Skip to main content

Fast license auditor for uv projects - Extract and analyze license information with uv.lock integration

Project description

py-license-auditor

Crates.io PyPI License

The fastest license auditor for uv projects - Built specifically for the modern Python ecosystem.

🎯 uv-First Strategy: This tool is designed exclusively for uv projects. We focus on providing the best possible experience for uv users rather than supporting all package managers.

✨ Why uv + py-license-auditor?

  • 🚀 Built for Speed: Both tools are written in Rust for maximum performance
  • 🎯 uv-Native: Deep integration with uv.lock and uv workflows
  • 🔧 Zero Config: Works out of the box with uv projects
  • Fast Workflow: uv sync && py-license-auditor - that's it!

🚀 Installation

For uv Users (Recommended)

# Install as a uv tool
uv tool install py-license-auditor

# Use in any uv project
cd my-uv-project
uv tool run py-license-auditor

Manual Installation

Download the binary for your platform from GitHub Releases.

From Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo install --path .

📖 Usage

📚 Quick Start: See QUICKSTART.md for a step-by-step guide

Quick Start

# 1. Setup your uv project
uv init my-project
cd my-project
uv add requests pandas

# 2. Configure license policy (one-time setup)
py-license-auditor --init corporate

# 3. Run license audit
uv sync
py-license-auditor

Configuration Setup

Initialize with Built-in Policies

# For corporate/enterprise projects
py-license-auditor --init corporate

# For personal/open source projects  
py-license-auditor --init personal

# For CI/CD environments (strict)
py-license-auditor --init ci

This creates a [tool.py-license-auditor] section in your pyproject.toml with appropriate settings.

Basic Usage

# Auto-detect .venv in current directory
py-license-auditor

# Specify site-packages directory
py-license-auditor --path /path/to/site-packages

# Save to file
py-license-auditor --output licenses.json

Output Formats

# JSON (default)
py-license-auditor --format json

# Table for terminal viewing
py-license-auditor --format table

# CSV for spreadsheets
py-license-auditor --format csv

Advanced Options

# Include packages without license info
py-license-auditor --include-unknown

# Combine options
py-license-auditor --format csv --output report.csv --include-unknown

# Interactive mode for handling violations
py-license-auditor --interactive

📊 Output Example

JSON Format

{
  "packages": [
    {
      "name": "requests",
      "version": "2.31.0",
      "license": "Apache-2.0",
      "license_classifiers": [
        "License :: OSI Approved :: Apache Software License"
      ],
      "metadata_source": "METADATA"
    }
  ],
  "summary": {
    "total_packages": 50,
    "with_license": 45,
    "without_license": 5,
    "license_types": {
      "osi_approved": {
        "MIT": 20,
        "Apache-2.0": 15,
        "BSD": 8
      },
      "non_osi": {
        "MIT License": 2
      }
    }
  },
  "violations": {
    "total": 2,
    "errors": 1,
    "warnings": 1,
    "details": [
      {
        "package_name": "some-gpl-lib",
        "package_version": "2.1.0",
        "license": "GPL-3.0",
        "violation_level": "Forbidden",
        "matched_rule": "exact: GPL-3.0",
        "message": "License 'GPL-3.0' is forbidden by policy"
      }
    ]
  }
}

CSV Format

name,version,license,license_classifiers,metadata_source
requests,2.31.0,Apache-2.0,"License :: OSI Approved :: Apache Software License",METADATA
click,8.1.7,BSD-3-Clause,"License :: OSI Approved :: BSD License",METADATA

🎛️ Policy Configuration

Built-in Policies

Three ready-to-use policies are included:

# Corporate: Conservative policy for proprietary software
py-license-auditor --init corporate

# Personal: Balanced policy for open source projects  
py-license-auditor --init personal

# CI: Very restrictive - only MIT, Apache-2.0, BSD-3-Clause
py-license-auditor --init ci
Policy Allowed Forbidden Review Required
Corporate MIT, Apache-2.0, BSD-* GPL-, AGPL-, LGPL-* MPL-2.0
Personal MIT, Apache-2.0, BSD-*, MPL-2.0 None GPL-, AGPL-
CI MIT, Apache-2.0, BSD-3-Clause GPL-, AGPL-, MPL-2.0 ISC, BSD-*

