Skip to main content

License compliance

License compliance: 9

Start with the license obligations.

See what applies, who owns the work, and what evidence you need before a buyer asks.

Last updated: July 2, 2026

Most teams pass security audits but still cannot prove third-party license obligations stay current with what they ship. The gap is not effort: It is that duties from hundreds of dependencies, fonts, and SDKs were never inventoried against what actually releases.

Open source does not mean no legal duties. Every component is a license agreement with notice, attribution, and sometimes copyleft rules that engineering changes every sprint.

Common questions

Is using open source the same as being allowed to ship it?

No. Open source grants use under specific license conditions: Notice, attribution, copyleft rules, or distribution limits. Each component can differ.

Who is responsible for license compliance?

The organization that distributes the software, not an individual developer. Engineering builds the record; legal or compliance often reviews; procurement shares it externally.

Does a security audit replace a license compliance page?

No. SOC 2, penetration tests, and SBOM programs answer different questions. Buyers still ask for reviewed third-party license disclosure.

Is this legal advice?

No. These pages explain operational duties and common patterns. Legal interpretation stays with your counsel.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.