YENRA — OPEN-SOURCE RELEASE REVIEW Companion: https://yenra.com/open-source-law/ Evidence organizer, not legal advice or a compatibility verdict. Product / exact release / artifact hash / owner / review date: Delivery paths (installer, browser assets, container, device, source, SaaS): Who receives copies? Who interacts with modified services remotely? Contractor, affiliate or customer arrangements needing review: Repeat for EACH component, including bundled and transitive dependencies: Name / version or commit / source URL / checksum: Exact license files and locations: SPDX identifier or expression / exception / alternative selected: Evidence for that grant (not only a scanner label): Modifications and dates / copied or vendored portions: Integration (library, plugin, executable, browser asset, remote service): Distribution and remote-use scenarios: Required license and copyright notices: Applicable NOTICE or modification notices: Corresponding-source obligation and defined scope, if applicable: Chosen permitted delivery method / recipients / duration / owner: Source bundle or access URL matching this release: Build/installation material required by applicable terms: Compatibility or scope questions / qualified review outcome: Evidence attached / approver / unresolved blocker: Release verification: Actual installer/image/archive inspected for notices: Recipient can obtain required source and instructions: Source and binary identities reconciled: Retention and source-access fulfillment owner: Non-code assets (fonts/images/data/docs) reviewed separately: Automated scanner findings checked against original material: Unresolved items prevent release until a supported path is established.