Custom Policy Configuration

After running py-license-auditor --init, you can customize the generated configuration in pyproject.toml:

[tool.py-license-auditor]
format = "json"
include_unknown = true
fail_on_violations = true

[tool.py-license-auditor.policy]
name = "Custom License Policy"
description = "Tailored policy for our project"

[tool.py-license-auditor.policy.allowed_licenses]
exact = ["MIT", "Apache-2.0", "BSD-3-Clause", "ISC"]
patterns = ["BSD-*"]

[tool.py-license-auditor.policy.forbidden_licenses]
exact = ["GPL-3.0", "AGPL-3.0"]
patterns = ["GPL-*", "AGPL-*"]

[tool.py-license-auditor.policy.review_required]
exact = ["MPL-2.0"]
patterns = ["LGPL-*"]

[[tool.py-license-auditor.policy.exceptions]]
name = "legacy-package"
version = "1.0.0"
reason = "Approved by legal team for legacy compatibility"

Policy Rules

  • allowed_licenses: Licenses that are automatically approved
  • forbidden_licenses: Licenses that cause build failures
  • review_required: Licenses that need manual review (warnings)
  • exceptions: Package-specific overrides with justification

Pattern Matching

Use glob patterns for flexible license matching:

  • "GPL-*" matches GPL-2.0, GPL-3.0, etc.
  • "BSD-*" matches BSD-2-Clause, BSD-3-Clause, etc.

🎯 Use Cases

License Compliance

Generate comprehensive reports for legal review and compliance auditing.

# Generate compliance report
py-license-auditor --format json --output compliance-report.json

CI/CD Integration

Automate license checking in your deployment pipeline.

# GitHub Actions example
- name: Setup License Policy
  run: py-license-auditor --init corporate
  
- name: License Check  
  run: py-license-auditor
    
- name: Generate License Report
  run: py-license-auditor --format json --output license-report.json

Dependency Auditing

Understand your project's license obligations and risks.

# Focus on potential issues
py-license-auditor --format json

🔍 License Categories

The tool categorizes licenses into two groups:

  • OSI Approved: Licenses approved by the Open Source Initiative (legally vetted)
  • Non-OSI: Custom licenses, proprietary licenses, or unrecognized formats

This helps you quickly identify which licenses need manual legal review.

🛠️ Development

Building from Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo build --release

Running Tests

cargo test

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

📄 License

This project is licensed under either of

at your option.

🙏 Acknowledgments

  • Built with Clap for CLI parsing
  • Uses Serde for serialization
  • Inspired by the need for better Python license compliance tools

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_license_auditor-0.4.0.tar.gz (2.5 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_license_auditor-0.4.0-py3-none-any.whl (2.6 MB view details)

Uploaded Python 3

File details

Details for the file py_license_auditor-0.4.0.tar.gz.

File metadata

  • Download URL: py_license_auditor-0.4.0.tar.gz
  • Upload date:
  • Size: 2.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for py_license_auditor-0.4.0.tar.gz
Algorithm Hash digest
SHA256 1df3e712e5ee34f605fb2797b6fc86ebcc9a822353d6fa87ef35c3816f4b7e81
MD5 45862b77c2f1ecbe03ea969cc23f1f6c
BLAKE2b-256 d5f17831a77aad71f2b3bd04c368a1cf5896c7580f61869329a1c867385cfd3f

See more details on using hashes here.

File details

Details for the file py_license_auditor-0.4.0-py3-none-any.whl.

File metadata

File hashes

Hashes for py_license_auditor-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 759ae6bb364a412f107c405442d44ddb632dc760aef3056434a18b69d6703df7
MD5 b64139b11de5425b4c6bac12ecebb5b7
BLAKE2b-256 f842a29cca386515cfa447526ce3b3eb2455190e02c9482522628f7195983c89

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page