OFICIAL GitHub Blog Gadgets · Jun 30, 2026

How GitHub maintains compliance for open source dependencies

In brief · 4 sentences
Based on GitHub Blog · Jun 30, 2026

GitHub’s Open Source Program Office now uses a new license compliance feature to manage open source dependencies at scale, helping organizations enforce license policies directly in pull requests.

How GitHub maintains compliance for open source dependencies
GitHub Blog — GitHub
Key points
·
Main topic: the way GitHub maintains compliance for open source dependencies.
·
Category affected: gadgets and hardware.
·
Figures mentioned: 2.0, 3, 2004.
·
The information comes from an official source.
·
The next step is to watch availability, pricing and real-world impact.

The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.

GitHub’s Open Source Program Office (OSPO) has adopted a new license compliance feature within GitHub Advanced Security to manage thousands of open source dependencies across its platform. The tool scans pull requests for new dependencies, checking their licenses against predefined policies to ensure compliance with organizational requirements. This approach replaces manual reviews and third-party software, reducing legal and operational risks associated with noncompliance. The feature supports both permissive licenses like MIT and Apache 2.0 and allows customization to block or permit specific licenses based on business needs.

The OSPO initially tested the feature in 'Evaluate' mode, generating non-blocking annotations in pull requests to familiarize developers with the workflow without disrupting productivity. After a month, the team transitioned to active enforcement, focusing on dependencies with unusual, missing, or disallowed licenses. License checks are triggered by rulesets that target repositories via a custom property, enabling or disabling enforcement as needed. Developers receive alerts for problematic packages and can either remove the dependency or request an exception for review by the policy team.

The license policy team, composed of OSPO members and engineers, reviews exception requests with a response time typically within hours. Approvals can be granted at the enterprise or repository level, depending on the license or package. For example, permissive licenses are often approved enterprise-wide, while commercial licenses may be restricted to specific repositories. The tool also supports wildcard exceptions for internal packages, streamlining approvals for related dependencies. Emergency overrides are available for critical fixes, though their use has been rare.

GitHub Enterprise Cloud customers with an active GitHub Advanced Security license can now access the License Compliance feature. The OSPO emphasizes the importance of license compliance in managing software supply chain risks, noting that informed dependency choices prevent costly legal issues and rewrites. The team has provided internal documentation and training to support developers in adopting the tool, which has been in public preview since its initial adoption.

Original source → Deals on Clipraptor.com →
Extracted signals · detected in the story
ExploreOpen Source Program OfficeEveryAndAt GitHubHereOSPOGitHub License ComplianceNearlyThose2.03200414,00045 days