Maine Street Partners

[ MSP.DD ] For investors and founders · Updated

What open-source licence risks show up in tech due diligence?

Short answer

Licence conflicts are common. Black Duck's 2025 analysis of 965 commercial codebases found licence conflicts in 56% of them, and open source with no licence or a custom licence in 33%. A copyleft component in the wrong place can force a company to release its own code or renegotiate customer contracts.

Why it matters

Licence problems rarely stop a deal, but they change its terms: warranties, a fix before closing, or a lower price. They're cheap to find and expensive to discover later.

How to check

  1. 01Generate a full dependency list, including transitive dependencies.
  2. 02Flag copyleft licences such as GPL and AGPL in distributed or hosted products.
  3. 03Flag components with no licence or a custom licence.
  4. 04Check the licence terms of AI models and datasets too, not only code.

Red flags

  • AGPL components inside a hosted product.
  • Code copied from the internet with no licence.
  • Open-weight models used against their licence terms.

Good signs

  • A maintained software bill of materials.
  • Licence checks in the build pipeline.

The numbers

  • Black Duck's 2025 OSSRA found licence conflicts in 56% of 965 audited commercial codebases, with transitive dependencies causing nearly 30% of them. [1]
  • 33% of the audited codebases contained open source with no licence or a customised licence. [1]
  • Only 77% of dependencies could be identified through package manager scanning. [1]

Sources

  1. Black Duck, 2025 Open Source Security and Risk Analysis (press release)