CC-BY-4.0 · Permissive
Permissive for content, requiring attribution. Designed for creative works rather than code, so it lacks the warranty and patent language software licenses normally carry.
The same license produces different obligations depending on whether the software is distributed, hosted, or kept internal. This is the distinction most dependency scanners collapse.
| How you ship it | Result | Why |
|---|---|---|
| Hosted SaaS | No obligation | CC-BY-4.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Distributed binary / app | No obligation | CC-BY-4.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Delivered to customer | No obligation | CC-BY-4.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Internal use only | No obligation | CC-BY-4.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Published library | No obligation | CC-BY-4.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
Attribution
As a build-time dependency it is a different question.
CC-BY-4.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.
Want to know whether anything in your project is under CC-BY-4.0?
Check your whole manifest →LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.