Software built with open source components carries licence obligations that transfer with the code and are examined in every technology transaction.
Permissive licences require attribution and preservation of notices, and impose few other conditions.
Copyleft licences require that derivative works, and in stronger variants works that link to the component, be distributed under the same licence with source made available. Compliance failures here are what create real exposure, because the remedy sought is disclosure of proprietary source.
Network copyleft extends the obligation to software made available as a service, which catches businesses that never distribute anything.
Distribution triggers. Many obligations attach only on distribution, and whether providing software in a container, an appliance or an embedded device constitutes distribution requires analysis.
Policy and tooling. An approved licence list, a review process before a component is introduced, automated scanning in the build pipeline, and a software bill of materials.
Remediation. Replacement of the component, isolation through a process boundary, or compliance with the licence. Each takes engineering time, which is why finding it before a transaction matters.
Diligence. A scan report is now standard in technology acquisitions, and unresolved copyleft findings produce holdbacks.