Guides
How to ensure license compliance, step by step
Inventory what you ship, review licenses, publish proof, and catch drift before the next release. Practical guides for teams that need a defensible record under deadline.
Last updated: July 2, 2026
Pick the task in front of you
Each guide walks one deliverable end to end, with the checks reviewers actually run.
- License compliance checklistWhat to verify before you share a compliance URL or export externally.Open checklist
- Procurement license requestWhen a buyer asks for license disclosure, and why snapshots go stale as dependencies change.Read procurement guide
- Review third-party inventoryA practical review workflow from import to approved publish.See review workflow
- SBOM to compliance pageTurn existing lockfiles or CycloneDX inputs into a reviewed disclosure record.Read SBOM guide
- License compliance for M&AWhat diligence counsel asks for, red flags, and how to assemble a proof pack.Read M&A guide
Common questions
Where should I start?
If a buyer asked for a URL today, start with the compliance page checklist. If you are building the process, start with the review third-party inventory guide.
Can I send a PDF instead of a URL?
If procurement asks for a PDF, send one, generated from your current reviewed publish, with the release or date it reflects. The problem is not PDF vs URL; it is sending a static snapshot and treating it as current while your team keeps merging dependency updates.
Does SourceTrust replace our SBOM tool?
No. Import from FOSSA, Snyk, Syft, or lockfiles. SourceTrust is the reviewed disclosure record you share externally.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.