EPISODE · Nov 13, 2025 · 4 MIN
The Real Risk of License Drift
from Sushi Bytes · host FossID
In this episode of Sushi Bytes, Shinobi and Gen dive into the hidden risk of license drift – when the open source license declared in metadata files like package.json or README doesn’t match the actual licenses embedded in the source code. It’s a common problem with serious consequences, especially in embedded systems or M&A deals. The duo explores why relying on metadata alone can mislead engineering teams and expose organizations to IP risk, and how SCA tools like FossID catch mismatches through file-level inspection – so you don’t ship surprises with your software.
What this episode covers
In this episode of Sushi Bytes, Shinobi and Gen dive into the hidden risk of license drift – when the open source license declared in metadata files like package.json or README doesn’t match the actual licenses embedded in the source code. It’s a common problem with serious consequences, especially in embedded systems or M&A deals. The duo explores why relying on metadata alone can mislead engineering teams and expose organizations to IP risk, and how SCA tools like FossID catch mismatche...
NOW PLAYING
The Real Risk of License Drift
No transcript for this episode yet
Similar Episodes
Jun 25, 2026 ·68m
Jun 25, 2026 ·39m
Jun 19, 2026 ·38m
Jun 12, 2026 ·53m