skip to content

OWASP ZAP is Apache-2.0 with no paid tier — what does that settle in a tool choice, and what does it not?

level: middleimportance: should knowfreq 50%

answer

  1. free is not the interesting half
  2. fit, not price
  3. the download is a bundle
  4. the forked files kept their own licence
  5. core can write its own SBOMs

basics

~20 s

Apache-2.0 with no paid tier settles price and access: nothing to buy, no seat to provision per CI runner, the same build everywhere. It does not settle legal review, because the shipped package bundles code under several other licences.

solid answer

~40 s

Both main repositories carry an `Apache-2.0` `LICENSE`, and the add-ons a distribution pulls are public release downloads pinned by hash in the core repository — so there is no seat to provision per runner and no entitlement service a build agent has to reach. That takes price out of the comparison and leaves fit. It does not take out an open-source review: the project's own `LEGALNOTICE.md` records that it is a fork of Paros Proxy, whose inherited files carry the Clarified Artistic License, and the distribution ships that text in a `license/` directory beside the GPL and LGPL texts bundled libraries require. Core's `-sbomzip` option writes the available SBOMs into a zip, which is usually the artefact that review wants. `Apache-2.0` is the project's licence, not the whole package's.

code

yaml · 3 lines
yaml
# from the project's own image release workflow
labels: |
  org.opencontainers.image.licenses=Apache-2.0

go deeper

for a junior

Recall that it is released under Apache-2.0, a permissive licence, and that there is no paid edition to compare against. Knowing you may use it commercially without publishing your own code is the part that gets checked.

for a middle

Explain what the licence does and does not cover: the project's own code, versus the files inherited from the fork it came from, versus third-party libraries whose texts ship in the distribution's licence directory.

for a senior

Show that you would run the review rather than assert the outcome. Point at the legal notice, the shipped licence texts and the -sbomzip option, and say what you would hand to whoever signs it off.

for a principal

Own the reframing: with price removed, the decision is fit and total cost of ownership. Be explicit about what replaces the support contract — whose time, on what budget, and what the escalation path is when nobody is obliged to answer.

## The licence, measured rather than remembered Both of the project's main repositories — the core program and the add-on repository — carry an `Apache-2.0` `LICENSE` file, and the project stamps that same identifier on the container images it publishes, as an `org.opencontainers.image.licenses` label in its own release workflow. The core repository's `LEGALNOTICE.md` says it in one line: the open source software licence of the program is `Apache-2.0`. Apache-2.0 is a **permissive** licence. You may run it, modify it, and redistribute it — including inside something you sell — as long as you keep the notices and the attribution. It carries no obligation to publish your own code, which is the single most common thing candidates get wrong about it. There is no per-seat purchase, no entitlement service, and no separately licensed edition sitting behind the build you downloaded. ## What that settles For an unattended pipeline the consequences are concrete, and they are the reason this question gets asked at all: - **Provisioning.** Nothing has to be bought or allocated before a build agent may run it, so the number of parallel runners is a capacity decision rather than a procurement one. - **Reproducibility.** The build a developer runs on a laptop is the build the pipeline runs; there is no "desktop edition" whose behaviour diverges from the automated one. - **Egress.** Core ships a `-silent` option — also settable through a `ZAP_SILENT` environment variable, which is what you want inside a container — that stops the program making any unsolicited request, the check for updates included. A runner with locked-down outbound access is a supported configuration, not a workaround. - **Escalation.** When something misbehaves, the source is available and is your escalation path. That is a real option, and it is also a bill: your engineers' time instead of a support contract. So the licence takes **price** out of the comparison and leaves **fit**. That reframing is the answer an interviewer is listening for. ## What it does not settle: the download is a bundle The most useful thing to know here is that a top-level `LICENSE` does not describe every file that ships. `LEGALNOTICE.md` keeps a third-party section, and it records **two separate things** that are very easy to merge into one and should not be: 1. The program is a **fork of Paros Proxy**, developed by another company and licensed under the **Clarified Artistic License**. Files inherited from that fork still carry that header today — they are the classes under the `org.parosproxy.paros` packages, which is not a museum corner: the active-scan engine, the network types, the database record classes and the command-line class all live there. 2. **Separately**, files that had been imported under the GPL were later relicensed under `Apache-2.0` with their authors' permission. That is a different set of files and a different event, and conflating it with the fork is the mistake to avoid. On top of both, the distribution ships a `license/` directory holding the Apache text alongside the Clarified Artistic text and the GPL and LGPL texts that bundled libraries require — and `LEGALNOTICE.md` tabulates each bundled library against its licence. | what you are being asked | where the answer actually is | what that source does not cover | |---|---|---| | the project's own licence | `LICENSE` in both main repositories, and `LEGALNOTICE.md` | the files inherited from the fork | | the inherited files' licence | the Clarified Artistic License header on the `org.parosproxy.paros` classes | third-party libraries | | bundled libraries | the table in `LEGALNOTICE.md` and the texts in the distribution's `license/` directory | add-ons you install afterwards | None of this makes the tool hard to adopt. It makes "it is Apache, we are fine" an incomplete sentence, and an open-source review that has been handed that sentence will come back. ## The artefact a review will ask for Core registers a `-sbomzip <path>` command-line option whose own help text reads *"Creates a zip file containing all of the available SBOMs"*. It is worth knowing simply because it turns a manual inventory exercise into one invocation: you run the program once with that option and hand the result to whoever owns the review. Knowing the option exists is a better answer than promising to compile a list by hand. ## How to say this in an interview Lead with the reframing, not the licence name. *"It is `Apache-2.0` with no paid tier, so the choice is not about price — it is about whether the shape of the tool matches how we intend to run it."* Then show that you know the licence question has a second half: the project's own licence is not the whole package's, the fork it came from carries a different one, and the distribution ships those texts because it has to. A candidate who stops at "it's free" has answered the easy half of the question.

  • Where would you look to find out what the distribution actually bundles?
    `LEGALNOTICE.md` in the core repository names the fork the program came from and tabulates each bundled library against its licence, and the distribution ships the licence texts themselves in a `license/` directory. For a machine-readable answer, core's `-sbomzip` option writes the available SBOMs into a zip you can hand straight to review.
  • If there is no licence to buy, is adoption free?
    No — the cost moved rather than vanished. You maintain whatever drives it, you carry your own escalation path when something breaks, and you own the upgrade risk when an add-on's programmatic surface changes. That is a real budget line; it is just an engineering one instead of a procurement one.

saying these in an interview costs you the question

  • It is free, so there is nothing for legal to review
  • Apache-2.0 covers every file inside the download
  • Using it obliges you to open-source your own code
  • The free build is a cut-down version of a paid product
  • No vendor means it cannot be used in a serious pipeline