Open Source License Compliance
Open Source License Compliance. The Contractor shall maintain a comprehensive inventory of all open source software components incorporated into or distributed with the Deliverables, including the name, version, and applicable license for each component. The Contractor represents and warrants that: (a) all open source components used in the Deliverables are identified in the Software Bill of Materials (SBOM) provided to the Client; (b) all open source components are used in compliance with their respective license terms; (c) no open source component is incorporated in a manner that would require the Client's proprietary software to be disclosed or distributed under an open source license (including any "copyleft" or "viral" license obligation such as GPL, LGPL, or AGPL) unless expressly approved in writing by the Client in advance; (d) the Contractor has conducted due diligence, including automated scanning with commercially available tools, to identify all open source components and their license obligations; and (e) the Contractor shall promptly notify the Client of any newly discovered open source components or license obligations. The Contractor shall indemnify the Client against any claims arising from the Contractor's failure to comply with open source license obligations.