Skip to main content

Deliverables

One record. Ready to share.

Publish a license page, hand over license files, or export an SBOM. Each comes from the same reviewed snapshot.

Every project produces

Four outputs. One reviewed record.

A maintained disclosure record for buyers and auditors, plus export files when engineering needs them in git or a release bundle.

Illustrative examplePublished · rev 12
Acme Platform

sourcetrust.app/acme/platform

reactMIT
expressMIT

Public attestation page

Per-project buyer-facing page with approved components and full license text. Immutable snapshots with revision history. Regenerated when inventory is re-reviewed and republished.

Attestation page
Illustrative examplePublished · rev 12
THIRD_PARTY_LICENSES.mdreact · MIT

© Meta Platforms, Inc. and affiliates.

Permission is hereby granted, free of charge, to any person obtaining a copy…

Third-party license disclosure

Complete license disclosure for everything in the product, copyright notices, license names, and attribution copy for repository roots and release packages.

Illustrative examplePublished · rev 12
NOTICEAcme Platform

react · MIT

© Meta Platforms, Inc. and affiliates.

Attribution and NOTICE files

Short-form attribution many licenses require inside distributed artifacts. Scoped to the same reviewed inventory as the attestation page.

Illustrative examplePublished · rev 12
JSONCSVPDFHTMLCycloneDXSPDX

Multi-format exports

JSON, CSV, HTML, plist, CycloneDX, SPDX, and branded PDF from the same snapshot. Includes provenance and the public page URL when published. See Exports for the full catalog.

Exports

How it stays aligned with what you ship

Built from the same snapshot.

How to share

Most teams share whichever format diligence asks for, URL, export, or attachment, from the same approved inventory. Export files are there when engineering needs them in git or release bundles.

What buyers see

License posture and attribution, what procurement reviewers check on a diligence list. Not a public vulnerability SBOM. We publish confirmed licenses and full license text, not component versions mapped for attack-surface analysis.

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.