Open-source audit of your components
We will find every piece of other people's code inside your build, read the licence that came with it, and tell you which of its conditions your release has already switched on.
Written source offer
Обещание исходника
at least 3 years
не меньше 3 лет
After a first notice
После уведомления
30 days to cure
30 дней на исправление
After you stop
После прекращения
60 silent days
60 дней молчания
A patent grant
Патентное разрешение
ends the day you sue
снимается вашим иском
When you need an open-source audit

A buyer sent a component list
Diligence asks for every package in the build and the licence beside it. Nobody on the team has ever produced that list before.
You are shipping a device
Software inside hardware travels to the customer, and some conditions wake up only at that moment. A download page is a different question.
A customer wants an indemnity
The contract asks you to stand behind the whole product. Part of that product came from strangers on terms nobody in the room has read.
Someone filed a complaint
A maintainer says a condition was missed. Whether your permission still exists depends on what you do in the next few weeks.
The build pulls in what it likes
Dependencies arrive with dependencies. What is in the release today was chosen by a resolver, and its licences came along unread.
What you get
- A list of every component
- The licence text behind each
- Conditions sorted by what triggers them
- The notices file you owe
- A rule for adding new packages
What an open-source audit reads

Free code is not free of conditions. Every package you pulled in came with a document, that document is a licence and not a gift, and the moment you hand the software on, its conditions apply to you.
The audit answers three questions in writing: what is inside the build, what each licence demands, and which of those demands your release already triggers. Who owns the material your own team wrote is a separate job, and that is an audit of the chain of title.
What the audit reads
- The dependency tree as the build resolves it, including what nobody chose.
- The licence text sitting in each package, at the version you ship, and not the label a directory gives it.
- Code copied in by hand: snippets from forums, sample files and generated fragments.
- How the software reaches people: a download, a device, a service reached over a network.
- What you already publish: the notices file and the attribution screen.
Where conditions come from
One set of conditions asks only that you pass the paperwork on: retain the copyright, patent, trademark and attribution notices in the source form you distribute, carry a copy of the licence, mark the files you changed, and reproduce the notices file where the package ships with one. The Apache License version 2.0 asks for that set.
Another group reaches your own code, and the reach differs by licence: the Mozilla Public License version 2.0 covers the files its code sits in, including new files you write that carry it, while the GNU General Public License covers the whole work you distribute.
Version 3 of the GNU Affero General Public License goes further: if you modify the program and let people use your modified version over a network, you have to offer those users the source of your version from a network server, at no charge.
What ends a permission
The permission is conditional, so a breach ends it by itself. Under the GNU General Public License version 2 that is the whole story: rights terminate automatically, and the text sets out no way to restore them.
Version 3 added a way out. Stop the violation, and your licence from a given holder is reinstated provisionally at once, and permanently if that holder does not notify you within sixty days of the cessation. If they do notify you, and it is the first notice you have had from them, curing within thirty days of receiving it makes the reinstatement permanent. The Mozilla Public License version 2.0 is built the same way.
Where you ship the compiled form inside a physical product, version 3 of the GNU General Public License lets you accompany it with a written offer of the source instead. That offer has to stay valid for at least three years, and for as long as you offer spare parts or support for that product model.
Patent permissions end on their own trigger: the Apache License ends yours on the day you start patent litigation claiming the work infringes.
Sources: the written source offer — three years, and as long as you offer spare parts or support for that model — and reinstatement after sixty silent days or a cure within thirty days of a first notice are in the GNU General Public License; automatic termination, in its version 2; the network source duty, in the Affero licence; the patent grant ends the day you sue, Apache.
Stages of work
Building the inventory — 3–5 working days.
The starting point is the release you ship, not the repository as it looks today. We will take the dependency tree at that version, with all it pulled in.
Reading the licences themselves.
The file inside the package is the licence; a directory label is a guess about it. We will read the text that shipped, at the version that shipped, and record which we read.
Following each condition to where it lands.
Every condition gets a trigger: distributing binaries, modifying files, linking, putting it in a device, letting people reach it over a network. Only the triggered ones cost anything.
Marking what reaches your own code.
We will separate the components that ask only for notices from the ones whose conditions travel into whatever you combine them with, and say how far each goes in your build.
Fixing what is cheap and naming what is not.
Missing notices, an absent licence copy and an unwritten notices file are drafted and closed in one pass. A component whose conditions cannot live with your product becomes a replacement decision.
The report and the rule for next time.
One document: the components, the licences, the triggered conditions, what was fixed and what is open. A buyer can be given it in the form it was assembled in, and it closes with a short rule for adding the next package.
The wider practice this belongs to is IP & Content.
FAQ
Only some of it does, and only when you hand the software on. One group of licences asks for notices and an attribution file and nothing more. Another carries conditions that travel into whatever you combine them with, and even inside that group the reach differs: the Mozilla Public License covers the files its code sits in, the GNU General Public License the whole work you distribute. Which of yours falls where is what the inventory is for.
There are four of them, in rising order of cost. Keep the copyright, patent, trademark and attribution notices that came with the package. Ship a copy of the licence text, mark the files you changed, and reproduce the attribution file where the package brought one, in a place the recipient can read. The Apache License version 2.0 asks for that set; the copyleft family adds a duty to make source available, and that is where the real work sits.
The permission ends by itself, because it was conditional from the start. Under the older second version of the general public licence that is final: the text terminates the rights and offers no way back. The third version gives one. Stop the violation and the licence is reinstated provisionally at once, and permanently if the holder stays silent for sixty days after you stopped; if they do write, and it is their first notice to you, curing within thirty days of receiving it makes it permanent.
Because the conditions do not stay with you, they travel with the software they are attached to. A buyer who acquires the product acquires every duty inside it, including the ones nobody recorded, and the price of that lands in the negotiation instead of in a court. The component list with a licence beside each line answers a whole section of their questionnaire, and it is worth more when it exists beforehand.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.

