Skip to main content

Compliance page

What a license compliance page is, and what it should contain

One way to host a maintained disclosure record: Reviewed inventory, full license text, and attribution buyers can verify.

Last updated: July 2, 2026

What is a license compliance page?

A license compliance page is a stable public URL that lists third-party components in a shipped product, with reviewed licenses and full license text. Procurement, security reviewers, and auditors open it during diligence, so it should match what you actually ship, not a snapshot from last year.

The reviewed part matters: Black Duck's 2025 OSSRA found that 33% of audited codebases contained open source with no license or a customized license, the kind of components that need human review before any page can fairly claim them.

This page explains the concept. The pre-share walkthrough version is the guides page "Compliance page checklist".

What does a strong page include?

The reviewer's checklist
  • Product identity: Which shipped product the page covers
  • Component inventory with identifiable names and versions
  • SPDX-style license identifiers, after human review
  • Full license text or reliable links to it for each component
  • Attribution blocks where licenses require them
  • A revision or date so the reader knows what release it reflects

What is it not?

  • A raw SBOM dump without reviewed disclosure.
  • A PDF emailed once and never updated.
  • A list of npm packages with no license text.
  • Legal advice or a guarantee of compliance.

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Next step

When you are ready to move from reading to action:

Inspect our live page

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.