@joshbressers excellent topic, rarely discussed! In this area there is a point of junction between OSS licenses compliance and cyber: the SBOM and source code distribution is a recipe starting point for attack (at least in my embedded ecosystem, e.g. a kernel).