Knowing and honoring the legal terms of every open-source component you ship.
Every open-source package comes with a license — MIT, Apache-2.0, GPL, and hundreds more — each carrying different obligations. Some require attribution; some require you to open-source derivative work; some are incompatible with each other. Shipping a product without knowing its license graph is legal risk waiting to mature.
Safeguard identifies the license of every component, maps the obligations, and flags conflicts, so legal clarity is part of the same verification pass as security. Each package page on Gold shows its license alongside its vulnerability status.