SourceTrust.dev
FOSSA
Snyk
Mend.io
Black Duck
Sonatype
sbomify
Nordchecks
FOSSA
Syft
Snyk
OWASP Dependency-Track
Trivy
Vanta
Almost every software product is built on open-source packages. Each package comes with a license, and most licenses ask for something in return: keep the copyright notice, include the license text, or share your changes. When a customer's procurement or legal team reviews a vendor, they increasingly ask for proof that this is handled and kept up to date.
SourceTrust makes that proof simple to produce and simple to read. Import the dependency file you already have (lockfiles for JavaScript, Python, Java, Go, Rust, .NET, Ruby, PHP, Swift and Dart, or a CycloneDX or SPDX SBOM). SourceTrust lists every package with its license and explains in plain language what that license asks of you. You review each item, then publish a branded, public attestation page at your own URL or custom domain. Anyone can read it in a few minutes, no login needed. Connect a GitHub repository and imports run automatically, so the page stays current when you ship a new version.
Exports in CycloneDX, SPDX, NOTICE, CSV, JSON, HTML and PDF fit the questionnaires and vendor portals your customers use. Creating projects, importing and reviewing is free. Public GitHub repositories can publish their page for $0. Paid plans are $29 per project per month or $299 per year, with no per-user fees.
SourceTrust gives you an operational record you can share, not legal advice.
SourceTrust.dev
sbomifySourceTrust.dev's answer
SourceTrust turns the dependency list you already have into a reviewed, public compliance page: every open-source package you ship, its license, and what you did about each obligation. Each license is explained in plain language, you review each item, and the result is published at your own URL or custom domain. Anyone can read it in a few minutes, no login needed.
FOSSA - Open source license compliance and dependency analysis
Nordchecks - Free EU Cyber Resilience Act scope check + simple compliance tool: SBOM, daily vulnerability monitoring, 24h reporting and technical documentation.
Snyk - Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
Mend.io - Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. Our unified platform enables companies to manage application risk effectively in modern software development.
Syft - The most affordable & accurate email checker
Black Duck - Organizations worldwide use Black Duck Software's open source management and security solutions to ensure security in their applications and containers.About · We're Hiring!