Understand your license obligations.
Clear answers on licenses, evidence and the record you need to ship.
What the rules are, and where they apply
All license compliance topics- What actually accumulates in a productHundreds of packages, fonts, icons, and SDKs, and the triggers that force teams to finally look.Read
- Notice, attribution & full textThree different duties reviewers check, and the most common gap on compliance pages.Read
- Copyleft, without the legal lectureWhat GPL, LGPL, and AGPL actually require you to operationalize before you ship.Read
- Who owns the obligationEngineering, legal, and product, and when license duties apply to your organization.Read
- Where obligations show upWebsites, mobile apps, desktop installers, and embedded products each carry different duties.Read
- What it costs the businessDeal delays, audit surprises, and false confidence when nobody owns what ships.Read
- Legal outcomes in practiceInjunctions, damages, and forced disclosure from real license enforcement cases.Read
- The compliance page, explainedWhat a buyer-facing license page must contain, and why a spreadsheet does not count.Read
Where compliance programs stop short
All regulatory topics- Does SOC 2 or ISO 27001 cover this?No. Here is the exact gap between a security certificate and license disclosure.Read
- The EU Cyber Resilience ActWhat CRA documentation requires vs. the license page diligence still expects.Read
- SBOM vs. a license pageWhy a machine-readable component list is not the same as reviewed disclosure.Read
- License questions in questionnairesHow to answer from a reviewed, product-scoped inventory, without overclaiming.Read
Step-by-step, when you're under deadline
All guides- License compliance checklistWhat to verify on inventory, text, and attribution before you share a URL.Read
- What procurement actually asks forContinuous proof, why exports go stale, and how to respond when dependencies move faster than paperwork.Read
- Review an inventory before publishA practical sequence from import to approved publish, without skipping gates.Read
- From SBOM to a compliance pageTurn CycloneDX or lockfiles you already generate into a reviewed record.Read
- License compliance for M&ADiligence-ready proof: attestation page, SPDX, CycloneDX, and PDF from one snapshot.Read
What each license actually asks for
All license guides- MITThe short permissive grant. Notice travels with every copy.Read
- Apache-2.0Permissive with an explicit patent grant and a notice file.Read
- GPL-2.0-or-laterStrong copyleft. Distribute the binary and the source duty follows.Read
- AGPL-3.0-onlyNetwork copyleft. Hosting the software can trigger the source duty.Read
Start here
“Open source” is not permission to ship. It's a contract.
Three assumptions cause most last-minute license work. Fix them before the next release or buyer request.
Read the full misconceptions breakdown“It's open source, we can ship it.”
Permissive licenses still require copyright and license notices in distributions. Copyleft can require source offers. Never a footnote on a wiki.
“We're SaaS, licenses don't apply.”
Some obligations are lighter for network-only use; many aren't. Fonts, installers, and bundled assets still carry duties, and buyers still ask.
“npm update is just a patch.”
A version bump can change the effective license or add copyleft. Routine updates are the most common way compliance breaks unnoticed.
Reading up because someone asked for proof?
Skip the fire drill. Import your inventory and see where you stand, free, in minutes.

