Skip to main content

Guides

How to ensure license compliance, step by step

Inventory what you ship, review licenses, publish proof, and catch drift before the next release. Practical guides for teams that need a defensible record under deadline.

Last updated: July 2, 2026

Common questions

Where should I start?

If a buyer asked for a URL today, start with the compliance page checklist. If you are building the process, start with the review third-party inventory guide.

Can I send a PDF instead of a URL?

If procurement asks for a PDF, send one, generated from your current reviewed publish, with the release or date it reflects. The problem is not PDF vs URL; it is sending a static snapshot and treating it as current while your team keeps merging dependency updates.

Does SourceTrust replace our SBOM tool?

No. Import from FOSSA, Snyk, Syft, or lockfiles. SourceTrust is the reviewed disclosure record you share externally.

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Next step

When you are ready to move from reading to action:

Run a free surface scan

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.