Skip to main content

Fast license auditor for uv projects - Extract and analyze license information with uv.lock integration

Project description

py-license-auditor

Crates.io PyPI License

The fastest license auditor for uv projects - Built specifically for the modern Python ecosystem.

🎯 uv-First Strategy: This tool is designed exclusively for uv projects. We focus on providing the best possible experience for uv users rather than supporting all package managers.

✨ Why uv + py-license-auditor?

  • 🚀 Built for Speed: Both tools are written in Rust for maximum performance
  • 🎯 uv-Native: Deep integration with uv.lock and uv workflows
  • 🔧 Zero Config: Works out of the box with uv projects
  • Fast Workflow: uv sync && py-license-auditor - that's it!

🚀 Installation

For uv Users (Recommended)

# Install as a uv tool
uv tool install py-license-auditor

# Use in any uv project
cd my-uv-project
uv tool run py-license-auditor

Manual Installation

Download the binary for your platform from GitHub Releases.

From Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo install --path .

📖 Usage

📚 Quick Start: See QUICKSTART.md for a step-by-step guide

Quick Start

# Auto-detect .venv in current directory
py-license-auditor

# Specify site-packages directory
py-license-auditor --path /path/to/site-packages

# Save to file
py-license-auditor --output licenses.json

Output Formats

# JSON (default)
py-license-auditor --format json

# TOML
py-license-auditor --format toml

# CSV for spreadsheets
py-license-auditor --format csv

Advanced Options

# Include packages without license info
py-license-auditor --include-unknown

# Combine options
py-license-auditor --format csv --output report.csv --include-unknown

License Violation Detection

# Use built-in policies (no setup required)
py-license-auditor --policy corporate --check-violations
py-license-auditor --policy permissive --check-violations  
py-license-auditor --policy strict --check-violations

# Use custom policy file
py-license-auditor --policy-file policy.toml --check-violations

# Fail build on forbidden licenses (for CI/CD)
py-license-auditor --policy corporate --check-violations --fail-on-violations

# Generate compliance report with violations
py-license-auditor --policy strict --check-violations --output compliance.json

📊 Output Example

JSON Format

{
  "packages": [
    {
      "name": "requests",
      "version": "2.31.0",
      "license": "Apache-2.0",
      "license_classifiers": [
        "License :: OSI Approved :: Apache Software License"
      ],
      "metadata_source": "METADATA"
    }
  ],
  "summary": {
    "total_packages": 50,
    "with_license": 45,
    "without_license": 5,
    "license_types": {
      "osi_approved": {
        "MIT": 20,
        "Apache-2.0": 15,
        "BSD": 8
      },
      "non_osi": {
        "MIT License": 2
      }
    }
  },
  "violations": {
    "total": 2,
    "errors": 1,
    "warnings": 1,
    "details": [
      {
        "package_name": "some-gpl-lib",
        "package_version": "2.1.0",
        "license": "GPL-3.0",
        "violation_level": "Forbidden",
        "matched_rule": "exact: GPL-3.0",
        "message": "License 'GPL-3.0' is forbidden by policy"
      }
    ]
  }
    }
  }
}

CSV Format

name,version,license,license_classifiers,metadata_source
requests,2.31.0,Apache-2.0,"License :: OSI Approved :: Apache Software License",METADATA
click,8.1.7,BSD-3-Clause,"License :: OSI Approved :: BSD License",METADATA

🎛️ Policy Configuration

Built-in Policies

Three ready-to-use policies are included:

# Corporate: Conservative policy for proprietary software
py-license-auditor --policy corporate --check-violations

# Permissive: Balanced policy for open source projects  
py-license-auditor --policy permissive --check-violations

# Strict: Very restrictive - only MIT, Apache-2.0, BSD-3-Clause
py-license-auditor --policy strict --check-violations
Policy Allowed Forbidden Review Required
Corporate MIT, Apache-2.0, BSD-* GPL-, AGPL-, LGPL-* MPL-2.0
Permissive MIT, Apache-2.0, BSD-*, MPL-2.0 None GPL-, AGPL-
Strict MIT, Apache-2.0, BSD-3-Clause GPL-, AGPL-, LGPL-*, MPL-2.0 ISC, BSD-*

