SourceTrust turns the dependency list you already have into a reviewed, public compliance page: every open-source package you ship, its license, and what you did about each obligation.
Almost every software product is built on open-source packages, and each license asks for something back: keep the copyright notice, include the license text, or share your changes. When a customer's procurement or legal team reviews a vendor, they ask for proof that this is handled and kept current.
I built SourceTrust to make that proof simple to produce and simple to read. You import the dependency file you already have (lockfiles for JavaScript, Python, Java, Go, Rust, .NET, Ruby, PHP, Swift and Dart, or a CycloneDX or SPDX SBOM). SourceTrust lists every package with its license and explains in plain language what that license asks of you. You review each item, then publish a branded public attestation page at your own URL or custom domain, readable in a few minutes with no login. Connect a GitHub repository and imports run automatically, so the page stays current when you ship.
Exports in CycloneDX, SPDX, NOTICE, CSV, JSON, HTML and PDF fit the questionnaires and vendor portals your customers use. Creating projects, importing and reviewing is free, eligible public GitHub repositories can publish their page for $0, and paid plans are $29 per project per month or $299 per year with no per-user fees.
It gives you an operational record you can share, not legal advice. The legal interpretation stays with you. Happy to answer questions about formats or the review flow.
AM