Skip to main content
See other licenses

UPL-1.0

Universal Permissive License v1.0

UPL-1.0 is Oracle's short permissive grant with an express patent license. Notice stays. Intended as a simpler Apache-2.0 for some Oracle drops.

On this page

What it does

The Universal Permissive License 1.0 lets you use, change and ship the software, including commercially, with an express patent grant from contributors. Keep the copyright and permission notice. There is no Apache NOTICE file dance. Oracle used it on some Java and cloud samples. Buyers who want Apache-2.0's extra patent-termination language should still read the UPL text.

Pros

  • Easy to drop into a closed, paid product. Procurement has seen this family many times.
  • No copyleft on your own files. You keep your source private.

Cons

  • The notice duty is easy to miss in a desktop, mobile, or container build. A web page is not a substitute for notices inside the artifact.
  • Transitive copies in the lockfile count. Listing only direct dependencies leaves notices out.

What it allows and requires

Choose a category to see the full grant in one scannable list. Permissions show what the license allows, limits show what it withholds, and obligations show the conditions your release process must satisfy.

Permissions

  • Commercial use

    You may ship the code inside a paid product. The license does not restrict commercial use.

  • Modify

    You may change the code, including keeping those changes private, unless a later obligation says otherwise.

  • Distribute

    You may give copies to others. Distribution is what usually turns notice and source duties into real work.

  • Sublicense

    You may include the code under your own product terms, so long as you still meet this license's conditions.

  • Private use

    Use inside your company, including internal forks, does not by itself trigger distribution duties.

  • Patent use

    The license includes an express patent grant from contributors for the licensed work.

What UPL-1.0 requires when you ship

When a copy that includes UPL-1.0 code leaves your company, the grant is broad and the paperwork is easy to miss. Distribution here means an installer, a mobile binary, a container image, or an SDK another team embeds. Work this list against the artifact you actually hand over, not against a README. A hosted service that never gives out a copy still belongs on the record, but the notice duty does not fire until a copy exists.

  1. You meet the notice condition when each UPL-1.0 component's copyright line and license text appear in the material the recipient actually gets.

  2. You are done for a hosted service that never hands out a copy. Running the software for users over a network does not, by itself, trigger a notice duty.

  3. You are covered for a desktop, mobile or on-premise build when the notices sit inside the artifact. An about screen or a bundled licenses file both work.

The duties named in UPL-1.0

The license text itself is short. These are the named conditions. They follow the code, including files you vendor into your own repository and transitive packages in the lockfile.

Include copyright

Keep the copyright line with every copy or substantial portion you distribute.

Include license

Keep the license text with every copy or substantial portion you distribute. A web page is not a substitute for notices inside a shipped artifact.

Things to be aware of

  • Reading UPL-1.0 as no obligations at all and shipping a binary with no notices in it. Put the notices in the artifact you hand over.
  • Deleting the license header when you copy one or two files into your own repository. The condition follows the code, not the package it came in.

What the Universal Permissive License v1.0 does not do

Search results often flatten Universal Permissive License v1.0 into a slogan. These are the usual misreads. UPL-1.0 is a grant with conditions, not a permission to skip the paperwork below.

  • UPL-1.0 does not mean no obligations. The copyright line and the license text still have to travel with copies you distribute.
  • UPL-1.0 does not force you to open your own source. There is no copyleft here unless a later clause in this text says otherwise.

How UPL-1.0 differs from nearby licenses

These licenses are often confused with UPL-1.0, but their release duties differ. Each row summarizes what the license requires when you ship. Open the linked page for the full checklist.

UPL-1.0
UPL-1.0 is Oracle's short permissive grant with an express patent license. Notice stays. Intended as a simpler Apache-2.0 for some Oracle drops.
Apache-2.0
Permissive like MIT, plus an express patent grant. The catch is the NOTICE file: it has to travel inside the binaries you ship.
MIT
MIT lets you ship the code inside a closed, paid product. The one condition is that the copyright line and license text travel with every copy.
BlueOak-1.0.0
BlueOak-1.0.0 is a modern permissive grant in plain English with an express patent license. Keep the notice. OSI-approved.

Common questions about Universal Permissive License v1.0

Answers to common questions about what Universal Permissive License v1.0 requires, when its duties apply, and what evidence belongs with a release.

What is the Universal Permissive License v1.0?

The Universal Permissive License 1.0 lets you use, change and ship the software, including commercially, with an express patent grant from contributors. Keep the copyright and permission notice. There is no Apache NOTICE file dance. Oracle used it on some Java and cloud samples. Buyers who want Apache-2.0's extra patent-termination language should still read the UPL text.

What does UPL-1.0 require when you ship a product?

You meet the notice condition when each UPL-1.0 component's copyright line and license text appear in the material the recipient actually gets. You are done for a hosted service that never hands out a copy. Running the software for users over a network does not, by itself, trigger a notice duty. You are covered for a desktop, mobile or on-premise build when the notices sit inside the artifact. An about screen or a bundled licenses file both work.

Does UPL-1.0 require me to open my own source?

UPL-1.0 does not force you to open your own source. There is no copyleft here unless a later clause in this text says otherwise.

How do I attribute UPL-1.0 in a product I ship?

Attribution for UPL-1.0 means the copyright line and the license text travel with every copy a recipient actually gets. That can be an about screen, a licenses file inside the installer, or a notice in the container image. A public page helps a buyer audit the inventory. It does not replace notices inside the artifact. If you copied files into your own repository, the header on those files still has to stay.

Is a website notice enough for UPL-1.0?

No. UPL-1.0 talks about copies. A public attestation page is the honest list for procurement. The condition is met when the notices sit in the material you hand over. Put them in the installer, the about screen, or a licenses file inside the binary, then keep the same texts on the page.

Do transitive UPL-1.0 dependencies count?

Yes. The condition follows the code, not the package you chose by name. If the lockfile pulled in UPL-1.0 transitively and you distribute that tree, those notices travel too. Listing only direct dependencies is how teams miss the duty.

How is UPL-1.0 different from Apache License 2.0?

UPL-1.0 asks this: UPL-1.0 is Oracle's short permissive grant with an express patent license. Notice stays. Intended as a simpler Apache-2.0 for some Oracle drops. Apache License 2.0 asks this: Permissive like MIT, plus an express patent grant. The catch is the NOTICE file: it has to travel inside the binaries you ship. Open the Apache License 2.0 page for what that license requires when you ship. Do not treat the SPDX ids as interchangeable because the short names look similar.

Where do I record UPL-1.0 for a buyer?

UPL-1.0 is a notice license in the catalog, so a component under it needs license text attached before it counts as live on your published page. SourceTrust fetches the published artifact, extracts the license file, and compares that text against the declared SPDX id. A match fills the text in. Every other outcome waits for a person. The stored text is what your page and each export file carry.

Where do I record UPL-1.0 for a buyer?

UPL-1.0 is a notice license in the catalog, so a component under it needs license text attached before it counts as live on your published page. SourceTrust fetches the published artifact, extracts the license file, and compares that text against the declared SPDX id.

A match fills the text in. Every other outcome waits for a person.

The stored text is what your page and each export file carry. Read /docs/auto-fetch-license for how the fetch works.

See also

The hub is the pillar for this cluster. Sibling licenses are the other spokes. Product FAQ links explain how SourceTrust records the duty, not the license text itself.

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Ship the proof.

Import Universal Permissive License v1.0 and the rest of what you ship. Free to import and review. You only pay when you publish.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.