SSolarc Labs
Resources/Guide/SBOM Risk Pack

Open-source licence review

SBOM licence review for enterprise procurement

How to turn an existing CycloneDX or SPDX JSON SBOM into a deterministic licence disposition queue and buyer-ready evidence.

Best fit

Small SaaS vendors entering enterprise procurement, software agencies handing code to clients and due-diligence providers.

What the focused offer actually does

Turn one existing CycloneDX or SPDX JSON SBOM into a deterministic open-source licence review queue and buyer-ready evidence pack.

Current commercial scope: US$500 one-time

Practical workflow

Four checks before you add more software.

The useful unit is a bounded operating workflow: explicit input, evidence, human judgement where needed, and a visible handoff.

01

Start from an existing customer-provided CycloneDX or SPDX JSON SBOM rather than cloning and executing arbitrary code.

02

Normalise components deterministically before applying licence policy.

03

Keep unknown or ambiguous licences in a needs-review state for human disposition.

04

Export the input/tool provenance with the result; licence review is not legal clearance.

Boundary

Do not turn a useful check into an unsupported claim.

Not a legal opinion or licence clearance
Not a vulnerability scanner or CVE-coverage claim
No arbitrary remote clone/build, uploaded-code execution or CRA certification