Learn
The plain-language guide to third-party license compliance
What open-source licenses actually require, how the rules show up in real products, and how to produce a record you can defend. Written for people answering diligence under deadline, not lawyers.
Start here
“Open source” is not permission to ship. It's a contract.
Every library, font, icon, and SDK you bundle comes with conditions: Notice, attribution, sometimes copyleft. They're standardized, public, and enforceable, often without anyone on the team having read them. Here are the three assumptions that cost teams the most.
“It's open source, we can ship it.”
Permissive licenses still require copyright and license notices in distributions. Copyleft can require source offers. Never a footnote on a wiki.
“We're SaaS, licenses don't apply.”
Some obligations are lighter for network-only use; many aren't. Fonts, installers, and bundled assets still carry duties, and buyers still ask.
“npm update is just a patch.”
A version bump can change the effective license or add copyleft. Routine updates are the most common way compliance breaks unnoticed.
01What the rules are, and where they apply
All license compliance topicsFundamentals
- What actually accumulates in a productHundreds of packages, fonts, icons, and SDKs, and the triggers that force teams to finally look.
- Notice, attribution & full textThree different duties reviewers check, and the most common gap on compliance pages.
- Copyleft, without the legal lectureWhat GPL, LGPL, and AGPL actually require you to operationalize before you ship.
- Who owns the obligationEngineering, legal, and product, and when license duties apply to your organization.
- Where obligations show upWebsites, mobile apps, desktop installers, and embedded products each carry different duties.
- What it costs the businessDeal delays, audit surprises, and false confidence when nobody owns what ships.
- Legal outcomes in practiceInjunctions, damages, and forced disclosure from real license enforcement cases.
- The compliance page, explainedWhat a buyer-facing license page must contain, and why a spreadsheet does not count.
02Where compliance programs stop short
All regulatory topicsRegulatory & SBOM
- Does SOC 2 or ISO 27001 cover this?No. Here is the exact gap between a security certificate and license disclosure.
- The EU Cyber Resilience ActWhat CRA documentation requires vs. the license page diligence still expects.
- SBOM vs. a license pageWhy a machine-readable component list is not the same as reviewed disclosure.
- License questions in questionnairesHow to answer from a reviewed, product-scoped inventory, without overclaiming.
03Step-by-step, when you're under deadline
All guidesGuides
- License compliance checklistWhat to verify on inventory, text, and attribution before you share a URL.
- What procurement actually asks forContinuous proof, why exports go stale, and how to respond when dependencies move faster than paperwork.
- Review an inventory before publishA practical sequence from import to approved publish, without skipping gates.
- From SBOM to a compliance pageTurn CycloneDX or lockfiles you already generate into a reviewed record.
- License compliance for M&ADiligence-ready proof: attestation page, SPDX, CycloneDX, and PDF from one snapshot.
Reading up because someone asked for proof?
Skip the fire drill. Import your inventory and see where you stand, free, in minutes.