# Do i need to bundle licenses of my project's dependencies even if my project is open source

**URL:** <https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800>\
**Category:** help\
**Created:** [October 2, 2026, 6:26pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800 "2026-10-02T18:26:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Monochrotec](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/monochrotec/32/54131_2.png) [@Monochrotec](https://users.rust-lang.org/u/Monochrotec)\
**Post date:** [October 2, 2026, 6:26pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/1 "2026-10-02T18:26:24Z")

</div>

hello my project has quite a lot of dependencies. about 500 of them. I looked for a few  
posts but they old. I was wondering if I'm publishing both the source code and the binary.  
do i still need to have to bundle all of their licenses(I know licenses vary from one another. I'm mostly talking about mit, apache and similar permisive licenses). if i have to bundle them. do i have to contain a full copy or is an spdx identifier or a link to the project enough.  
the project will be AGPLv3 licensed but i doubt its affect on bundling licenses. I'm still mentioning it just in case.

---

<div class="post-metadata">

**Author:** ![MOCKBA](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/mockba/32/41423_2.png) [@MOCKBA](https://users.rust-lang.org/u/MOCKBA)\
**Post date:** [October 2, 2026, 6:38pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/2 "2026-10-02T18:38:17Z")

</div>

I provide licenses to all OSS I use in my projects. It's easy, and you can ask AI for a full list to save time. However, you may ignore that and more likely nothing will happen, unless your company filed for IPO.

---

<div class="post-metadata">

**Author:** ![Monochrotec](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/monochrotec/32/54131_2.png) [@Monochrotec](https://users.rust-lang.org/u/Monochrotec)\
**Post date:** [October 2, 2026, 6:41pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/3 "2026-10-02T18:41:57Z")

</div>

thanks but I would rather not use ai.

---

<div class="post-metadata">

**Author:** ![branan](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/branan/32/3801_2.png) [@branan](https://users.rust-lang.org/u/branan)\
**Post date:** [October 2, 2026, 6:46pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/4 "2026-10-02T18:46:48Z")

</div>

IANAL, but I have worked with lawyers on open source license compliance in the past.

For most licenses, the "include the license text" clause is about _distribution of the licensed code_. So when you're providing only your source, with an expectation that users download dependencies themselves (by hand or via Cargo), there is no need to include attribution.

As soon as you ship binaries (or vendor the source, but vendoring usually pulls in licenses anyway), the license clauses start to fire. That means you need to include proper attribution for all of your dependencies as specified in their licenses. You'll likely have to include full license text for some dependencies, but it's common practice to deduplicate those licenses (IE, including only one copy of the GPL, one of Apache, and one of MIT, then specifying which dependencies use which license files)

There are tools (such as `cargo-bundle-licenses` and `cargo-about`) that can help generate the appropriate attribution for you based on your Cargo.toml

---

<div class="post-metadata">

**Author:** ![Monochrotec](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/monochrotec/32/54131_2.png) [@Monochrotec](https://users.rust-lang.org/u/Monochrotec)\
**Post date:** [October 2, 2026, 6:49pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/5 "2026-10-02T18:49:39Z")

</div>

thanks. I was exactly wondering about the binary release. as I'm pretty sure the average user either doesn't know what compiling is or they don't want to bother.

---

<div class="post-metadata">

**Author:** ![scottmcm](https://sea1.discourse-cdn.com/flex019/user_avatar/users.rust-lang.org/scottmcm/32/4286_2.png) [@scottmcm](https://users.rust-lang.org/u/scottmcm)\
**Post date:** [October 2, 2026, 8:06pm UTC](https://users.rust-lang.org/t/do-i-need-to-bundle-licenses-of-my-projects-dependencies-even-if-my-project-is-open-source/142800/6 "2026-10-02T20:06:12Z")

</div>

You might be interested in [https://rosenlaw.com/oslbook.htm](https://rosenlaw.com/oslbook.htm): it's getting older, but is freely available and should still be a good introduction to copyright and licenses.

In general, shipping your source code on its own has very different requirements from shipping the aggregate compiled binary.
