{"version":"0.2.0","built_at":"2026-10-10T20:58:14.188Z","license":"CC BY 4.0 © Mike Reams","canonical":"https://catalog.mikereams.com","capability":{"id":"BC-1280.30","name":"Inbound Open Source Governance","level":2,"parent_id":"BC-1280","l1_id":"BC-1280","industry":"software","macro_id":null,"path":["Open Source & Community","Inbound Open Source Governance"],"description":"Know what open source the product depends on, under which licenses, and keep use and contribution within the company's policy so a license term never becomes a surprise at due diligence.","aliases":["Open Source Compliance","Dependency Licensing","Contribution Policy"],"in_scope":["Approved license list and review of exceptions","Inventory of open source shipped in the product","Policy for employees contributing to external projects"],"out_of_scope":["Vulnerability tracking of those dependencies (see BC-1270)","Procurement of commercial software (see BC-620)"],"csdm_note":null,"status":"active","successor_id":null,"child_ids":["BC-1280.30.10","BC-1280.30.20","BC-1280.30.30"]},"crosswalk":{"realized_by":[],"used_in":[{"vs_id":"VS-100","vs":"Commit-to-Production","stage_id":"VS-100.10","stage":"Commit & Build","order":1,"via":null}],"patterns":[{"id":"DP-490","name":"Inner Source","category":"Organization","via":"BC-1280.30.30"}],"stacks":[],"books":[]},"ancestors":[{"id":"BC-1280","name":"Open Source & Community","level":1}],"children":[{"id":"BC-1280.30.10","name":"License Policy & Review","level":3,"child_count":0},{"id":"BC-1280.30.20","name":"Component Inventory & Attribution","level":3,"child_count":0},{"id":"BC-1280.30.30","name":"Employee Contribution Policy","level":3,"child_count":0}]}