LicenseGuard

Is pitchfork safe for commercial use?

Ruby gem package · License: GPL-2.0+ AND Ruby

pitchfork is licensed under GPL-2.0+ AND Ruby. That triggers obligations in 3 of the 5 common shipping models, so whether it is safe for you depends on how you ship.

Can I use pitchfork in SaaS, a distributed app, or internally?

How you ship itResultWhy
Hosted SaaS No obligation Multiple licenses apply at once. GPL-2.0 triggers its obligations on distribution. Your distribution model is hosted SaaS, which is not distribution, so no obligation arises today. Shipping this software later — on-premises delivery, a binary, or a published library — would trigger whole-work source disclosure. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Distributed binary / app Obligation triggered Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is distributed binary or application, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Delivered to customer Obligation triggered Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is software delivered to a customer environment, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Internal use only No obligation Multiple licenses apply at once. GPL-2.0 triggers its obligations on distribution. Your distribution model is internal use only, which is not distribution, so no obligation arises today. Shipping this software later — on-premises delivery, a binary, or a published library — would trigger whole-work source disclosure. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.
Published library Obligation triggered Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is a published library, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

What obligations does pitchfork carry?

Attribution

If you only use it at build time, the answer changes.

Multiple licenses apply at once. GPL-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually. / Ruby appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

Questions this page answers

Is pitchfork safe for commercial use?

pitchfork is licensed under GPL-2.0+ AND Ruby. That triggers obligations in 3 of the 5 common shipping models, so whether it is safe for you depends on how you ship.

Can I use pitchfork (GPL-2.0+ AND Ruby) in hosted saas?

Multiple licenses apply at once. GPL-2.0 triggers its obligations on distribution. Your distribution model is hosted SaaS, which is not distribution, so no obligation arises today. Shipping this software later — on-premises delivery, a binary, or a published library — would trigger whole-work source disclosure. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use pitchfork (GPL-2.0+ AND Ruby) in distributed binary / app?

Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is distributed binary or application, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use pitchfork (GPL-2.0+ AND Ruby) in delivered to customer?

Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is software delivered to a customer environment, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use pitchfork (GPL-2.0+ AND Ruby) in internal use only?

Multiple licenses apply at once. GPL-2.0 triggers its obligations on distribution. Your distribution model is internal use only, which is not distribution, so no obligation arises today. Shipping this software later — on-premises delivery, a binary, or a published library — would trigger whole-work source disclosure. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Can I use pitchfork (GPL-2.0+ AND Ruby) in published library?

Multiple licenses apply at once. GPL-2.0 requires that a work incorporating it, when distributed, be licensed as a whole under the same terms with corresponding source made available. Your distribution model is a published library, which triggers that obligation. / Ruby requires retaining the copyright notice and the license text. There is no source-disclosure obligation.

Does pitchfork matter if it is only a build-time or dev dependency?

Multiple licenses apply at once. GPL-2.0 appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually. / Ruby appears as a dev dependency, so it is not part of the artifact you ship. Distribution-triggered obligations do not arise. Tools that emit code into your output, such as code generators, are a separate case worth checking individually.

This page covers one package. Your Gemfile.lock has many more.

Check your whole manifest →

How was this determined?

The license was read from the Ruby gem registry, then evaluated against each shipping model. Only the declared license is considered; code copied into a project's own source files is not detected by this method.

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).