webpki-root-certs safe for commercial use?Rust crate package · License: CDLA-Permissive-2.0
webpki-root-certs is licensed under CDLA-Permissive-2.0. It carries no source-disclosure obligation, but its terms restrict how the software may be used, so all 5 shipping models below need a reading of the license itself.
| How you ship it | Result | Why |
|---|---|---|
| Hosted SaaS | Needs review | CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review. |
| Distributed binary / app | Needs review | CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review. |
| Delivered to customer | Needs review | CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review. |
| Internal use only | Needs review | CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review. |
| Published library | Needs review | CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review. |
None
If you only use it at build time, the answer changes.
CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.
webpki-root-certs is licensed under CDLA-Permissive-2.0. It carries no source-disclosure obligation, but its terms restrict how the software may be used, so all 5 shipping models below need a reading of the license itself.
CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.
This page covers one package. Your Cargo.lock has many more.
Check your whole manifest →The license was read from crates.io, then evaluated against each shipping model. Dependencies in this ecosystem are linked statically, which is assumed here. Only the declared license is considered; code copied into a project's own source files is not detected by this method.
License data last reviewed .
LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.
Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).