RESEARCH · PRIMARY SOURCE TRACKER
The state of open source relicensing exposure, 2026.
BY FREDRIK FILIPSSON · REVIEWED BY MORTEN ANDERSEN
Every major open source project that moved to source available terms, in one place: the date, the license before and after, whether an OSI approved open option has since been added, and the community fork that kept the prior terms alive. Compiled from primary sources and kept current.
KEY TAKEAWAYS
- Four flagship data and infrastructure projects relicensed in seven years, affecting software run in production across most large enterprises.
- Two of them, Elastic and Redis, later added the OSI approved AGPLv3 as an option. Two, HashiCorp and MongoDB, remain source available with no OSI approved open option.
- Every relicensed project now has a community fork or an OSI approved alternative, most under Linux Foundation governance.
Major relicensing events, 2018 to 2026
| Project | Owner | Changed | From | To | OSI open option since | Community fork |
|---|---|---|---|---|---|---|
| MongoDB | MongoDB Inc. | Oct 2018 | AGPLv3 | SSPLv1 | None | FerretDB (Apache 2.0) |
| Elasticsearch, Kibana | Elastic | 2021 (7.11) | Apache 2.0 | SSPL + Elastic License | AGPLv3, Sep 2024 | OpenSearch (Apache 2.0, Linux Foundation) |
| Terraform, Vault, Consul, Nomad, Packer | HashiCorp (IBM, Feb 2025) | Aug 2023 | MPL 2.0 | Business Source License 1.1 | None | OpenTofu (MPL 2.0, Linux Foundation / CNCF) |
| Redis | Redis Ltd. | Mar 2024 | BSD 3-Clause | RSALv2 + SSPLv1 | AGPLv3, May 2025 (Redis 8) | Valkey (BSD, Linux Foundation) |
Source available licenses (BSL, SSPL, RSALv2) are not approved by the Open Source Initiative. License names and dates are referenced for identification only. Confirm current terms with your own counsel.
What the pattern means for buyers
The common thread is timing. In every case the license changed after the software was already running in production, which is what turns a licensing decision into an exposure. A project you adopted under Apache 2.0 or BSD did not change for you on the day you adopted it. It changed later, and the new terms can reach versions you deploy after the change date.
An added open option does not always neutralise the exposure. AGPLv3, which Elastic and Redis added, is OSI approved but is strong copyleft, and for some deployment models it creates obligations the prior permissive license did not. The right path depends on how you run the software, which version, and whether your use looks like a competing service. That is a mapping exercise, not a headline.
For a walkthrough of how we quantify and contain this, see the case studies and the BSL vs SSPL vs AGPL comparison. For how we research and review this page, see our editorial standards.
CITE THIS RESEARCH
OpenSource Risk Experts. "The State of Open Source Relicensing Exposure 2026." Updated 25 June 2026. https://opensourcelicenserisk.com/research/state-of-relicensing-exposure-2026/
Know your exposure before the next relicense.
A confidential, buyer side open source license risk assessment. Independent, paid only by you.