Open Source and Third-Party Components
Purpose
Open-source and third-party components can accelerate delivery but must be managed carefully.
Required Checks
Before use, check:
licence type
commercial restrictions
attribution requirements
security vulnerabilities
maintenance status
compatibility with customer requirements
export or regulatory restrictions
support model
IP contamination risk
Approved Use
A component may be used where:
the licence is acceptable
security risk is acceptable
the component is actively maintained or risk-managed
the customer permits its use
the component does not conflict with the project IP model
Records
Projects should record:
component name
version
licence
source
purpose
approval status
known vulnerabilities
mitigation
Last updated
Was this helpful?

