CC-BY-SA-3.0 is share-alike content copyleft from 2007. Adaptations you share must stay under SA. Wikipedia used this before moving to 4.0.
On this page
What it does
Creative Commons Attribution-ShareAlike 3.0 Unported lets you use and adapt the work, including commercially, if you credit the author and license adaptations under CC-BY-SA. Version 3 is not identical to 4.0 (moral rights, database rights, compatibility). Wikipedia's text was CC-BY-SA-3.0 for years. This is not GPL and not a code license.
Pros
- The grant is public and the reciprocity is written down. Buyers know what they are looking at.
- Internal use without distribution stays ordinary. The hard work starts when a copy leaves the company.
Cons
- The source-offer duty is real the moment you distribute binaries that include covered files.
- How far copyleft reaches in a mixed stack is a counsel question. Do not guess from a blog post.
What it allows and requires
Choose a category to see the full grant in one scannable list. Permissions show what the license allows, limits show what it withholds, and obligations show the conditions your release process must satisfy.
Permissions
Commercial use
Commercial use is allowed. CC-BY and OFL do not ban selling a product that includes the work.
Modify
You may adapt the work, within the license's share-alike or non-commercial limits if those apply.
Distribute
You may share copies of the original and, where allowed, of your adaptations.
Limits
Hold liable
The authors disclaim warranty. Recipients cannot hold them liable for damages arising from the software, except where law forbids that disclaimer.
Use trademark
The license is not a trademark license. Names, logos and product marks stay with their owners unless a separate grant says otherwise.
Obligations
Give credit
Give the credit the license asks for, in a reasonable manner, without implying endorsement.
Same license
Adapted Material you share must go out under CC BY-SA 4.0 or a Creative Commons compatible license, not a more restrictive wrap.
What CC-BY-SA-3.0 requires when you ship
When you distribute a binary that includes CC-BY-SA-3.0 code, notice still travels with the copy, and the corresponding source has to be available under the same license. Internal use without a copy leaving the company is a different situation. The list below is the shipping work: what a recipient of that binary can demand, and what you record so a buyer can see it.
You meet CC-BY-SA-3.0 on a shipped binary when every recipient can get the corresponding source the license describes.
You meet the notice terms when the original copyright lines and the license text travel with the copy.
You keep internal use inside the terms when no copy leaves your company. Distribution is what usually turns the source duty into real work.
The duties named in CC-BY-SA-3.0
Notice still travels with the copy. On top of that, CC-BY-SA-3.0 names a source duty. These are the conditions in the text. The how-to above is when they become real work.
Give credit
Give the credit the license asks for, in a reasonable manner, without implying endorsement.
Same license
Adapted Material you share must go out under CC BY-SA 4.0 or a Creative Commons compatible license, not a more restrictive wrap.
Things to be aware of
- Saying you only use CC-BY-SA-3.0 on the server, then shipping a Docker image or an on-prem build. Ask the question per artifact you hand out.
- Offering source for the covered package alone when the license asks for corresponding source of the work you shipped.
What the Creative Commons Attribution-ShareAlike 3.0 does not do
Search results often flatten Creative Commons Attribution-ShareAlike 3.0 into a slogan. These are the usual misreads. CC-BY-SA-3.0 is a grant with conditions, not a permission to skip the paperwork below.
- CC-BY-SA-3.0 is not "permissive with extra paperwork." Change covered files and ship them, and that source has to be available under the same license.
- CC-BY-SA-3.0 does not erase notice duties. Copyright lines and the license text still travel with the copies you hand over.
How CC-BY-SA-3.0 differs from nearby licenses
These licenses are often confused with CC-BY-SA-3.0, but their release duties differ. Each row summarizes what the license requires when you ship. Open the linked page for the full checklist.
- CC-BY-SA-3.0
- CC-BY-SA-3.0 is share-alike content copyleft from 2007. Adaptations you share must stay under SA. Wikipedia used this before moving to 4.0.
- CC-BY-SA-4.0
- Use it commercially, but anything you build on it stays under the same license. This is where Stack Overflow snippets bite.
- CC-BY-3.0
- The older Creative Commons Attribution license. The same deal as 4.0, with a stricter credit form and national ported versions.
Common questions about Creative Commons Attribution-ShareAlike 3.0
Answers to common questions about what Creative Commons Attribution-ShareAlike 3.0 requires, when its duties apply, and what evidence belongs with a release.
What is the Creative Commons Attribution-ShareAlike 3.0?
Creative Commons Attribution-ShareAlike 3.0 Unported lets you use and adapt the work, including commercially, if you credit the author and license adaptations under CC-BY-SA. Version 3 is not identical to 4.0 (moral rights, database rights, compatibility). Wikipedia's text was CC-BY-SA-3.0 for years. This is not GPL and not a code license.
What does CC-BY-SA-3.0 require when you ship a product?
You meet CC-BY-SA-3.0 on a shipped binary when every recipient can get the corresponding source the license describes. You meet the notice terms when the original copyright lines and the license text travel with the copy. You keep internal use inside the terms when no copy leaves your company. Distribution is what usually turns the source duty into real work.
Does hosting a product that uses CC-BY-SA-3.0 trigger extra duties?
Hosting alone usually does not trigger the source duty for CC-BY-SA-3.0. Shipping a binary, a container, or an on-prem build does. Notice still travels with any copy you hand over.
Can I keep my application closed if I use CC-BY-SA-3.0?
CC-BY-SA-3.0 is library-scoped copyleft. Your application can stay closed if recipients can replace the library with their own build. Static linking makes that expensive. The library itself still ships with corresponding source and notices. Confirm the linking story on the component, then record it.
What is corresponding source for CC-BY-SA-3.0?
Corresponding source is the source a recipient needs to build and run the same binary, including scripts and interface files the license names. Hosting a repository URL can be an offer. The offer has to match what you actually shipped. SourceTrust records that a person on your team confirmed the offer. It does not publish your source and does not host a mirror.
How is CC-BY-SA-3.0 different from Creative Commons Attribution-ShareAlike 4.0?
CC-BY-SA-3.0 asks this: CC-BY-SA-3.0 is share-alike content copyleft from 2007. Adaptations you share must stay under SA. Wikipedia used this before moving to 4.0. Creative Commons Attribution-ShareAlike 4.0 asks this: Use it commercially, but anything you build on it stays under the same license. This is where Stack Overflow snippets bite. Open the Creative Commons Attribution-ShareAlike 4.0 page for what that license requires when you ship. Do not treat the SPDX ids as interchangeable because the short names look similar.
Where do I record CC-BY-SA-3.0 for a buyer?
The catalog marks CC-BY-SA-3.0 as copyleft, so a source offer item appears on the project checklist when the project's distribution context is Distributed binary or Mixed. A SaaS-only project sees no item for it unless the row also carries a network trigger. Nobody ticks the item for you: a person on your team confirms it, and publishing stays blocked until every applicable item is confirmed. SourceTrust does not publish your source and does not host a mirror.
Where do I record CC-BY-SA-3.0 for a buyer?
The catalog marks CC-BY-SA-3.0 as copyleft, so a source offer item appears on the project checklist when the project's distribution context is Distributed binary or Mixed. A SaaS-only project sees no item for it unless the row also carries a network trigger.
Nobody ticks the item for you: a person on your team confirms it, and publishing stays blocked until every applicable item is confirmed. SourceTrust does not publish your source and does not host a mirror.
See also
The hub is the pillar for this cluster. Sibling licenses are the other spokes. Product FAQ links explain how SourceTrust records the duty, not the license text itself.
Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.
