Do I have to worry about copyright issues for code posted on Stack Overflow?
meta.stackexchange.com
meta.stackexchange.com
The person posting the code to SO as an answer may not own the copyright to the code they're sharing, despite the SO TOS requiring them to. So even a link to SO isn't a total solution if lawyers are getting involved.
All in all in CAN be a shitshow, in practice it mostly works out.
This also is largely ignoring what fair use means in different jurisdictions, let alone what licenses work where. Many tech companies operate globally from day one, so all sorts of issues can come up. In reality, ignore almost all of them and solve them if you ever actually start making money.
Blatant infringement is typically punished worse by judges / legislation.
You still can be fined, have injunctions bought against products etc without it being wilful.
There have been a bunch of song examples of this, where someone alleges a small riff is taken unknowingly or not from another song, and the songwriter losing all royalties to the song.
Ever since https://en.wikipedia.org/wiki/SCO_Group,_Inc._v._Internation.... Eclipse Foundation required what they call "Type B" IP scan for all projects (Eclipse F. is not just an IDE but a competitor to the Apache F.), essentially a deep scan of the code searching for any bits of GPL (our Eclipse project had a dojox dependency flagged because its MIT-licensed code contained a small snippet of GPL, that was the only time we got a rejection of a library). In late 2019, the change was made to make "Type A", a deep scan of the licenses only, to be the default (https://blogs.eclipse.org/post/wayne-beaton/updates-eclipse-...).
To me it signals that the common sense in the enterprise community now is that there is not much risk in that scenario, worst case would be that the original IP holder can force you to remove their code if they convince the court the developer had no right to publish it as opposed to getting crazy amounts awarded. I think it is also judged that the likelihood and the amount of trouble are relatively small compared to full code scan of all deps transitively at all times (incl lost productivity).
No it's not. The example in the SO answer is that the SO snippet is copied both into your software and a GPL'd open-source project.
Although it must be said that the scenario whereby someone posts a code snippet for which they do not own the copyright, perhaps indeed because they copy-pasted it from an OSS project, is an obvious one and less sneaky than the example.
They have no ownership over the copyright to give.
This is not legal advice, just sharing our story.
As parent said, this is not legal advice -- ask someone qualified to answer.
If the code is used verbatim, it must be released under the same version of the CC-BY-SA licence (unless permitted by the copyright holder), but adapting it would let you put the new work under a later version.[3] But there is also a jurisdiction-dependent question of what constitutes an adaptation, and how much of the larger codebase could be considered an adaptation of the CC'd work (and would therefore be covered by the same licence).[4]
1. https://meta.stackexchange.com/questions/74867/should-stack-...
2. https://meta.stackexchange.com/questions/333089/stack-exchan...
3. https://opensource.stackexchange.com/questions/7430/can-i-up...
4. https://wiki.creativecommons.org/index.php?title=ShareAlike_...
Now, content posted before the 2018 license change is licensed under CC-BY-SA 3.0, whereas content posted after is licensed under 4.0. You can see the licensing history for a post by clicking the “timeline” icon under the voting arrows.
That’s the idea...the linked post is a part of Stack Exchange’s FAQ library. Perhaps a better title could provide a slightly more useful summary of the content, but HN guidelines discourage editorializing submission titles.
By submitting the code to StackOverflow, you are exercising a right of ownership. According to their terms, you give them irrevocable rights to publish and license the code onwards, etc.
> A Short Story To Illustrate:
> Someone else decides the code is a good solution for a problem they are facing, and decides to copy it into their open source GnuFizzBuzz project, covered by the GPL. Five years from now, someone is doing an open source audit on your code (maybe you are selling to a nervous customer, or your company is going public).
> The open source audit finds the snippet of code you got from Stack Overflow, and recognizes it as originating in GnuFizzBuzz.
> You are now stuck explaining how/why you have GPL code mixed into your commercial product, or proving that the code was actually from Stack Overflow. Can you prove that the person posting the code to Stack Overflow owned it to begin with (maybe they actually copied it from GnuFizzBuzz to begin wih).
I can circumvent this system by taking the snippet I need or just wholesale copying the library and changing around a few variables.