Skip to main content

Business impact

What companies risk without a maintained obligation record

Deal delays, audit surprises, and false confidence: The pattern behind operational risk. For court outcomes and case law, see Legal outcomes.

Last updated: July 2, 2026

When obligations stay invisible

01When obligations stay invisible

These are not edge cases. They are the pattern behind deal delays, legal exposure, and last-minute scrambles before a release, at startups and enterprises alike.

If this feels uncomfortable, that is the point. The gap is common; pretending it does not exist is the expensive choice.

For court outcomes, damages, and case law, see Legal outcomes.

  • Shipping blind on third-party obligations

    Most teams track features and bugs, not license duties. When a buyer or lawyer asks for current third-party license disclosure, nobody can produce a reviewed list with full text, not because the team is careless, but because obligations were never operationalized.

  • Ship without valid notice and attribution

    Missing or stale attribution files can breach license terms across every affected component, emergency releases and reputational damage follow.

  • Cannot prove compliance to customers or auditors

    Procurement expects proof that stays current and consistency between SBOM, published disclosure, and shipped attribution. Stale snapshots are a red flag that slows deals.

  • Copyleft surprises after binaries go out

    GPL-family licenses may require source offers and careful distribution analysis. SaaS-only use does not automatically clear all licenses.

  • Invisible third parties create silent liability

    Fonts, icon packs, and native SDKs rarely appear in dependency imports, yet customers care about them in audits.

  • Inventory drift = false confidence

    Last year's PDF while your package inventory moved on, including after routine package updates that changed licenses. Per-release import → review → publish → regenerate, with CI flags when drift appears before ship.

  • Misrepresenting compliance is worse than no page

    Vague pages without full text or unapproved components mislead customers. Publish gates exist so you do not claim what you have not operationalized.

  • Deal and M&A friction

    Weak OSS hygiene delays enterprise closes, chips M&A price, and increases indemnity exposure when customers rely on your representations.

Read what violations can cost in court

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.