pako safe for commercial use?npm package · License: (MIT AND Zlib)
pako is licensed under (MIT AND Zlib), which imposes no source-disclosure obligation in any of the shipping models below.
| How you ship it | Result | Why |
|---|---|---|
| Hosted SaaS | No obligation | Multiple licenses apply at once. MIT requires retaining the copyright notice and the license text. There is no source-disclosure obligation. / Zlib requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Distributed binary / app | No obligation | Multiple licenses apply at once. MIT requires retaining the copyright notice and the license text. There is no source-disclosure obligation. / Zlib requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Delivered to customer | No obligation | Multiple licenses apply at once. MIT requires retaining the copyright notice and the license text. There is no source-disclosure obligation. / Zlib requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Internal use only | No obligation | Multiple licenses apply at once. MIT requires retaining the copyright notice and the license text. There is no source-disclosure obligation. / Zlib requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
| Published library | No obligation | Multiple licenses apply at once. MIT requires retaining the copyright notice and the license text. There is no source-disclosure obligation. / Zlib requires retaining the copyright notice and the license text. There is no source-disclosure obligation. |
Attribution
If you only use it at build time, the answer changes.
Multiple licenses apply at once. MIT appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually. / Zlib appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.
This page covers one package. Your package-lock.json has many more.
Check your whole manifest →The license was read from the npm registry, then evaluated against each shipping model. Only the declared license is considered; code copied into a project's own source files is not detected by this method.
LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.