SBOMs in automotive: A roundtable on open source license compliance & risk
In this session, experts from RunSafe, May Mobility, HARMAN, and The Product Cybersecurity Group explore how accurate SBOMs and early license checks reduce open-source compliance risks in complex automotive software.
The discussion highlights how restrictive licenses can introduce hidden risks and why compliance is critical to safety, reliability, and lifecycle visibility.
What you’ll learn:
- How incomplete or inaccurate SBOMs can hide critical open-source license risks
- Why restrictive licenses like GPL and AGPL can spread through transitive dependencies
- The unique, real-world license compliance challenges in embedded and automotive systems
- How integrating license checks into CI/CD pipelines enables earlier risk detection and resolution
- Why accurate SBOMs are essential for building scalable, reliable license compliance processes