GitHub's Open Source Program Office (OSPO) shares how they use the new GitHub License Compliance feature (part of GitHub Advanced Security) to manage open source dependency licenses at scale. The post covers their migration from internal tools, how they configured rulesets in 'Evaluate' then 'Active' mode, how the policy review team triages exception requests, and how they handle emergency overrides. Key practices include enterprise-level vs. repository-level license exceptions, wildcard package matching, and developer training to make compliance frictionless.
Table of contents
Managing the open source license compliance processSetting up for policy successHow GitHub license compliance worksA day in the life of the license policy teamMaking it easy for developersWrapping upTags:Written by27 Impressions