Best for
- Due diligence, enterprise deals and the questionnaire that asks about licences
- Products shipping binaries or embedding code, where copyleft terms bite differently
- Replacing 'probably all fine' with a documented answer
What you give it
- Your lockfiles and how you ship (service, distributed binary, embedded, SDK)
What you get back
- The inventory: every dependency's licence, direct and transitive, with the unknowns flagged for resolution
- Findings against YOUR shipping model: what obliges what, where conflicts live, ranked by real consequence
- The going-forward policy: allowed, review-required and refused licence classes, wired as a pipeline check
How it works
- Scans the full tree from lockfiles — transitive dependencies carry licences too, and they arrived uninvited.
- Evaluates against your actual shipping model: a server-side service, a distributed binary and an embedded SDK have different obligations from the same licence.
- Separates real obligations (attribution bundles, source offers, notice files) from folklore, and prices the options where conflicts exist.
- Encodes the policy as a pipeline check so the audit does not rot: new licences outside the allowed set fail loudly at addition time.
Example
You: The acquirer's due diligence asks for our licence position. We have never looked.
Result: The audit of 1,241 packages (62 direct): mostly permissive, obligations documented (the attribution bundle your distributed app was supposed to ship — now generated at build); two real findings — a copyleft-licensed library statically linked into the shipped binary (options priced: the maintained permissive alternative was a half-day swap) and one package with NO licence at all (author contacted; replaced meanwhile, since no licence means no permission). The policy now gates additions in CI; due diligence got a documented yes.
Limits — please read
- It identifies issues and options by licence class; for genuine legal edge cases it says 'this one needs a lawyer' — specifically, not generally.
- Licence detection from package metadata has gaps (the no-licence, the custom text); those are flagged for human resolution, never guessed.
- Dual-licensed and 'source-available' packages need business decisions; it frames them with the facts.