Free code.
Binding licenses.

Free and Open Source Software (FOSS) is used extensively in software development — yet even this free code comes with license terms that must be observed. We support companies in avoiding civil claims and criminal liability arising from license and copyright infringements.

Lead counsel: Yvonne Roßmann · deputy lead: Lisa Breunung.

Illustration for FOSS compliance: software

What we do.

01

Compliance processes

Guiding the establishment of effective open-source compliance processes — from kick-off through process design to lasting integration into development and procurement workflows. With an eye to scalability, auditability and the reality of your engineering teams.

02

License evaluation

Assessment of the open-source licenses in use — from permissive models (MIT, BSD, Apache 2.0) through weak copyleft (LGPL, MPL) to strict copyleft (GPL, AGPL). We name the risks in each component before they become an issue in an audit or a dispute.

03

License-compliant use

Ensuring technically and legally license-compliant use — avoiding viral copyleft effects, resolving license incompatibilities, structuring combined distributions to avoid license conflicts. So that one forgotten clause does not make the entire product open source.

04

Product materials

Producing license-compliant product materials — notice files, attribution lists, a software bill of materials (SBOM) in SPDX or CycloneDX format, source code disclosure packages for copyleft components. So that every delivery survives the audit.

What is at stake

One forgotten license clause
can make an entire product
open source.

How we work.

[ Format and focus areas ]
OpenChain
Partner

OpenChain Project: ISO/IEC 5230 as the compliance standard

JUN Legal GmbH is a partner of the OpenChain Project — the initiative backed by the Linux Foundation that, with ISO/IEC 5230:2020, created an international standard for open-source compliance in companies.

We support companies in building structures that conform to OpenChain, in gap analyses against the standard and in preparing for self-certification or third-party certification — starting with the six core requirements (program, staff, competence, materials, verification, conformance).

Hands-on
Engineering teams

Technical support for non-legal teams

Open-source compliance is not only a legal issue; it is also an engineering issue. Legal processes have to fit the way software is actually built. We work directly with your development, DevOps and product teams: on component selection, on build pipeline integration and on defining acceptable license stacks for each product line.

To that end, we set up semi-automated legal checks — license scanners (FOSSology, ScanCode, ORT), SBOM generators and policy engines, integrated into CI/CD pipelines. License issues are identified before they become release blockers.

Training
In-house or remote

Training for development, product and legal teams

Tailored formats for everyone who works with open source — from a license fundamentals module for mixed teams (What is copyleft? When do I become a distributor?) to deep dives into license combinations, patent clauses and SBOM standards. Also available as a kick-off workshop at the start of a compliance initiative.

Cross-reference
AI code

When AI meets FOSS

When LLM tools may incorporate paraphrased open-source code into proprietary products, two fields of law come together — open-source license law and copyright questions around AI-generated code. Read more in our practice area AI & legal tech.

Book
Standard reference

Praxishandbuch Open Source

Client experience translated into a standard reference work: the practitioner's handbook on open-source compliance, edited and written by Christian Galetzka, Chan-jo Jun and Yvonne Roßmann — all of JUN Legal GmbH. Published (in German) in the “Kommunikation & Recht” series by Fachmedien Recht und Wirtschaft (Frankfurt), 415 pages.

View in the Beck-Shop →