Permissive scanner components
Trivy, Syft, and Prowler are tracked as Apache-2.0 components. Preserve license text, copyright notices, and NOTICE files when redistributing scanner images.
Scanner Operations
BlackShield keeps scanner support broad while making the customer-facing default path conservative: use bundled safe defaults, keep optional tools explicit, and preserve third-party notices.
Trivy, Syft, and Prowler are tracked as Apache-2.0 components. Preserve license text, copyright notices, and NOTICE files when redistributing scanner images.
Semgrep CE is LGPL-2.1; OSSEC and Wazuh are GPLv2. BlackShield treats them as separate tools or alert producers and keeps customer-facing defaults explicit.
Scanner rules, vulnerability feeds, and compliance benchmark content can carry terms separate from scanner code. Use local/customer-owned Semgrep rules and avoid implying third-party certification.
Customers remain responsible for authorizing scan targets, approving scanner installation choices inside their environments, and validating third-party license obligations for their own redistribution model.
BlackShield normalizes scanner output into tenant findings. It does not grant trademark rights or imply endorsement by scanner vendors, cloud providers, CIS, MITRE, NIST, or other framework owners.