Complying with the GNU Lesser General Public License comes down to a handful of concrete obligations that kick in when you distribute software containing an LGPL-covered library: you have to preserve the user’s ability to replace that library with a modified version, ship the library’s source code, include the license texts and notices, and, under version 3, respect an automatic patent grant. The LGPL license requirements are stricter than a permissive license like MIT but narrower than the full GPL, and where developers get into trouble is almost always the linking method they chose or the source materials they failed to provide.
What the License Actually Covers
The LGPL is a “weak copyleft” license. Its conditions attach to the library itself, not to everything the library touches. You can link an LGPL library into a proprietary application, modify the library, and sell the result commercially. Your application keeps whatever license you choose. The library portion, and any changes you make to it, stay under the LGPL.1GNU Project. GNU Lesser General Public License v3.0
Nearly every obligation turns on how the license classifies your code. The “Library” is the LGPL-covered component. An “Application” is a separate work that uses the Library’s interface without being derived from it. A “Combined Work” is the linked or combined product you distribute.1GNU Project. GNU Lesser General Public License v3.0 If your code is a genuinely separate Application that only calls into the Library, the copyleft does not spread into your proprietary source. If your code has become a modified version of the Library, the full copyleft applies to it.
None of this is public domain. The original authors keep their copyright, and the license conditions are enforceable in court.2GNU Project. GNU Lesser General Public License v2.1
Linking Method Decides What You Owe
Whether you link the library dynamically or statically changes your compliance work more than any other technical decision.
Dynamic linking is the easier path. Your application calls the library at runtime from a separate shared library or DLL file. The library stays a swappable component, so a user can drop in an updated or modified version without help from you. Under LGPL v3, using a suitable shared library mechanism that loads a compatible library version at runtime satisfies the relinking requirement on its own.1GNU Project. GNU Lesser General Public License v3.0
Static linking merges the library’s compiled code into your binary. The user can no longer swap the library on their own. To preserve that ability, you have to provide enough material for a skilled user to relink your application against a modified library. That usually means shipping the object files or source code for your application together with the library source, so the whole thing can be recompiled with a patched library.1GNU Project. GNU Lesser General Public License v3.0 If you statically link and distribute only a finished binary, you are almost certainly out of compliance.
What You Must Ship With the Combined Work
The obligations activate when you “convey” the Combined Work to someone else. Internal use inside your organization does not trigger them. Once you distribute, you owe recipients the following:
- A prominent notice with each copy stating that the work uses an LGPL-licensed library and that the library’s use is governed by the LGPL.1GNU Project. GNU Lesser General Public License v3.0
- Copies of both the LGPL and the GNU General Public License, because the LGPL operates as a set of additional permissions on top of the GPL.3GNU Operating System. GNU Lesser General Public License Version 3
- Complete source code for the library portion. Any modifications you made to the library must be released under the LGPL, or at your option, under the full GPL.1GNU Project. GNU Lesser General Public License v3.0
- A way for recipients to swap in a modified library. Dynamic linking with a shared library mechanism satisfies this; otherwise, you provide the application’s object code so users can relink it.1GNU Project. GNU Lesser General Public License v3.0
- If your Combined Work displays copyright notices during execution (an “About” screen, a splash, a startup banner), the library’s copyright notice belongs among them, together with a reference pointing users to the GPL and LGPL texts.1GNU Project. GNU Lesser General Public License v3.0
For delivering source code, the GPL v3 (which the LGPL incorporates) accepts several methods: bundle the source with the binary, provide a written offer valid for at least three years to supply source on request, or host it on a network server with equivalent access.4GNU Project. GNU General Public License, version 3 Most projects host the library source in a public repository and link to it from their documentation.
Consumer Products Have an Extra Requirement
If your Combined Work ships inside a consumer product such as a router, smart TV, or embedded device, LGPL v3 adds an obligation borrowed from the GPL v3’s anti-tivoization provisions. You have to provide “Installation Information” sufficient for the user to install and run a modified version of the Combined Work with a replacement library. The rule prevents manufacturers from locking hardware down so that only unmodified original software will boot.1GNU Project. GNU Lesser General Public License v3.0 The requirement applies only to consumer products, not to software running on general-purpose servers or workstations.
