Skip to main content

Learn

The plain-language guide to third-party license compliance

What open-source licenses actually require, how the rules show up in real products, and how to produce a record you can defend. Written for people answering diligence under deadline, not lawyers.

Start here

“Open source” is not permission to ship. It's a contract.

Every library, font, icon, and SDK you bundle comes with conditions: Notice, attribution, sometimes copyleft. They're standardized, public, and enforceable, often without anyone on the team having read them. Here are the three assumptions that cost teams the most.

“It's open source, we can ship it.”

Permissive licenses still require copyright and license notices in distributions. Copyleft can require source offers. Never a footnote on a wiki.

“We're SaaS, licenses don't apply.”

Some obligations are lighter for network-only use; many aren't. Fonts, installers, and bundled assets still carry duties, and buyers still ask.

“npm update is just a patch.”

A version bump can change the effective license or add copyleft. Routine updates are the most common way compliance breaks unnoticed.

Reading up because someone asked for proof?

Skip the fire drill. Import your inventory and see where you stand, free, in minutes.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.