Open source · Security & Privacy

License Obligation Scanner

Map dependency licenses to obligations, notices and distribution boundaries.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Read an inventory of dependencies and bundled source, open the licence, NOTICE and attribution files it points at, and emit a human review queue: for each component, either the obligation categories its licence raises -- with the phrase from the licence text that identified it -- or the reason the licence could not be resolved at all.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

npm run example                                                   # the clean tree, exits 0
node bin/license-obligation-scanner.mjs --inventory examples/broken/inventory.json   # exits 2

Read the result

examples/clean/ resolves four bundled components from their own licence texts with the notices they require. examples/broken/ exercises each way the tool refuses to conclude: a missing licence file, a dual expression, a bespoke licence, a bundled Apache component with no NOTICE, a copyleft component, a declaration its own text contradicts, and a component absent from the attribution file. The licence files in both trees are abbreviated copies carrying the marker phrases; a real distribution ships the complete texts.

Where this check stops

Bounds are part of the contract. Exceeding one is a named finding and an incomplete report, never a silent truncation: --max-bytes (1048576), --max-components (500), --max-files (1500), --max-file-bytes (262144), --max-depth (12), --max-millis (5000). If the time budget is spent, every entry is returned to the queue unresolved -- a review that did not finish concludes nothing.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.