Skip to main content

license-radar

PyPI version Python versions License: MIT

Scan a project's dependency manifests (requirements.txt, pyproject.toml, setup.cfg, Pipfile, package.json) for license compliance risk before a GPL/AGPL dependency turns into a legal problem for a closed-source product.

Why

Pulling in a GPL- or AGPL-licensed dependency can obligate a company to open its own source, or expose it to a lawsuit — and it usually happens by accident, several dependency layers deep. Existing SCA/security scanners focus on vulnerabilities; license risk is often an afterthought bolted onto an expensive enterprise product. This is a small, focused tool that does just the license check, fast, in CI.

Install

pip install license-radar

Usage

license-radar scan .                 # scan a directory tree (recurses into subprojects)
license-radar scan requirements.txt   # scan a single manifest
license-radar scan . --online         # also query PyPI/npm for packages not in the local DB
license-radar scan . --json           # machine-readable output for CI
license-radar scan . --policy policy.json

Directory scans recurse into subdirectories, so monorepos with manifests in nested subprojects (e.g. services/api/requirements.txt, frontend/package.json) are covered in a single run. Vendored and environment directories (node_modules, .venv, vendor, dist, VCS/cache dirs, …) are skipped so the scan reflects what the project itself declares, not the manifests bundled inside its dependencies.

Within each manifest, every section that declares the project's own dependencies is scanned — not just the primary one. For pyproject.toml that includes PEP 621 [project.optional-dependencies] extras and Poetry [tool.poetry.group.*.dependencies] groups; for legacy setup.cfg it includes [options] install_requires and [options.extras_require]; for Pipenv Pipfile it includes [packages] and [dev-packages]; for package.json it includes optionalDependencies and peerDependencies. A copyleft dependency hidden in a test/docs extra or an optional group is exactly the kind of accidental exposure this tool exists to catch.

Requirements files that pull in other files with pip's -r other.txt / --requirement other.txt directive are followed (resolved relative to the including file, with cycle guarding), so a dependency declared only in an included file — e.g. a thin requirements.txt that does -r prod.txt — is scanned too. -c/--constraint files only pin versions of already-required packages, so they are not followed.

Exit code is 1 if any dependency violates the policy (useful as a CI gate), 0 otherwise.

pre-commit

This repo is a pre-commit hook source. Add to a project's .pre-commit-config.yaml:

repos:
  - repo: https://github.com/Hiro-012/claude-
    rev: <commit SHA of a published license-radar version>
    hooks:
      - id: license-radar

(This repo doesn't tag releases yet — pin a commit SHA from the history of pyproject.toml version bumps until versioned tags are published.)

The hook runs on any commit that touches requirements*.txt, pyproject.toml, setup.cfg, Pipfile, or package.json, and blocks the commit if a new dependency violates policy.

Policy

By default, any strong-copyleft (GPL/AGPL/SSPL) or unknown license is a violation. Override with a JSON file:

{
  "fail_at_or_above": "weak-copyleft",
  "treat_unknown_as_violation": false
}

How it classifies

Licenses are normalized to an SPDX id and bucketed into four tiers: permissive < weak-copyleft < strong-copyleft < unknown. See license_radar/classify.py for the exact lists.

Limitations

The offline database (license_radar/license_db.py) is a hand-curated table of ~220 common PyPI/npm packages (each entry verified against the live registry JSON API), not a registry mirror — use --online for full coverage against live PyPI/npm metadata (adds a network dependency and is not covered by the deterministic test suite).

Because the offline table is keyed by package name only, a package whose license changed across its version history cannot be pinned to a single correct value. Such packages are deliberately left out of the table and reported as unknown (flagged for review) rather than guessed — for example chardet, which is LGPL-2.1-or-later up to 5.2.0 but relicensed to 0BSD in its 6.x/7.x line. Use --online with a pinned version, or check the specific version you depend on, when a dependency is reported this way.

License

MIT

Support

license-radar is built and maintained independently under the HiroCheck name. It's free under the MIT license, its default scan runs entirely on your machine, it sends no telemetry, and no paid tier gates the core check.

If it caught a license problem for you — or you'd just like to see the offline database and manifest coverage keep growing — a one-off contribution funds the time that goes into it:

https://buy.stripe.com/bJeeVe2te0U16Ln1yudMI00

Not in a position to chip in? Starring the repo, or opening an issue when the database gets a package's license wrong, helps just as much and costs nothing.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

license_radar-0.1.10.tar.gz (20.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

license_radar-0.1.10-py3-none-any.whl (15.9 kB view details)

Uploaded Python 3

File details

Details for the file license_radar-0.1.10.tar.gz.

File metadata

  • Download URL: license_radar-0.1.10.tar.gz
  • Upload date:
  • Size: 20.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.13

File hashes

Hashes for license_radar-0.1.10.tar.gz
Algorithm Hash digest
SHA256 c3860e4f3c7008ef43d2cb9b1bd9b3593b9733a446b6b4184466bf5c45d34cdb
MD5 f4e589ae5b675d4352a86ad0d45a222b
BLAKE2b-256 70ab3ca71550045492751eabe784b24c70e1c9db9940cbde8e256f6df7e7c1c1

See more details on using hashes here.

File details

Details for the file license_radar-0.1.10-py3-none-any.whl.

File metadata

  • Download URL: license_radar-0.1.10-py3-none-any.whl
  • Upload date:
  • Size: 15.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.13

File hashes

Hashes for license_radar-0.1.10-py3-none-any.whl
Algorithm Hash digest
SHA256 031aef91abc74d11534d0425ca1995c83c9df37033aca4cf410196676d337df9
MD5 58724c000c5e185335513c18b7898c2e
BLAKE2b-256 1c54cb80ebd4b185648c964f3ca8294f7c14395045c55dcbcd999fb17a8b0814

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page