Open Source License Risk

Know what your dependencies oblige you to do

Catalog open-source dependencies across your repositories with license analysis, risk scoring, and CycloneDX SBOM export, keeping supply chain evidence audit-ready for SOC 2, ISO 27001, and customer security reviews.

Why license risk matters

A license is a contract you agreed to by installing a package.

It can reach your own source code

Reciprocal licenses such as GPL and AGPL can require you to publish the code you built around them. That obligation attaches to how you ship, not to whether you noticed the license.

It arrives through dependencies you never chose

Your direct dependencies get reviewed. Theirs do not. Most license exposure enters through transitive packages several levels down the tree.

It surfaces at the worst moment

License questions tend to appear during an acquisition, an enterprise security review, or a funding round, when the timeline is fixed and the answer is needed now.

Know what is in your software

A generated SBOM, license risk sorted from noise, and obligations in plain language.

Generate an SBOM for Every Repository

Connect GitHub, add the repository you want covered, and SecureSlate builds its software bill of materials, using SPDX through the GitHub dependency graph and CycloneDX through manifest parsing. The inventory spans every package manager in the repository, including npm, PyPI, RubyGems, and Packagist, and records the version, license, and package URL of each component. Export or regenerate it whenever the dependency tree changes.
SBOM dashboard showing repository scan status, component counts, and license risks

See Which Licenses Actually Put You at Risk

Every component is sorted into permissive, restrictive, or unknown, and shown alongside the licenses your codebase actually depends on. Copyleft and restrictive licenses are flagged for legal review, and unknown licenses are surfaced rather than quietly counted as clean, because no stated license means no permission granted.
License risk breakdown showing risky, unknown, and permissive components

Obligations in Plain Language, With a Recommended Action

License texts are written for lawyers. SecureSlate explains what a license actually requires, such as that GPL obliges any distributed derivative work to ship under the same license, and pairs it with a recommended action, whether that is replacing the dependency with a permissively licensed alternative or obtaining a commercial license from the maintainer.
Plain language explanation of a GPL obligation with a recommended action
FAQs

License and SBOM questions answered.

Know what you are shipping

Connect your repositories and get a full component inventory with license risk flagged.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?