Skip to main content

Workflow

Review before you release.

Bring imports, license evidence and approvals into one workflow. Publish the reviewed record and keep it current.

Import

Inventory what creates obligations

Import from GitHub, GitLab, or Azure DevOps auto-sync, or 10+ lockfile and SBOM formats

Every import classifies packages as new, updated, or unchanged first, so you see exactly what will land.

Learn more

Import from repo auto-sync or upload CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), Rust (Cargo.lock), Python (uv.lock, poetry.lock), NuGet (packages.lock.json), Maven (pom.xml), Gradle (gradle.lockfile), Composer (composer.lock), Bundler (Gemfile.lock). Each row is a license you must satisfy. Add fonts, icons, SDKs, and manual entries automated imports miss. Nothing is “done” until a human confirms the license; imports start as needs review.

Connect your repository
Illustrative examplePreview
acme/platformmain
web/package-lock.json
api/uv.lock
core/Cargo.lock
12 new · 3 updated · 40 unchanged

Needs review

Distribution context

Warnings follow how you ship.

Set SaaS, binary, or library context. SourceTrust surfaces the license risks that apply.

This choice is not cosmetic. It changes which compatibility warnings and license obligations appear.

What the engine checks

You declare how the product is distributed: Hosted service, shipped binary, library, or a mix. That choice changes which compatibility warnings and obligations appear, because AGPL in a SaaS backend is a different legal question than AGPL in an internal tool.

  • Warnings only for patterns that have caused real disputes: AGPL and SSPL in SaaS, GPL in shipped binaries, BUSL, Elastic 2.0 in managed services, OFL fonts
  • Deduplicated: Twenty AGPL packages produce one warning, not twenty
  • Re-licensing watch: Flags dependencies pinned inside known license-change windows, like Redis to AGPL or HashiCorp to BUSL
Illustrative exampleLicense intelligence
Distribution contextSaaS
queue-workerAGPL-3.0

AGPL package in your hosted service

Review the AGPL network clause before this package goes live.

Keep license and copyright notices

Guided review

Clear safe packages. Review the exceptions.

Safe, verified packages clear in bulk. The rest stay gated until the license, text, and obligations are resolved.

Auto-approve safe defaults

One click clears every permissive package with verified text and no open obligations, and says exactly why it skipped the rest.

A wizard for the rest

One package at a time with a progress bar and Approve, Skip, or Park. Each shows a plain-language situation card: What the system saw, and the single next action.

Obligations become checkboxes

License law splits into notices we render for you and the manual steps only your team can take, each with a what-this-means-for-you explainer. The Publish button stays gated until they're ticked.

Review obligations per package

Match SPDX-style licenses, not raw manifest strings. Auto-fetch license text, bulk-approve safe licenses, and surface copyleft and distribution risk from the catalog. Full license text is required before publish for notice-bearing terms. External duties must be acknowledged or publish is blocked.

Illustrative examplePackages
Auto-approved 138 packages.

4 packages need attention.

charting-libGPL-3.0
Needs review
LicenseConfirmed as GPL-3.0
License textAuto-fetched by the system

Offer the corresponding source

Share the source if you ship this package to customers.

Check off the manual steps.

Publish

Publish an attestation page per project

Each project gets a branded public attestation page from reviewed inventory; link from docs, trust centers, and RFP responses. Only approved packages with complete license text appear. Publish is blocked until your team has verified what you represent.

View attestation page
Illustrative exampleReviewed and published

Download compliant files when you need them

Generate disclosure, NOTICE, JSON, PDF, CycloneDX, and SPDX exports from the same frozen snapshot as the live page. Download into repos, attach to releases, or archive for audits. Exports include provenance and the public URL when published.

NOTICEJSONPDFCycloneDXSPDX

Govern obligations across products

Org-wide compliance dashboard, cross-project inventory search, and audit trail for compliance-relevant changes. Published vs Testing branch lanes for connected projects. License catalog maintained without redeploy.

OrganizationProject (one per shipped product)

Each project’s page and exports describe that product only. Obligations do not bleed across projects.

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.