For the complete documentation index, see llms.txt. This page is also available as Markdown.

Open Source and Third-Party Components

Purpose

Open-source and third-party components can accelerate delivery but must be managed carefully.

Required Checks

Before use, check:

  • licence type

  • commercial restrictions

  • attribution requirements

  • security vulnerabilities

  • maintenance status

  • compatibility with customer requirements

  • export or regulatory restrictions

  • support model

  • IP contamination risk

Approved Use

A component may be used where:

  • the licence is acceptable

  • security risk is acceptable

  • the component is actively maintained or risk-managed

  • the customer permits its use

  • the component does not conflict with the project IP model

Records

Projects should record:

  • component name

  • version

  • licence

  • source

  • purpose

  • approval status

  • known vulnerabilities

  • mitigation

Last updated

Was this helpful?