Skip to main content

What accumulates

What actually accumulates in a normal product

Hundreds of third-party components, and the moments that finally force teams to document what they ship.

Last updated: July 2, 2026

What accumulates in a normal product

  • Hundreds of npm, Go, or Rust packages, each a distinct license obligation

  • UI fonts under the Open Font License or proprietary terms that typical dependency imports never list

  • Icon packs and stock assets with Creative Commons or custom attribution rules

  • Maps, analytics, payment, and native SDKs with binary redistribution terms

  • Apache projects that require attribution inside installers, not only on a web page

components in a typical product

247

Each one a distinct license obligation.

fonts, icons, or SDKs in your lockfile

0

The assets that carry terms rarely appear in dependency lists.

missing NOTICE file

1

Enough to breach terms across every release that shipped it.

Nobody has a single list. Nobody has confirmed the license text. Nobody has published what actually shipped.

That’s usually when teams finally look

  • Enterprise customer asks for proof third-party license obligations stay current

  • SOC 2, ISO 27001, or SOC 1 report in hand. Then a buyer asks something your questionnaire never covered

  • M&A or investment diligence on IP and OSS exposure

  • Major release with dependency churn; legal flags GPL/LGPL/AGPL

  • New fonts or icon packs without documented licenses

  • Attribution file in the repo years out of date

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.