Classify open source licences into permissive, weak copyleft and strong copyleft categories with their distribution triggers.
Open Source Licence Compliance and Copyleft Obligations in Software Products
Build a practical open source compliance programme covering licence scanning, copyleft obligations, SBOM production and clearance decisions before shipment.
Course Overview
Every shipped product now carries hundreds of open source components, and a single miscategorised copyleft dependency can force source code disclosure, delay a release or unwind an acquisition. This course teaches lawyers, engineers and compliance officers to run a defensible open source clearance process from intake to release. Participants work through the real distinctions that matter in practice: permissive versus copyleft, weak versus strong copyleft, and the network-use trigger in the AGPL that catches software-as-a-service products many teams assume are safe. Sessions cover building a software bill of materials with SPDX or CycloneDX metadata, running automated scanning tools against a codebase, resolving licence conflicts before merge, and drafting the notices and offer-of-source letters that copyleft licences require on distribution. The course closes with the governance layer: an OpenChain-aligned compliance programme, a clearance request workflow with defined approval gates, and the open source due diligence checklist used in technology mergers and acquisitions. Every exercise uses a real licence text or scan report so participants leave able to make and document a clearance decision, not just describe the risk.
Expected Learning Outcomes
Generate a software bill of materials in SPDX format from a dependency tree using automated scanning tools.
Resolve licence compatibility conflicts between components before a release candidate is approved.
Draft attribution notices, licence texts and offer-of-source letters required on binary distribution.
Design a clearance request workflow with defined approval gates for new open source dependencies.
Build an OpenChain-aligned compliance programme covering policy, training and audit records.
Run open source due diligence on a target company's codebase ahead of a merger or acquisition.
Who Should Attend
In-house counsel supporting software product and engineering organisations.
Open source programme office leads and licence compliance officers.
Software engineers and architects responsible for dependency selection.
M&A and technology transaction lawyers conducting code-level due diligence.
Procurement staff evaluating vendor software for embedded open source components.
Compliance managers building or auditing an open source governance programme.
Course Modules
Select any module to see its sessions and points.
01Licence Categories, Copyleft Triggers and Obligation Mapping
2 sessions · 8 points
Session 1Permissive, Weak Copyleft and Strong Copyleft Licence Families
- Compare MIT, BSD and Apache 2.0 obligations, including the Apache patent grant and its effect on downstream users.
- Explain the file-level and library-linking triggers that separate LGPL weak copyleft from GPL strong copyleft duties.
- Analyse the AGPL network-use clause and its consequences for software delivered only as a hosted service.
- Identify dual-licensing and commercial licence exception structures used by projects that also sell proprietary terms.
Session 2Distribution Triggers, Modification Duties and Source Disclosure
- Determine what counts as distribution under a given licence, including internal use, SaaS delivery and embedded firmware.
- Draft the corresponding source offer letter and delivery mechanism required when a copyleft trigger is met.
- Assess modification and derivative work tests that decide whether copyleft terms extend to newly written code.
- Document licence obligations against each component in a clearance record before a build is approved for release.
02Scanning, SBOM Production and Compatibility Analysis
2 sessions · 8 points
Session 1Automated Scanning Tools and Software Bill of Materials Generation
- Configure automated scanning tools such as ScanCode, FOSSA or Black Duck against a build pipeline for licence detection.
- Generate a software bill of materials in SPDX or CycloneDX format that lists components, versions and declared licences.
- Reconcile scanner findings against manual review for components with ambiguous or missing licence declarations.
- Maintain a component inventory that updates automatically as dependencies change across product releases.
Session 2Licence Compatibility Matrices and Conflict Resolution
- Build a licence compatibility matrix that flags combinations, such as GPL and proprietary code, requiring escalation.
- Resolve a detected conflict by substitution, isolation through a separate process, or licence exception negotiation.
- Assess copyright notice stacking and attribution file requirements when multiple licensed components ship together.
- Prepare a technical isolation plan that keeps a copyleft component's obligations from spreading to proprietary code.
03Governance Programme Design and Approval Workflows
2 sessions · 8 points
Session 1Clearance Workflows, Approval Gates and Engineering Policy
- Design an intake form and clearance request workflow engineers use before adding a new open source dependency.
- Set risk-based approval gates that route high-risk copyleft requests to legal while auto-approving low-risk permissive ones.
- Draft an internal open source usage policy covering contribution rules for code released back to public projects.
- Build training materials that teach engineers to recognise copyleft triggers during code review, not after release.
Session 2OpenChain Alignment, Audit Records and Incident Response
- Map an open source compliance programme against the OpenChain ISO 5230 conformance requirements.
- Maintain audit-ready records of clearance decisions, scan reports and licence texts for each shipped product.
- Design an incident response process for a compliance failure reported by a customer, auditor or community maintainer.
- Report programme metrics, including scan coverage and clearance turnaround time, to engineering leadership.
04Open Source Due Diligence in Corporate Transactions
2 sessions · 8 points
Session 1Code-Level Due Diligence Ahead of a Merger or Acquisition
- Run a codebase scan of a target company to surface undisclosed copyleft components before signing.
- Draft due diligence questionnaires that request a target's software bill of materials and clearance history.
- Quantify remediation cost and timeline for copyleft exposure discovered during the diligence window.
- Negotiate representations, warranties and indemnities addressing open source compliance in the transaction agreement.
Session 2Post-Acquisition Remediation and Portfolio Harmonisation
- Prioritise a remediation backlog that separates release-blocking copyleft issues from lower-risk attribution gaps.
- Harmonise open source policies across an acquired engineering team without halting an active release schedule.
- Consolidate scanning tools and component inventories across merged codebases into a single governance system.
- Report residual open source risk to the acquiring board alongside a costed remediation plan.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
