Open-source audit of your components

We will find every piece of other people's code inside your build, read the licence that came with it, and tell you which of its conditions your release has already switched on.

 

Written source offer

Обещание исходника

at least 3 years

не меньше 3 лет

After a first notice

После уведомления

30 days to cure

30 дней на исправление

After you stop

После прекращения

60 silent days

60 дней молчания

A patent grant

Патентное разрешение

ends the day you sue

снимается вашим иском

When you need an open-source audit

A buyer sent a component list

Diligence asks for every package in the build and the licence beside it. Nobody on the team has ever produced that list before.

You are shipping a device

Software inside hardware travels to the customer, and some conditions wake up only at that moment. A download page is a different question.

A customer wants an indemnity

The contract asks you to stand behind the whole product. Part of that product came from strangers on terms nobody in the room has read.

Someone filed a complaint

A maintainer says a condition was missed. Whether your permission still exists depends on what you do in the next few weeks.

The build pulls in what it likes

Dependencies arrive with dependencies. What is in the release today was chosen by a resolver, and its licences came along unread.

What you get

  • A list of every component
  • The licence text behind each
  • Conditions sorted by what triggers them
  • The notices file you owe
  • A rule for adding new packages

What an open-source audit reads

Free code is not free of conditions. Every package you pulled in came with a document, that document is a licence and not a gift, and the moment you hand the software on, its conditions apply to you.

The audit answers three questions in writing: what is inside the build, what each licence demands, and which of those demands your release already triggers. Who owns the material your own team wrote is a separate job, and that is an audit of the chain of title.

What the audit reads

  • The dependency tree as the build resolves it, including what nobody chose.
  • The licence text sitting in each package, at the version you ship, and not the label a directory gives it.
  • Code copied in by hand: snippets from forums, sample files and generated fragments.
  • How the software reaches people: a download, a device, a service reached over a network.
  • What you already publish: the notices file and the attribution screen.

Where conditions come from

One set of conditions asks only that you pass the paperwork on: retain the copyright, patent, trademark and attribution notices in the source form you distribute, carry a copy of the licence, mark the files you changed, and reproduce the notices file where the package ships with one. The Apache License version 2.0 asks for that set.

Another group reaches your own code, and the reach differs by licence: the Mozilla Public License version 2.0 covers the files its code sits in, including new files you write that carry it, while the GNU General Public License covers the whole work you distribute.

Version 3 of the GNU Affero General Public License goes further: if you modify the program and let people use your modified version over a network, you have to offer those users the source of your version from a network server, at no charge.

What ends a permission

The permission is conditional, so a breach ends it by itself. Under the GNU General Public License version 2 that is the whole story: rights terminate automatically, and the text sets out no way to restore them.

Version 3 added a way out. Stop the violation, and your licence from a given holder is reinstated provisionally at once, and permanently if that holder does not notify you within sixty days of the cessation. If they do notify you, and it is the first notice you have had from them, curing within thirty days of receiving it makes the reinstatement permanent. The Mozilla Public License version 2.0 is built the same way.

Where you ship the compiled form inside a physical product, version 3 of the GNU General Public License lets you accompany it with a written offer of the source instead. That offer has to stay valid for at least three years, and for as long as you offer spare parts or support for that product model.

Patent permissions end on their own trigger: the Apache License ends yours on the day you start patent litigation claiming the work infringes.

Sources: the written source offer — three years, and as long as you offer spare parts or support for that model — and reinstatement after sixty silent days or a cure within thirty days of a first notice are in the GNU General Public License; automatic termination, in its version 2; the network source duty, in the Affero licence; the patent grant ends the day you sue, Apache.

Stages of work

Building the inventory — 3–5 working days.

The starting point is the release you ship, not the repository as it looks today. We will take the dependency tree at that version, with all it pulled in.

Reading the licences themselves.

The file inside the package is the licence; a directory label is a guess about it. We will read the text that shipped, at the version that shipped, and record which we read.

Following each condition to where it lands.

Every condition gets a trigger: distributing binaries, modifying files, linking, putting it in a device, letting people reach it over a network. Only the triggered ones cost anything.

Marking what reaches your own code.

We will separate the components that ask only for notices from the ones whose conditions travel into whatever you combine them with, and say how far each goes in your build.

Fixing what is cheap and naming what is not.

Missing notices, an absent licence copy and an unwritten notices file are drafted and closed in one pass. A component whose conditions cannot live with your product becomes a replacement decision.

The report and the rule for next time.

One document: the components, the licences, the triggered conditions, what was fixed and what is open. A buyer can be given it in the form it was assembled in, and it closes with a short rule for adding the next package.

The wider practice this belongs to is IP & Content.

Our case studies

Tech JV Entry into Saudi Arabia

Client

Leading Singapore-based technology company

arrow_outward

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward
Anton Karpenko

Anton

Karpenko

arrow_outward

FAQ

Does open-source code make our product open too?
add
remove
What does an open-source licence require of us?
add
remove
What happens if we have breached a licence?
add
remove
Why do buyers ask about open-source components?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.