Open Source

Use open source intentionally, securely and in line with license obligations.

Open source should be managed for licensing, security, provenance and contribution responsibilities.

01Principles

  • Review license obligations before adoption
  • Track material dependencies
  • Avoid incompatible license combinations
  • Monitor vulnerabilities
  • Preserve notices/attribution where required
  • Review client-contract restrictions
  • Use an approved contribution process for company-owned code

02License review

Common Permissive Examples
MIT, BSD, Apache-2.0
Legal Review Often Useful
GPL family, AGPL, LGPL, SSPL/source-available, Custom licenses
Rule
This is not an automatic approval list; obligations depend on use and distribution.

03Software bill of materials

REPLACE_WITH_APPROVED_SBOM_POLICY

This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.