Custom Policy File Format

Create a policy.toml file to define your license compliance rules:

name = "Corporate License Policy"
description = "License policy for proprietary software development"

[allowed_licenses]
exact = ["MIT", "Apache-2.0", "BSD-3-Clause", "ISC"]
patterns = ["BSD-*"]

[forbidden_licenses]
exact = ["GPL-3.0", "AGPL-3.0"]
patterns = ["GPL-*", "AGPL-*"]

[review_required]
exact = ["MPL-2.0", "LGPL-2.1"]
patterns = ["LGPL-*"]

[[exceptions]]
name = "legacy-package"
version = "1.0.0"
reason = "Approved by legal team for legacy compatibility"

Policy Rules

  • allowed_licenses: Licenses that are automatically approved
  • forbidden_licenses: Licenses that cause build failures
  • review_required: Licenses that need manual review (warnings)
  • exceptions: Package-specific overrides with justification

Pattern Matching

Use glob patterns for flexible license matching:

  • "GPL-*" matches GPL-2.0, GPL-3.0, etc.
  • "BSD-*" matches BSD-2-Clause, BSD-3-Clause, etc.

🎯 Use Cases

License Compliance

Generate comprehensive reports for legal review and compliance auditing.

# Generate compliance report
py-license-auditor --format json --output compliance-report.json

CI/CD Integration

Automate license checking in your deployment pipeline.

# GitHub Actions example
- name: Check license compliance
  run: |
    py-license-auditor --policy corporate --check-violations --fail-on-violations
    
- name: Generate license report
  run: |
    py-license-auditor --format json --output license-report.json
# Basic license extraction
py-license-auditor --format json > licenses.json

Dependency Auditing

Understand your project's license obligations and risks.

# Focus on non-OSI licenses that need manual review
py-license-auditor --format json | jq '.summary.license_types.non_osi'

🔍 License Categories

The tool categorizes licenses into two groups:

  • OSI Approved: Licenses approved by the Open Source Initiative (legally vetted)
  • Non-OSI: Custom licenses, proprietary licenses, or unrecognized formats

This helps you quickly identify which licenses need manual legal review.

🛠️ Development

Building from Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo build --release

Running Tests

cargo test

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

📄 License

This project is licensed under either of

at your option.

🙏 Acknowledgments

  • Built with Clap for CLI parsing
  • Uses Serde for serialization
  • Inspired by the need for better Python license compliance tools

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_license_auditor-0.3.3.tar.gz (2.5 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_license_auditor-0.3.3-py3-none-any.whl (2.5 MB view details)

Uploaded Python 3

File details

Details for the file py_license_auditor-0.3.3.tar.gz.

File metadata

  • Download URL: py_license_auditor-0.3.3.tar.gz
  • Upload date:
  • Size: 2.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for py_license_auditor-0.3.3.tar.gz
Algorithm Hash digest
SHA256 3c0067ab94a4ce12d49fc2cec5c334bd379e855bc730e318f2752a5fdc306c06
MD5 5ae2a75d29834dd57b854006b3b8bc85
BLAKE2b-256 4ebf3390b826eab9490e5e4c05aaf2aff9f69b7de7a9b5e9d7328c50303dea71

See more details on using hashes here.

File details

Details for the file py_license_auditor-0.3.3-py3-none-any.whl.

File metadata

File hashes

Hashes for py_license_auditor-0.3.3-py3-none-any.whl
Algorithm Hash digest
SHA256 df2f21aae8d2cd21f2a42300d5aff690e95060855bd8779a82df0efb072293b6
MD5 64ed52e53ae5c177d3e407fb7d217b9b
BLAKE2b-256 957e6ad5be500b5234f8ab5a91c4a1b173df513fe993da00e34c25c5782ec3d4

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page