Skip to main content

0307Deliverables

Every product gets a compliance record that stays current

Reviewed inventory, attestation page, and multi-format exports; share as a hosted URL, export bundle, or both from the same snapshot.

Last updated: July 2, 2026

Primary deliverable

One reviewed inventory, every format diligence asks for

Add a project for each shipped product. SourceTrust keeps obligations reviewed and current as dependencies change, then publishes proof buyers can verify, a hosted page, exports for questionnaires, or both from the same inventory.

Every project produces

A maintained disclosure record for buyers and auditors, plus export files when engineering needs them in git or a release bundle.

  • Public attestation page

    Per-project buyer-facing page with approved components and full license text. Immutable snapshots with revision history. Regenerated when inventory is re-reviewed and republished.

  • Third-party license disclosure

    Complete license disclosure for everything in the product, copyright notices, license names, and attribution copy for repository roots and release packages.

  • Attribution and NOTICE files

    Short-form attribution many licenses require inside distributed artifacts. Scoped to the same reviewed inventory as the attestation page.

  • Multi-format exports

    JSON, CSV, HTML, plist, CycloneDX, SPDX, and branded PDF from the same snapshot. Includes provenance and the public page URL when published. See Exports for the full catalog.

License posture and attribution, what procurement reviewers check on a diligence list. Not a public vulnerability SBOM. We publish confirmed licenses and full license text, not component versions mapped for attack-surface analysis.

How it stays aligned with what you ship

  • Compliance that stays up to date

    Imports from your repos and SBOMs stay tied to review and publish. When packages update, licenses change, or repo sync detects drift, affected projects are flagged before you represent compliance you no longer meet.

  • Shareable proof per project

    Each product gets its own public compliance page when you need a link for docs, questionnaires, trust centers, or sales. Customers and auditors see approved components, confirmed licenses, and full license text for that product only.

  • Exports for releases and audits

    THIRD_PARTY_LICENSES.md, NOTICE, JSON, CSV, PDF, CycloneDX, and SPDX from the same frozen publish snapshot as your attestation page. Generated when engineering needs files in a repo or release bundle.

Most teams share whichever format diligence asks for, URL, export, or attachment, from the same approved inventory. Export files are there when engineering needs them in git or release bundles.

Stop shipping on assumptions

Map your obligations before the next release

Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.

Not ready to start yet? View pricing

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.