|
This certificate confirms that a software project has all direct and transitive dependencies identified, verified for licence compatibility and critical vulnerabilities, documented, and reviewed by the Licence Management Team, without addressing the software’s own licence or compliance artefacts.
It requires your team to internally assess all dependencies and third-party intellectual property, prepare verification material, and provide it to the Licence Management Team for review.
The certificate builds on the Self-Assessed Dependencies Certificate by adding thorough verification, inclusion of transitive dependencies, and submission of evidence.
You may use this document as a checklist template for your project's certification process.
Aligned with Self-Assessed Dependencies Certificate
NOTICE file).Record information on direct dependencies and third-party IP (name, version, licence) in a README, NOTICE, or only in an internal document.
Additional Requirements
See Contact Us for information on how to communicate with the Licence Management Team.
Consider drafting public artefacts based on available templates. These files are reviewed and amended as part of the SLA Service.
README – Optional, but useful to capture basic information about the software early; it is the starting point for documented and licensed software NOTICE – Optional, but required if legal notices or attributions for third-party components are mandated by dependency licencesUpon approval, your project will receive the Verified Dependencies Certificate, visible at certificates.software.geant.org and in the GÉANT Software Catalogue.
Keep dependency, licence, and vulnerability data up to date. Review new or changed dependencies and monitor for newly discovered vulnerabilities or licence conflicts.
You may integrate continuous dependency and licence scanning (e.g. through CI/CD pipelines) to detect issues early and maintain long-term compliance.
The certificate is valid for five years, covering all released versions within that period, provided issues are promptly addressed.
Reassess and submit a renewal request before the five-year validity ends, or sooner if there are significant changes (e.g. component replacement under a different licence, or inclusion of new components).
Further details are available in the Detailed Guide: Verified Dependencies Certificate.