Services›Code›Licenses & SBOM
Know every component. Stay compliant.

Licenses & SBOM

Automatically generate accurate Software Bill of Materials and detect risky open-source licenses before they create legal or security problems.
Licenses & SBOM
Hidden open-source risks
The problem

You can’t protect what you can’t see.

Modern applications rely on hundreds of open-source packages. Without a clear inventory, teams risk license violations, supply-chain attacks, and compliance failures. Most only discover these issues after a legal notice or security incident.
One operating picture

One inventory. Full transparency.

MadStack continuously builds accurate SBOMs and checks every license so your team stays compliant and secure — without slowing development.
Generate accurate SBOMs

Generate accurate SBOMs

Automatically create CycloneDX and SPDX SBOMs for every project and build — ready for audits and compliance.

Detect license risks

Detect license risks

Flag copyleft, restrictive, and unknown licenses that could create legal exposure or block distribution.

Track every dependency

Track every dependency

Get complete visibility into direct and transitive packages across npm, Maven, PyPI, Go, and more.

✦ What gets detected

Findings, ranked by what matters.

Prioritized by license risk, usage context, and potential legal or security impact — so you act on the most important issues first.

◈

Critical

Strong copyleft licenses (GPL, AGPL) used in proprietary code without proper compliance.

◷ Review & remediate
!

High

Restrictive or dual-licensed packages that may limit commercial use or redistribution.

◷ Legal review needed
↗

Medium

Unknown, custom, or poorly documented licenses that need clarification and tracking.

◷ Investigate & document
Sample finding

Evidence your team can act on.

Live output from the MadStack scanner — exact package, license type, and recommended action.

Package
lodash@4.17.21
License
MIT (Approved)
package-lock.json
{
"package": "lodash",
"version": "4.17.21",
"license": "MIT",
"risk_level": "Low",
"action": "Approved – no action needed"
}
FAQ illustration
FAQ

Questions, answered.

A Software Bill of Materials (SBOM) is a complete inventory of all components in your software. It helps with security, license compliance, and meeting regulatory requirements from the US Executive Order, EU regulations, and more.

We generate both CycloneDX and SPDX formats — the two most widely accepted industry standards, fully compatible with most security and compliance tools.

Yes. You can define allowed, restricted, and blocked licenses. MadStack will automatically flag any package that violates your policy during scans and in pull requests.

More in Code

Explore More Security Topics

Dive deeper into specific areas of application security, from source code analysis to dependency risks and beyond.
Dependencies (SCA)

Dependencies (SCA)

Detect vulnerable open-source packages and fix them before they reach production.

Secret Detection

Secret Detection

Find exposed API keys, tokens, and credentials before they leak.

SAST

SAST

Find and fix security flaws in your source code before they ship.

Ready when you are

Know every component. Stay compliant.

Licenses & SBOM CTA