What accumulates
What actually accumulates in a normal product
Hundreds of third-party components, and the moments that finally force teams to document what they ship.
Last updated: July 2, 2026
What accumulates in a normal product
Hundreds of npm, Go, or Rust packages, each a distinct license obligation
UI fonts under the Open Font License or proprietary terms that typical dependency imports never list
Icon packs and stock assets with Creative Commons or custom attribution rules
Maps, analytics, payment, and native SDKs with binary redistribution terms
Apache projects that require attribution inside installers, not only on a web page
- components in a typical product
247
Each one a distinct license obligation.
- fonts, icons, or SDKs in your lockfile
0
The assets that carry terms rarely appear in dependency lists.
- missing NOTICE file
1
Enough to breach terms across every release that shipped it.
Nobody has a single list. Nobody has confirmed the license text. Nobody has published what actually shipped.
That’s usually when teams finally look
Enterprise customer asks for proof third-party license obligations stay current
SOC 2, ISO 27001, or SOC 1 report in hand. Then a buyer asks something your questionnaire never covered
M&A or investment diligence on IP and OSS exposure
Major release with dependency churn; legal flags GPL/LGPL/AGPL
New fonts or icon packs without documented licenses
Attribution file in the repo years out of date
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.