Blog

Protecting Cockroach Labs' Source Code in the Age of AI

Published on September 15, 2026

0 minute read

Protecting Cockroach Labs' Source Code in the Age of AI

Cockroach Labs exists to solve some of the hardest problems in data infrastructure. Our customers rely on us to deliver a database that survives outages, scales globally, and evolves fast enough to meet requirements that change in unpredictable ways. That mission drives every decision we make, including how we manage and distribute our source code. From the beginning, CockroachDB was released as an open-source project. In 2019, we transitioned to the Business Source License, and in 2024, we evolved our licensing model further to consolidate around the CockroachDB Software License. Through each of those changes, we maintained our commitment to keeping CockroachDB's source code publicly available, commonly referred to as "source available." We believed then, and still believe, that transparency in how software is built fosters trust and helps the broader ecosystem.

Why we're making this changeCopy Icon

However, publicly available source code now carries risks that did not exist even two years ago. Security is at the top of that list.

AI has transformed the way code is consumed, analyzed, and reproduced. Large language models can surface implementation details, internal logic, and architectural patterns at a scale and speed that fundamentally changes the security calculus of source availability. Attack surfaces that once required deep manual analysis to find can now be identified rapidly and at scale. Vulnerabilities in publicly visible code can be discovered and exploited faster than fixes can be deployed. We saw this play out firsthand with Mythos: keeping our source publicly available while defending against AI-assisted analysis means fighting with one hand tied behind our backs.

Beyond security, the legal frameworks that have historically protected source code, particularly copyright, are entering genuinely uncertain territory as AI becomes central to how code is written and derived. Publicly available codebases can now be monitored and functionally reproduced at a scale that was not feasible before. These are not theoretical concerns. We are already seeing early real-world examples of AI being used to produce functional reproductions of protected software, and the trend is accelerating.

What is changingCopy Icon

These dynamics have led us to a straightforward decision: going forward, new versions of CockroachDB's source code will no longer be published to our public repository. This also applies to Pebble, our high-performance storage engine, which will similarly move to private development.

To be clear: our license terms are not changing. CockroachDB continues to be licensed under the CockroachDB Software License. What is changing is that new releases will no longer have their source code publicly visible.

The existing open-source repository is not going anywhere, however, we will no longer maintain or update it, but it remains available as-is.

What this means for customersCopy Icon

Our ability to innovate quickly on behalf of the businesses that depend on CockroachDB requires that we protect the intellectual property behind that innovation. As the security and legal protections around publicly available source code erode, continuing to publish our core IP introduces risk to our business and to the customers who rely on us to keep advancing the product.

We know that some customers and community members have relied on our public source code for workflows like understanding CockroachDB internals, filing issues, or referencing implementation details. We have prepared a detailed FAQ that addresses how these workflows will be supported going forward. If you have questions that aren't covered there, please reach out to your account team or our support channels.

Our continued investment in open sourceCopy Icon

We recognize that this decision sits within a broader conversation about the role of open source in an AI-driven world. We want to be direct: we still believe in open source. But we also believe that open source is most effective when applied thoughtfully, and that not every codebase carries the same risk profile. A general-purpose Go library and a proprietary distributed database represent fundamentally different security and IP considerations, and we think it's reasonable to treat them differently.

We continue to actively maintain a number of open-source Go libraries that are widely used beyond CockroachDB, including errors, apd, redact, datadriven, and others. We also contribute upstream to projects we depend on, including Go itself, gRPC, and the Bazel ecosystem.

We will continue to share the ideas and innovations behind CockroachDB through our blog, technical white papers, conference talks, and the many other ways we've always engaged with the community.

We are making this change because we believe it is the right decision for our customers, our business, and the long-term health of the product. Our commitment to our community, our partners, and our customers remains the same. Thank you for the trust you've placed in us and in CockroachDB.

#source code

FAQ

What exactly is changing?

Beginning with new releases, Cockroach Labs will develop CockroachDB and Pebble in private repositories rather than publishing new source code to the existing public repositories. The existing public repositories will remain available as-is but will no longer reflect ongoing development.

Is CockroachDB’s license changing?

No. There is no change to the CockroachDB Software License, pricing, or existing customer rights. The change is to where new versions of CockroachDB are developed and whether that source code is publicly visible.

Why is Cockroach Labs making this change now?

AI has changed how quickly software can be analyzed, understood, and reproduced. Making core development private reduces unnecessary exposure of CockroachDB’s core intellectual property and attack surface while allowing Cockroach Labs to continue investing aggressively in the security and development of the product.

What does this mean for existing CockroachDB customers?

For the overwhelming majority of customers, nothing changes in how they license, deploy, run, upgrade, or receive support for CockroachDB. Customers will continue receiving supported releases, updates, security fixes, and support through the same channels they use today.

How can customers evaluate CockroachDB’s security without access to the source code?

Customers will continue to have access to security and compliance artifacts including SOC 2 reports, SBOMs, third-party penetration testing, vulnerability disclosures, and other materials through the Cockroach Labs Trust Portal. Customers with specific regulatory or compliance requirements should work directly with their Cockroach Labs account team.

What happens to the existing CockroachDB GitHub repository and community contributions?

The existing repository will remain publicly accessible as a historical snapshot, but new CockroachDB development will take place privately. As a result, Cockroach Labs will no longer accept code contributions against the core CockroachDB codebase. The company will continue to provide a path for the community to report bugs and issues.

Is Cockroach Labs moving away from open source?

No. Cockroach Labs will continue maintaining and contributing to open-source projects where an open development model makes sense, including non-core Go libraries and upstream projects the company depends on. The change is specific to the core intellectual property behind CockroachDB and Pebble.

Will Cockroach Labs continue publishing new CockroachDB releases and security updates?

Yes. Cockroach Labs will continue releasing and supporting CockroachDB, including updates, patches, and security fixes. What changes is the public visibility of the underlying source code, not our commitment to maintaining and advancing the product.

Can developers still report bugs and security vulnerabilities?

Yes. Developers and customers will continue to have channels for reporting bugs and security vulnerabilities. While we will no longer accept external code contributions to the core CockroachDB codebase, community feedback and responsible vulnerability reporting remain important.

Does this change how CockroachDB is deployed?

No. This change does not affect how customers deploy CockroachDB or the deployment options available to them. It changes where CockroachDB is developed, not where customers can run it.

© 2026 Cockroach Labs. All rights reserved.
Privacy
Security