Server-Side and SaaS Use
The LGPL’s obligations are triggered by conveying the software to someone else. Running LGPL code on your own server to power a web application or cloud service is not conveying, because you never hand the software itself to the user. The user talks to your service over the network but never receives a copy of the code.1GNU Project. GNU Lesser General Public License v3.0
A SaaS company can therefore modify an LGPL library, run the modified version in production, and never share the modifications with anyone. The Free Software Foundation created the GNU Affero General Public License (AGPL) specifically to close this gap; the AGPL treats network interaction as a form of distribution that triggers source obligations. If you are only using an LGPL library on the server side, the LGPL by itself imposes no obligation to release source to your users.
Patent Rights Under Version 3
LGPL v3 includes an express patent grant that many developers overlook. Every contributor to the library automatically grants every downstream user a royalty-free, worldwide, non-exclusive patent license covering the contributor’s “essential patent claims,” meaning any patents that would be infringed by using, modifying, or distributing the contributor’s version of the code.5GNU Operating System. GNU Lesser General Public License, version 3 The grant flows to everyone who receives the software, not only to the person you handed it to directly.
The license also blocks a specific patent workaround: you cannot distribute the software under an arrangement where a third party provides patent licenses only to some recipients. A patent license that discriminates by excluding rights the LGPL grants puts you in violation.5GNU Operating System. GNU Lesser General Public License, version 3 Version 2.1 has no comparable patent provisions, which is one practical reason to prefer v3 for new projects.
What Happens If You Don’t Comply
The LGPL is a copyright license. Distributing code outside its terms is copyright infringement, with consequences in two categories: losing your license rights, and potential monetary damages.
Automatic Termination and the 30-Day Cure
A violation terminates your rights under the license automatically. Version 3 includes a forgiveness mechanism that matters in practice. If this is your first violation from a particular copyright holder, and the holder notifies you of the problem, your rights are permanently reinstated as long as you fix the violation within 30 days of receiving that notice.4GNU Project. GNU General Public License, version 3 Ignore the notice, or repeat the same violation, and the protection is gone.
Damages If It Reaches Court
If a dispute becomes litigation, the copyright holder can seek the usual remedies under U.S. copyright law: an injunction stopping distribution of the infringing software, actual damages and profits, or statutory damages. Statutory damages for a single work range from $750 to $30,000 at the court’s discretion, and for willful infringement the ceiling rises to $150,000.6Office of the Law Revision Counsel. 17 USC 504 – Remedies for Infringement: Damages and Profits There is a catch. Statutory damages and attorney’s fees are only available if the copyright holder registered the work with the U.S. Copyright Office before the infringement began, or within three months of first publication.7Office of the Law Revision Counsel. 17 USC 412 – Registration as Prerequisite to Certain Remedies for Infringement Many open-source libraries are never registered, so the holder is limited to proving actual damages. An injunction halting distribution of your product, however, can be more damaging than any dollar figure.
Version 2.1 vs. Version 3
Before pulling in an LGPL library, check the license header. Code marked “version 2.1 or later” can be upgraded to LGPL v3 and combined with v3-compatible code. Code marked “version 2.1 only” cannot be upgraded, which means it cannot be combined with anything requiring GPL v3 terms.8Free Software Foundation. Frequently Asked Questions about the GNU Licenses LGPL v3 is defined as the GPL v3 plus additional permissions, so LGPL v3 code can always be relicensed under GPL v3 by dropping the extra permissions. Apache 2.0 code, which conflicted with GPL v2 on patent language, works cleanly with GPL v3 and therefore with LGPL v3.9GNU Operating System. License Compatibility and Relicensing
Releasing Your Own Library Under the LGPL
If you are the author applying the LGPL rather than a consumer complying with it, the mechanics are short. Place the plain-text GPL in a file named COPYING and the plain-text LGPL in a file named COPYING.LESSER, both in the project root. You need both files because the LGPL sits on top of the GPL.10GNU Project. How to Use GNU Licenses for Your Own Software Add a copyright notice and license header to the top of every source file, using the template the FSF publishes, and include the phrase “either version 3 of the License, or (at your option) any later version” unless you have a specific reason to lock the code to a single version. The FSF recommends the “or any later version” language because it prevents future compatibility dead ends.8Free Software Foundation. Frequently Asked Questions about the GNU Licenses Do not edit the license texts themselves, even to fix a typo; any change creates ambiguity about which license actually applies. The last file to check before release is any source file created late in development, since those are the ones most likely to ship without a header.