0307Deliverables
Every product gets a compliance record that stays current
Reviewed inventory, attestation page, and multi-format exports; share as a hosted URL, export bundle, or both from the same snapshot.
Last updated: July 2, 2026
Primary deliverable
One reviewed inventory, every format diligence asks for
Add a project for each shipped product. SourceTrust keeps obligations reviewed and current as dependencies change, then publishes proof buyers can verify, a hosted page, exports for questionnaires, or both from the same inventory.
Every project produces
A maintained disclosure record for buyers and auditors, plus export files when engineering needs them in git or a release bundle.
Public attestation page
Per-project buyer-facing page with approved components and full license text. Immutable snapshots with revision history. Regenerated when inventory is re-reviewed and republished.
Third-party license disclosure
Complete license disclosure for everything in the product, copyright notices, license names, and attribution copy for repository roots and release packages.
Attribution and NOTICE files
Short-form attribution many licenses require inside distributed artifacts. Scoped to the same reviewed inventory as the attestation page.
Multi-format exports
JSON, CSV, HTML, plist, CycloneDX, SPDX, and branded PDF from the same snapshot. Includes provenance and the public page URL when published. See Exports for the full catalog.
License posture and attribution, what procurement reviewers check on a diligence list. Not a public vulnerability SBOM. We publish confirmed licenses and full license text, not component versions mapped for attack-surface analysis.
How it stays aligned with what you ship
Compliance that stays up to date
Imports from your repos and SBOMs stay tied to review and publish. When packages update, licenses change, or repo sync detects drift, affected projects are flagged before you represent compliance you no longer meet.
Shareable proof per project
Each product gets its own public compliance page when you need a link for docs, questionnaires, trust centers, or sales. Customers and auditors see approved components, confirmed licenses, and full license text for that product only.
Exports for releases and audits
THIRD_PARTY_LICENSES.md, NOTICE, JSON, CSV, PDF, CycloneDX, and SPDX from the same frozen publish snapshot as your attestation page. Generated when engineering needs files in a repo or release bundle.
Most teams share whichever format diligence asks for, URL, export, or attachment, from the same approved inventory. Export files are there when engineering needs them in git or release bundles.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.
Stop shipping on assumptions
Map your obligations before the next release
Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.
Not ready to start yet? View pricing