Open Source
Use open source intentionally, securely and in line with license obligations.
Open source should be managed for licensing, security, provenance and contribution responsibilities.
01Principles
- Review license obligations before adoption
- Track material dependencies
- Avoid incompatible license combinations
- Monitor vulnerabilities
- Preserve notices/attribution where required
- Review client-contract restrictions
- Use an approved contribution process for company-owned code
02License review
- Common Permissive Examples
- MIT, BSD, Apache-2.0
- Legal Review Often Useful
- GPL family, AGPL, LGPL, SSPL/source-available, Custom licenses
- Rule
- This is not an automatic approval list; obligations depend on use and distribution.
03Software bill of materials
REPLACE_WITH_APPROVED_SBOM_POLICY
This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.