Skip to main content

license-audit

CI PyPI Python versions License

Analyze dependency licenses for Python projects.

license-audit tells you what license your project can use, flags incompatible combinations, and generates compliance documents suitable for CI gating.

Features

  • License detection across the full transitive tree, from PEP 639 metadata, the legacy License field, trove classifiers, and user overrides.
  • Pairwise compatibility checking against the OSADL compatibility matrix (~120 licenses).
  • Outbound license recommendations ranked by permissiveness.
  • Compliance reports as Markdown, JSON, or third-party-notices.
  • CI exit codes that distinguish policy violations from undetected licenses.
  • Reads the licenses straight from your installed environment: provision it however you like (uv, Poetry, pip), then point license-audit at it.

Installation

pip install license-audit

Or with uv:

uv add license-audit --dev

Quickstart

Provision your dependencies first, then run license-audit inside that environment:

uv sync
uv run license-audit analyze

Or point it at an existing virtualenv:

license-audit --target .venv analyze
───────────────────── License Analysis: my-project ─────────────────────
Source: /path/to/my-project/.venv

                         Dependency Licenses
┏━━━━━━━━━━┳━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━━━━━━┳━━━━━━━━┳━━━━━━━━━━┓
┃ Package  ┃ Version ┃ License      ┃ Category   ┃ Source ┃ Parent   ┃
┡━━━━━━━━━━╇━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━━━━━━╇━━━━━━━━╇━━━━━━━━━━┩
│ click    │ 8.3.1   │ BSD-3-Clause │ permissive │ pep639 │ (direct) │
│ pydantic │ 2.12.5  │ MIT          │ permissive │ pep639 │ (direct) │
│ rich     │ 14.3.0  │ MIT          │ permissive │ pep639 │ (direct) │
└──────────┴─────────┴──────────────┴────────────┴────────┴──────────┘

Recommended Outbound Licenses (most -> least permissive):
  -> MIT
     Apache-2.0
     BSD-2-Clause
     BSD-3-Clause
     ISC
  ... and 111 more

──────────────────────────────── Summary ───────────────────────────────
  Total dependencies: 3
  Unknown licenses:   0
  Copyleft licenses:  0
  Policy check:       PASSED

Commands

Command Purpose
analyze Per-package analysis in the terminal, or as JSON with --format json
check CI policy gate with distinct exit codes
report Compliance documents: Markdown, JSON, or third-party notices
recommend Outbound license recommendation with guidance
refresh Re-download the OSADL compatibility data

See the commands reference for details.

CI quickstart

Add to your pipeline to gate on license policy:

jobs:
  license-check:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: astral-sh/setup-uv@v5
      - run: uv sync --locked
      - run: uv run license-audit check

Exit codes:

Code Meaning
0 All dependencies pass the policy
1 Policy violation (incompatible pairs, denied licenses, or category exceeded), or the check could not run
2 Unknown licenses detected and no other violation (when fail-on-unknown = true)

For GitLab, pre-commit, handling unknowns, and the new-dependency workflow, see the CI integration guide.

Configuration

[tool.license-audit]
fail-on-unknown = true
policy = "permissive"  # permissive | weak-copyleft | strong-copyleft | network-copyleft
allowed-licenses = ["MIT", "Apache-2.0", "BSD-3-Clause"]
denied-licenses = ["GPL-3.0-only"]
target = ".venv"  # optional; defaults to ./.venv, else the active environment

[tool.license-audit.overrides]
some-internal-package = "MIT"
dual-licensed-pkg = "Apache-2.0 OR MIT"

[tool.license-audit.license-classifications]
"CNRI-Python" = "permissive"  # your judgement for licenses OSADL doesn't cover

[tool.license-audit.ignored-packages]
pandas-stubs = "Stubs only, not redistributed"

Full reference: user guide -> configuration.

Documentation

Full documentation lives at https://dgeragh.github.io/license-audit:

License

MIT. See LICENSE.

This project bundles data from the OSADL Open Source License Obligations Checklists project, licensed under CC-BY-4.0. See THIRD_PARTY_NOTICES.md for full attribution.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

license_audit-0.14.0.tar.gz (177.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

license_audit-0.14.0-py3-none-any.whl (61.4 kB view details)

Uploaded Python 3

File details

Details for the file license_audit-0.14.0.tar.gz.

File metadata

  • Download URL: license_audit-0.14.0.tar.gz
  • Upload date:
  • Size: 177.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for license_audit-0.14.0.tar.gz
Algorithm Hash digest
SHA256 972cab807315f0544cf9bd9a959a01ebe5688df89de7467fbe91b6c366e6c85d
MD5 9361a1f30e304678c05fec4162e2598d
BLAKE2b-256 e324d04f0941e532154cd89e1d198646c030144b36d355457aff680e9378cc9c

See more details on using hashes here.

Provenance

The following attestation bundles were made for license_audit-0.14.0.tar.gz:

Publisher: release.yml on dgeragh/license-audit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file license_audit-0.14.0-py3-none-any.whl.

File metadata

  • Download URL: license_audit-0.14.0-py3-none-any.whl
  • Upload date:
  • Size: 61.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for license_audit-0.14.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ec3c037b7452c08535f7d3260e7a365289383dd5297e093c52eac19ceaed1028
MD5 aa296d693f6030f847508040a7460a6f
BLAKE2b-256 ade7f2000fd67ca21ff357f680a3c6187de6af645bc02460159e2d61e7255d48

See more details on using hashes here.

Provenance

The following attestation bundles were made for license_audit-0.14.0-py3-none-any.whl:

Publisher: release.yml on dgeragh/license-audit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.14.0 This release

2 files

0.13.0

2 files

0.12.3

2 files

0.12.2

2 files

0.12.1

2 files

0.12.0

2 files

0.11.0

2 files

0.10.0

2 files

0.9.0

2 files

0.8.0

2 files

0.7.0

2 files

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

0.2.0

2 files

0.1.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page