Skip to main content

The product

One connected record for every release.

Import your inventory, review the exceptions, publish buyer-ready proof, and see when it drifts.

Request a live walkthrough
mainv1.4.0
mainpackage-lock.jsonSBOM
Review142
reactMIT
expressMITLICENSE
date-fnsMIT
PublishMonitor
Illustrative exampleApproved release record
  1. ImportBring the inventory inRepository, lockfile, or SBOM.
  2. ReviewResolve what needs a decisionEvidence and status stay together.
  3. PublishApprove one release recordPage, notice files, and exports.
  4. MonitorSee when the record driftsChanges surface before buyers ask.

Guided review

Review the exceptions. Keep the evidence.

Straightforward matches clear in bulk. Your team stays focused on the packages that need a decision.

  • Evidence found
  • Human review
  • Obligations resolved
See how verification works
Acme PlatformTesting branch
Review gate
Illustrative exampleBulk approve safe
  • react 18.3.1MITApproved
  • gantt-pro 2.0.0GPL-3.0Copyleft
  • Satoshi fontCustomNeeds review

Stay current

See when the record drifts

See dependency drift and license changes. Add private security monitoring when you need it.

How drift detection works
Illustrative exampleacme/platform
Published · rev 12

Public page

12
3 dependencies changed, 1 license changed

Review changes

The dashboard banner and status pills name exactly what moved since the published revision

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.