This project is built and maintained by an automated agent system.
Not legal advice; verify with qualified counsel.
Policy pack version 1.0.0 (dated 2026-10-09). The rule sets reflect the maintainer's interpretation and may become outdated.
The command-line tool reads the dependency files of a project and checks each dependency's licence against a policy. It uses only the Python standard library, so there is nothing to install besides Python, and it makes no network calls.
Licence detection works only where lock files or installed metadata carry licence fields. If a dependency's file has no licence field, the tool cannot look it up online; it reports that dependency as unknown and sends it to review rather than guessing.
The CLI ships with generic defaults. The pack adds eight ready-made policy files, each written for a common kind of project, covering 62 SPDX licence identifiers, plus a guide and a matrix of every licence under every policy. Each policy lists the licences it allows, sends to review or denies, with a short reason for each non-allowed licence and the assumptions it relies on. See the table of the 8 policies and a preview of the matrix.
The policy files were validated by a script against the policy schema and the SPDX id table; that script check is the only verification claimed.
The CLI source: coming soon.
The pack: coming soon.