OpenSource Risk Experts Get a free exposure review

RESEARCH · PRIMARY SOURCE TRACKER

The state of open source relicensing exposure, 2026.

BY · REVIEWED BY MORTEN ANDERSEN

Every major open source project that moved to source available terms, in one place: the date, the license before and after, whether an OSI approved open option has since been added, and the community fork that kept the prior terms alive. Compiled from primary sources and kept current.

KEY TAKEAWAYS

  • Four flagship data and infrastructure projects relicensed in seven years, affecting software run in production across most large enterprises.
  • Two of them, Elastic and Redis, later added the OSI approved AGPLv3 as an option. Two, HashiCorp and MongoDB, remain source available with no OSI approved open option.
  • Every relicensed project now has a community fork or an OSI approved alternative, most under Linux Foundation governance.

Major relicensing events, 2018 to 2026

ProjectOwnerChangedFromToOSI open option sinceCommunity fork
MongoDBMongoDB Inc.Oct 2018AGPLv3SSPLv1NoneFerretDB (Apache 2.0)
Elasticsearch, KibanaElastic2021 (7.11)Apache 2.0SSPL + Elastic LicenseAGPLv3, Sep 2024OpenSearch (Apache 2.0, Linux Foundation)
Terraform, Vault, Consul, Nomad, PackerHashiCorp (IBM, Feb 2025)Aug 2023MPL 2.0Business Source License 1.1NoneOpenTofu (MPL 2.0, Linux Foundation / CNCF)
RedisRedis Ltd.Mar 2024BSD 3-ClauseRSALv2 + SSPLv1AGPLv3, May 2025 (Redis 8)Valkey (BSD, Linux Foundation)

Source available licenses (BSL, SSPL, RSALv2) are not approved by the Open Source Initiative. License names and dates are referenced for identification only. Confirm current terms with your own counsel.

What the pattern means for buyers

The common thread is timing. In every case the license changed after the software was already running in production, which is what turns a licensing decision into an exposure. A project you adopted under Apache 2.0 or BSD did not change for you on the day you adopted it. It changed later, and the new terms can reach versions you deploy after the change date.

An added open option does not always neutralise the exposure. AGPLv3, which Elastic and Redis added, is OSI approved but is strong copyleft, and for some deployment models it creates obligations the prior permissive license did not. The right path depends on how you run the software, which version, and whether your use looks like a competing service. That is a mapping exercise, not a headline.

For a walkthrough of how we quantify and contain this, see the case studies and the BSL vs SSPL vs AGPL comparison. For how we research and review this page, see our editorial standards.

CITE THIS RESEARCH

OpenSource Risk Experts. "The State of Open Source Relicensing Exposure 2026." Updated 25 June 2026. https://opensourcelicenserisk.com/research/state-of-relicensing-exposure-2026/

Know your exposure before the next relicense.

A confidential, buyer side open source license risk assessment. Independent, paid only by you.

Get a free exposure review