Publish a license page, hand over license files, or export an SBOM. Each comes from the same reviewed snapshot.
Approved release record
Ready to shareinventory · evidence · approval
Public pageLicense filesSBOM export
Every project produces
Four outputs. One reviewed record.
A maintained disclosure record for buyers and auditors, plus export files when engineering needs them in git or a release bundle.
Illustrative examplePublished · rev 12
A
Acme Platform
sourcetrust.app/acme/platform
reactMIT
expressMIT
Public attestation page
Per-project buyer-facing page with approved components and full license text. Immutable snapshots with revision history. Regenerated when inventory is re-reviewed and republished.
Permission is hereby granted, free of charge, to any person obtaining a copy…
Third-party license disclosure
Complete license disclosure for everything in the product, copyright notices, license names, and attribution copy for repository roots and release packages.
Short-form attribution many licenses require inside distributed artifacts. Scoped to the same reviewed inventory as the attestation page.
Illustrative examplePublished · rev 12
JSONCSVPDFHTMLCycloneDXSPDX
Multi-format exports
JSON, CSV, HTML, plist, CycloneDX, SPDX, and branded PDF from the same snapshot. Includes provenance and the public page URL when published. See Exports for the full catalog.
Most teams share whichever format diligence asks for, URL, export, or attachment, from the same approved inventory. Export files are there when engineering needs them in git or release bundles.
What buyers see
License posture and attribution, what procurement reviewers check on a diligence list. Not a public vulnerability SBOM. We publish confirmed licenses and full license text, not component versions mapped for attack-surface analysis.
We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.