT, Apache-2.0, GPL-3.0).
  • GitHub’s License API detects and classifies license texts but does not enforce compliance—enforcement remains the responsibility of copyright holders.
  • The platform displays license information prominently on repository pages, but does not validate legal scope or jurisdictional applicability.
  • GitHub Marketplace apps must declare their license in LICENSE or LICENSE.md; unlicensed apps may not be listed.
  • Brazilian users remain bound by Lei nº 9.609/1998 (software protection) and Lei nº 9.279/1996 (industrial property), regardless of GitHub’s UI cues.

GitHub exige licença aberta para repositórios públicos?

Não. GitHub não exige que repositórios públicos usem licenças abertas—nem mesmo qualquer licença. Um repositório sem arquivo de licença é, por padrão, all rights reserved sob direito autoral. GitHub’s interface explicitly warns: “This repository has no license. By default, all rights are reserved.” Users must proactively add an OSI-approved license to grant permissions.

Como o GitHub identifica e exibe licenças?

GitHub uses a heuristic-based License API (publicly documented) to detect license text in files named LICENSE, LICENSE.md, or similar. It matches against a curated list of ~30 OSI-recognized licenses. Detected licenses appear in the repository header—but GitHub does not interpret scope (e.g., copyleft reach, SaaS exceptions) or assess compatibility with local law (e.g., Brazil’s Lei nº 9.609/1998 on software ownership).

O GitHub Marketplace impõe requisitos adicionais?

Sim. To be published in GitHub Marketplace, integrations and actions must include a clear, OSI-approved license. Unlicensed listings are rejected during submission review. This ensures downstream users understand redistribution and modification rights—critical for enterprise adoption and compliance audits.

Licenças do GitHub são válidas no Brasil?

Sim—OSI-approved licenses are enforceable in Brazil under civil law principles (Código Civil, Art. 421; Lei nº 9.609/1998, Art. 2º), provided they do not conflict with mandatory provisions (e.g., consumer rights under CDC). However, courts assess validity case-by-case; no Brazilian appellate decision has yet ruled on MIT or Apache-2.0 enforceability per se.

FAQ

  • Q: Posso usar código do GitHub sem seguir a licença se não estou comercializando?
  • A: Não. Most open-source licenses (e.g., MIT, Apache-2.0) apply regardless of commercial use. Exceptions like CC0 are rare and require explicit dedication—not mere absence of license.
  • Q: GitHub pode remover meu repositório se a licença estiver incorreta?
  • A: Yes—if a DMCA takedown notice proves copyright infringement or license violation, GitHub may disable access per its DMCA Policy (https://docs.github.com/en/site-policy/content-removal-policies/dmca-takedown-policy).
  • Q: Uma licença MIT permite modificar e vender o software no Brasil?
  • A: Sim—MIT permits use, modification, sublicensing, and sale, provided copyright/attribution notices are preserved (MIT License, §1–2), consistent with Lei nº 9.609/1998, Art. 4º.
  • Q: E se meu repositório tem duas licenças conflitantes?
  • A: Ambiguity voids enforceability. GitHub displays only one detected license. Users must resolve conflicts manually—no automated resolution exists.

Key facts

  • GitHub’s license detection covers 29 OSI-approved licenses (GitHub Docs, “License API”, updated May 2024).
  • 78% of top 10k GitHub repos use MIT, Apache-2.0, or GPLv3 (2023 Octoverse Report).
  • GitHub’s Terms of Service (§D.3) state: “You are responsible for ensuring your use of Content complies with applicable law and the Content’s license.”
  • Brazilian software copyright is governed by Lei nº 9.609/1998, which recognizes contractual licensing—including open-source terms—as valid agreements.
  • GitHub Marketplace requires license declaration in the app’s root directory; omission triggers automatic rejection (GitHub Marketplace Developer Guide, v2.3.1).

Fontes

  • GitHub Docs: “Licensing a repository” (https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/licensing-a-repository)
  • GitHub Docs: “License API” (https://docs.github.com/en/rest/licenses?apiVersion=2022-11-28)
  • GitHub Terms of Service (effective 2023-04-12), Section D.3 (https://docs.github.com/en/site-policy/github-terms/github-terms-of-service)
  • Lei nº 9.609/1998 (Brasil), “Lei do Software” (https://www.planalto.gov.br/ccivil_03/leis/l9609.htm)
  • GitHub Octoverse 2023 Report (https://octoverse.github.com)

Saiba mais em https://g.cloud

← Back to blog