Third-party license disclosure fails when inventory is imported once and never reviewed. You need to match each component to an identified license, attach full license text, and block publish until a human approves what the compliance page will represent.
This workflow applies whether you start from npm lockfiles, CycloneDX SBOMs, FOSSA or Snyk exports, or manual spreadsheets. The steps are the same: Import, review per component, publish with gates, maintain on every release.
Import from shipped inputs
Lockfiles, SBOMs, or tool exports from the release branch. Every row starts unreviewed.
Review each component
Confirm the license, attach full text, escalate copyleft and conflicts.
Publish with gates
No unreviewed rows, stable URL, exports from the same snapshot.
Maintain on every release
Drift checks flag changes; re-review and re-publish before buyers notice.