LicenseGuard

Is webpki-root-certs safe for commercial use?

Rust crate package · License: CDLA-Permissive-2.0

webpki-root-certs is licensed under CDLA-Permissive-2.0, which imposes no source-disclosure obligation in any of the shipping models below. Attribution still applies.

Can I use webpki-root-certs in SaaS, a distributed app, or internally?

How you ship itResultWhy
Hosted SaaS No obligation CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Distributed binary / app No obligation CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Delivered to customer No obligation CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Internal use only No obligation CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Published library No obligation CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

What obligations does webpki-root-certs carry?

Attribution

If you only use it at build time, the answer changes.

CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

Questions this page answers

Is webpki-root-certs safe for commercial use?

webpki-root-certs is licensed under CDLA-Permissive-2.0, which imposes no source-disclosure obligation in any of the shipping models below. Attribution still applies.

Can I use webpki-root-certs (CDLA-Permissive-2.0) in hosted saas?

CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use webpki-root-certs (CDLA-Permissive-2.0) in distributed binary / app?

CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use webpki-root-certs (CDLA-Permissive-2.0) in delivered to customer?

CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use webpki-root-certs (CDLA-Permissive-2.0) in internal use only?

CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use webpki-root-certs (CDLA-Permissive-2.0) in published library?

CDLA-Permissive-2.0 requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Does webpki-root-certs matter if it is only a build-time or dev dependency?

CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

This page covers one package. Your Cargo.lock has many more.

Check your whole manifest →

How was this determined?

The license was read from crates.io, then evaluated against each shipping model. Dependencies in this ecosystem are linked statically, which is assumed here. Only the declared license is considered; code copied into a project's own source files is not detected by this method.

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).