Published July 12, 2026 · Added September 28, 2026

Rotalabs relicenses twelve libraries from AGPL-3.0 to Apache-2.0

Rotalabs relicensed all twelve of its libraries from AGPL-3.0 to Apache-2.0 on PyPI and npm, saying the strong copyleft mostly kept the right users out because many companies ban AGPL dependencies outright and the protection AGPL buys only pays off when someone might resell a product as a hosted service, which does not fit research tools meant to be imported into someone else's stack. The lab notes Apache-2.0 still requires attribution through a NOTICE file and adds an explicit patent grant that MIT lacks, keeps its product-shaped Red Queen red-teaming engine under AGPL-3.0 with a new explicit commercial option, and says older releases stay AGPL because relicensing cannot be retroactive.

Rotalabs relicensed all twelve of its libraries from AGPL-3.0 to Apache-2.0 on PyPI and npm, saying the strong copyleft mostly kept the right users out because many companies ban AGPL dependencies outright and the protection AGPL buys only pays off when someone might resell a product as a hosted service, which does not fit research tools meant to be imported into someone else’s stack. The lab notes Apache-2.0 still requires attribution through a NOTICE file and adds an explicit patent grant that MIT lacks, keeps its product-shaped Red Queen red-teaming engine under AGPL-3.0 with a new explicit commercial option, and says older releases stay AGPL because relicensing cannot be retroactive.

Read the original story.

Source: Rotalabs