LicenseGuard

Is webpki-roots safe for commercial use?

Rust crate package · License: CDLA-Permissive-2.0

webpki-roots is licensed under CDLA-Permissive-2.0. It carries no source-disclosure obligation, but its terms restrict how the software may be used, so all 5 shipping models below need a reading of the license itself.

Can I use webpki-roots in SaaS, a distributed app, or internally?

How you ship itResultWhy
Hosted SaaS Needs review CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
Distributed binary / app Needs review CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
Delivered to customer Needs review CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
Internal use only Needs review CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.
Published library Needs review CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

What obligations does webpki-roots carry?

None

If you only use it at build time, the answer changes.

CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

Questions this page answers

Is webpki-roots safe for commercial use?

webpki-roots is licensed under CDLA-Permissive-2.0. It carries no source-disclosure obligation, but its terms restrict how the software may be used, so all 5 shipping models below need a reading of the license itself.

Can I use webpki-roots (CDLA-Permissive-2.0) in hosted saas?

CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

Can I use webpki-roots (CDLA-Permissive-2.0) in distributed binary / app?

CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

Can I use webpki-roots (CDLA-Permissive-2.0) in delivered to customer?

CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

Can I use webpki-roots (CDLA-Permissive-2.0) in internal use only?

CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

Can I use webpki-roots (CDLA-Permissive-2.0) in published library?

CDLA-Permissive-2.0 does not match a known license identifier. The license text needs individual review.

Does webpki-roots matter if it is only a build-time or dev dependency?

CDLA-Permissive-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

This page covers one package. Your Cargo.lock has many more.

Check your whole manifest →

How was this determined?

The license was read from crates.io, then evaluated against each shipping model. Dependencies in this ecosystem are linked statically, which is assumed here. Only the declared license is considered; code copied into a project's own source files is not detected by this method.

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).