LicenseGuard

Is rollup-plugin-dts safe for commercial use?

npm package · License: LGPL-3.0-only

rollup-plugin-dts is licensed under LGPL-3.0-only. Nothing below is blocked, but it carries a source-disclosure obligation — what triggers it differs by how you ship, so read the table.

Can I use rollup-plugin-dts in SaaS, a distributed app, or internally?

How you ship itResultWhy
Hosted SaaS No obligation LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.
Distributed binary / app No obligation LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.
Delivered to customer No obligation LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.
Internal use only No obligation LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.
Published library No obligation LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

What obligations does rollup-plugin-dts carry?

Source disclosureAttribution

If you only use it at build time, the answer changes.

LGPL-3.0-only appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

What is LGPL-3.0-only?

Weak copyleft built on GPL-3.0 with a linking exception. The practical question is almost always static versus dynamic linking, since static linking triggers the relinking obligation.

Full LGPL-3.0-only reference →

Questions this page answers

Is rollup-plugin-dts safe for commercial use?

rollup-plugin-dts is licensed under LGPL-3.0-only. Nothing below is blocked, but it carries a source-disclosure obligation — what triggers it differs by how you ship, so read the table.

Can I use rollup-plugin-dts (LGPL-3.0-only) in hosted saas?

LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

Can I use rollup-plugin-dts (LGPL-3.0-only) in distributed binary / app?

LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

Can I use rollup-plugin-dts (LGPL-3.0-only) in delivered to customer?

LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

Can I use rollup-plugin-dts (LGPL-3.0-only) in internal use only?

LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

Can I use rollup-plugin-dts (LGPL-3.0-only) in published library?

LGPL-3.0-only requires publishing modifications to the library itself, but under dynamic linking that obligation does not extend to the code that calls it.

Does rollup-plugin-dts matter if it is only a build-time or dev dependency?

LGPL-3.0-only appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

This page covers one package. Your package-lock.json has many more.

Check your whole manifest →

How was this determined?

The license was read from the npm registry, then evaluated against each shipping model. Only the declared license is considered; code copied into a project's own source files is not detected by this method.

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).