Licence landmines in a .NET microservices stack
MassTransit, MediatR, AutoMapper, Duende and Redis: what changed, and the rule I now follow before adding any dependency.
The default .NET microservices stack of a few years ago (MediatR for CQRS, AutoMapper for mapping, IdentityServer for auth, MassTransit for messaging, Redis for caching) is no longer a free stack. Each of these has moved some or all of its usage to commercial terms. None of that is wrong; maintainers need to get paid. But a team that adds these packages from memory can ship a licence liability without anyone deciding to.
The ones I've hit
| Package | What changed | What I use instead |
|---|---|---|
| MassTransit | v9 is commercially licensed; v8 stays Apache-2.0 | Pin MassTransit 8.x and plan the decision before upgrading |
| MediatR | Moved to a commercial licence | A small in-house dispatcher (post) |
| AutoMapper | Moved to a commercial licence | Hand-written mapping |
| Duende IdentityServer | Commercial licence for most production use | OpenIddict (Apache-2.0), self-hosted |
| Redis | Left BSD for source-available licences | Valkey (BSD-3) or Microsoft Garnet (MIT) |
Check each project's current terms yourself. These change, which is exactly the point of this post.
How I found out about MassTransit
Not from a changelog. The containers crash-looped on startup: the bus threw a configuration exception asking for a licence. A package that had been "free" in every tutorial was now the reason the whole system wouldn't boot.
The rule
- State the licence of every new dependency in the pull request that adds it.
- Verify licences when you choose a package, not from memory. What you remember is the licence it had when you last used it.
- Pin major versions of anything with a history of licence changes, and treat a major upgrade as a decision, not a chore.
- Record it in an ADR so the next engineer knows why
MassTransitis pinned and why there's noMediatR.
Most of these replacements turned out to be small. The dispatcher is about 80 lines, and hand-written mapping is more verbose but easier to debug. Avoiding a surprise licence bill and a 2 a.m. crash loop is worth that cost.