02 — Capability · BC-1280.30
Inbound Open Source Governance
Know what open source the product depends on, under which licenses, and keep use and contribution within the company's policy so a license term never becomes a surprise at due diligence.
- Open Source Compliance
- Dependency Licensing
- Contribution Policy
In scope
- Approved license list and review of exceptions
- Inventory of open source shipped in the product
- Policy for employees contributing to external projects
Out of scope
- Vulnerability tracking of those dependencies (see BC-1270)
- Procurement of commercial software (see BC-620)
Realized by · 0
- No product in the catalog yet.
Used in · 1
Build it · 1
- pattern Inner Source via BC-1280.30.30
Decomposes into · 3
- BC-1280.30.10License Policy & ReviewDefine which licenses are acceptable in which contexts and review the exceptions with legal before code is merged.
- BC-1280.30.20Component Inventory & AttributionKeep an accurate list of shipped open source components and produce the attribution notices each license requires.
- BC-1280.30.30Employee Contribution PolicyMake it clear and easy for employees to contribute to external projects without putting company IP at risk.