Skip to main content

License compliance

Understand third-party license obligations before someone asks

What accumulates in a shipped product, who owns the duty, where it shows up, and how to keep a maintained record: inventory, review, publish, then watch for drift.

Last updated: July 2, 2026

01Why it matters

Most teams pass security audits but still cannot prove third-party license obligations stay current with what they ship. The gap is not effort: It is that duties from hundreds of dependencies, fonts, and SDKs were never inventoried against what actually releases.

Open source does not mean no legal duties. Every component is a license agreement with notice, attribution, and sometimes copyleft rules that engineering changes every sprint.

Common questions

Is using open source the same as being allowed to ship it?

No. Open source grants use under specific license conditions: Notice, attribution, copyleft rules, or distribution limits. Each component can differ.

Who is responsible for license compliance?

The organization that distributes the software, not an individual developer. Engineering builds the record; legal or compliance often reviews; procurement shares it externally.

Does a security audit replace a license compliance page?

No. SOC 2, penetration tests, and SBOM programs answer different questions. Buyers still ask for reviewed third-party license disclosure.

Is this legal advice?

No. These pages explain operational duties and common patterns. Legal interpretation stays with your counsel.

Next step

When you are ready to move from reading to action:

Run a free surface scan

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.