Skip to main content

Who is responsible

For companies that distribute software and inherit its license obligations

If third-party code, fonts, icons, or SDKs are in what you ship, your organization has legal duties whether or not anyone has documented them.

Last updated: July 2, 2026

01Who owns the duty?

SaaS, desktop, mobile, on-prem, appliances, embedded. The delivery model changes which obligations bite hardest, not whether obligations exist.

  • Legal / compliance / OSPO

    Owns whether publish and distribution steps satisfy each obligation. Needs a maintained record to share with procurement, not a stale spreadsheet or a dashboard only engineering can read.

  • Product / customer success

    Owns the enterprise deal when buyers ask for proof. Defensible disclosure they can verify release to release, not an ad-hoc snapshot sent under deadline.

  • Engineering / release

    Owns what actually ships, and keeps attribution files, SBOM imports, and pipeline checks aligned with the published page.

When this applies

  • Multi-product vendors. Each shipped product carries its own obligation set
  • Teams asked to prove third-party license posture in security reviews and procurement
  • Organizations tired of discovering GPL, missing required attribution, or invisible fonts after ship

Outside scope

  • Pure services with no bundled third-party materials and no distributable artifact
  • One-time legal opinions with no inventory tied to what engineering releases

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.