Skip to main content

THIRD-PARTY LICENSE COMPLIANCE

Your licenses.
Ready to share.

Turn your dependencies into a reviewed license page. Send it to your next customer. Keep it current as you ship.

Free to import and review. No credit card needed.

Code and dependency cards converge into one reviewed license summary with a sharing control.
Starts with what you already use
GitHubGitLabAzure DevOpsLockfiles & SBOMs

A LIVING RECORD OF WHAT YOU SHIP

Every dependency has a story.
Keep the whole paper trail.

Know what’s in your product, what needs a decision, and what you can share.

An overhead dependency map connects raised software modules, with a hidden indirect dependency highlighted in green.

SEE THE WHOLE SET

The packages behind your packages.

The dependencies you picked are only the beginning. Bring direct and transitive packages into the same review.

Explore your inventory
A code file connects two shallow comparison cards labelled MIT and GPL-3.0 to a review decision.

LOOK INSIDE

Evidence beneath the label.

Open the actual package. Read its license text. Make the mismatch visible before someone else asks.

See how verification works
A fan of URL, PDF and code export cards connects to the same reviewed source.

SHARE THE ANSWER

One review. Every way to share it.

A link for procurement. A PDF for counsel. Attribution files for your release. All from the same reviewed record.

Explore the outputs
Three successive software snapshots connected by a green thread, with one changed component raised out of the middle snapshot for review.

KEEP THE THREAD

The next commit is part of the story.

Changes keep coming. Catch dependency drift and review what changed before publishing the next revision.

See repository sync

FROM YOUR REPO TO THEIR INBOX

A clear process.
A record you can stand behind.

Start with the files you already have.
Finish with an answer you can send.

Repository, lockfile and SBOM inputs flow into license-evidence review and human approval, then into a published license page with sharing and export options.
  1. 01

    Import what you ship.

    Connect your repository or bring a lockfile or SBOM. Gather direct and transitive dependencies in one inventory.

  2. 02

    Review what matters.

    Inspect the evidence, approve straightforward licenses in bulk, and resolve the packages that need a decision.

  3. 03

    Publish your answer.

    Share a branded license page or download your files. Nothing publishes before your team’s review.

LOOK PAST THE LABEL

The evidence is
inside the package.

A registry entry is a starting point. SourceTrust retrieves the package you actually ship, checks its integrity, and reads the license inside.

01

The exact artifact. Checked against the registry’s digest.

02

The license text. Kept alongside the review.

03

Your team’s decision. Recorded with the published revision.

See how verification works
The LICENSE file inside a package archive connects to its extracted license text, with package integrity checked separately.
The label is a claim.The contents are evidence.

THE PRODUCT, END TO END

From first import to a shareable record.

See the review, publication, public page and readership record in one continuous flow.

05 / 06Static preview

  1. Import
  2. Verify
  3. Review
  4. Publish
  5. Share
  6. Measure

PRICING THAT GIVES BACK

Simple pricing.
Free for open source.

Start with the product you ship.
Bring your whole team.

YOUR PRODUCT. YOUR WHOLE TEAM.

Product plan

$29per product
per month

Billed monthly. No fees per user.

Everything for a reviewed record that stays current.

  • A branded, hosted license page
  • Every export format
  • Repository sync and drift checks
  • Unlimited team members
Start for free

Import and review for free. Billing starts on first publish or export download.

FOR THE BUILDERS WHO SHARE

Open source

Free publishing
$0for your public
GitHub project

No credit card. No trial clock.

You share the code.
We’ll host the license page.

  • Connect a public repo through our GitHub App
  • Publish its license page for free
  • Give readers a link back to your repository
Publish your project for free

For eligible public GitHub projects. Fair use applies. Free pages include SourceTrust attribution.

LIVE WALKTHROUGH

Let’s walk through it.

See how import, review and publishing fit your workflow.

A guided product walkthrough with a highlighted review row and two participants.Request a live walkthrough

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.