Diagnostics & monitoring · One-time website audits

Open-source license compliance audit

We review which open-source libraries and dependencies your product uses and under which licenses: where it is MIT and Apache and where it is copyleft (GPL/AGPL/LGPL), what obligations they impose (attribution, source disclosure), whether there are license conflicts and risky spots for a commercial product. We provide an inventory (SBOM) and a prioritized risk list. Honestly upfront: we are not lawyers — this is a technical inventory and analysis, not a legal opinion; the final interpretation of licenses and the legal assessment for your situation are given by a lawyer.

Price
$3,600
Duration
usually 5 to 10 business days (depends on the number of dependencies and the stack)

Open-source license compliance audit — overview

Open-source license compliance audit — price, timeline & scope

An open-source license compliance audit is a one-time technical review of your product's open-source libraries and dependencies for licenses and related obligations: an inventory of all dependencies, including transitive ones (dependencies of dependencies), with the license identified for each; classification by type (permissive — MIT, Apache, BSD; copyleft — GPL, AGPL, LGPL, MPL; and problematic/unknown); what obligations each license imposes (attribution, including the license text, source-code disclosure for copyleft, usage restrictions); finding conflicts between licenses and risks for your distribution model (especially AGPL for SaaS and copyleft in a proprietary product); dependencies with a missing, ambiguous or dual license; producing a software bill of materials (SBOM) and a prioritized risk list. Honestly and importantly: we are not lawyers — this is a technical inventory and analysis of licenses, NOT a legal opinion and not a guarantee against claims. We identify licenses and typical obligations and flag risky spots, but the final interpretation of a specific license for your situation and the legal assessment are given by a lawyer — our report helps them. Honestly about the method: license identification is done with tools and analysis, and there are limits here — transitive dependencies, libraries with no explicitly stated license, dual licensing and non-standard texts require manual review, and some cases remain "needs to be checked with a lawyer" rather than "definitely allowed/not allowed". It is a snapshot in time: with every update and new dependency the picture changes, so the audit is tied to a specific state of the project. And it is an assessment with a document, not fixing: replacing problematic libraries, adding attribution-notice files and changes are separate work, by us or by your team. An important boundary: this is a license audit, not a dependency security audit (vulnerabilities and CVEs are a separate topic) and not general legal compliance. If the product barely uses third-party dependencies, there is almost nothing to assess and you most likely do not need the audit. Picture this: instead of "it is all open-source libraries, it is free, right" you learn that one dependency is under AGPL and with your SaaS model that is a serious risk (by the letter of such a license you may be required to open the entire product source code), three libraries lack the required attribution, and one pulls in a copyleft dependency nobody knew about — with priorities and a clear "what to ask a lawyer". The base price starts from 18,000 ₽; it depends on the number of dependencies and the stack (this is a manual review on top of tools plus SBOM preparation, so it costs more than a simple scan).

Problems we solve

  • You do not know under which licenses your open-source dependencies are.
  • You sell or distribute the product and fear violating licenses (especially copyleft/AGPL).
  • A client or investor asks for an SBOM or confirmation of license cleanliness.
  • You suspect license conflicts or forgotten attribution obligations.

What's included in the Open-source license compliance audit service

  • An inventory of all dependencies, including transitive ones
  • License identification for each dependency
  • Classification: permissive / copyleft / problematic and unknown
  • Obligations of each license (attribution, text, source disclosure)
  • License conflicts and risks for your distribution model (AGPL/SaaS)
  • Dependencies with no license, ambiguous or dual license
  • A software bill of materials (SBOM) and a prioritized risk list
  • What to fix technically and what to ask a lawyer

What you get

  • A clear picture of your dependencies' licenses and their obligations
  • Visibility of conflicts and risky spots for your model
  • A ready SBOM and a prioritized risk list
  • Clarity on what is technical and what is a question for a lawyer

How the work goes: steps

  • We clarify the product, stack, distribution model and collect access to the code/dependencies
  • We inventory dependencies, identify licenses and obligations, look for conflicts
  • We prepare the SBOM and a prioritized risk list and review them with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Is this a legal opinion on license cleanliness?

    No. We are not lawyers: this is a technical inventory and analysis of licenses, not a legal opinion and not a guarantee against claims. We identify licenses, obligations and risky spots, while the final interpretation for your situation is given by a lawyer.

  • Are all licenses identified for certain?

    Identification is done with tools and manual analysis, but there are limits: transitive dependencies, libraries with no explicit license, dual licensing and non-standard texts require manual review, and some cases are "needs checking with a lawyer". No one can give a full mathematical guarantee, and some cases (no license, an abandoned project, a non-standard text) may have no clear resolution even after a lawyer — such modules are usually safer to replace.

  • Will you replace problematic libraries and add notices?

    No, that is separate work. The audit gives an inventory (SBOM), a risk list and recommendations. Replacing libraries, adding attribution files and changes are done separately or by your team.

About the provider

The «Open-source license compliance audit» service is provided by PDV Expert — a team specialising in «Diagnostics & monitoring». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated