Skip to main content

Fast license auditor for uv projects - Extract and analyze license information with uv.lock integration

Project description

py-license-auditor

Crates.io PyPI License

The fastest license auditor for uv projects - Built specifically for the modern Python ecosystem.

🎯 uv-First Strategy: This tool is designed exclusively for uv projects. We focus on providing the best possible experience for uv users rather than supporting all package managers.

✨ Why uv + py-license-auditor?

  • 🚀 Built for Speed: Both tools are written in Rust for maximum performance
  • 🎯 uv-Native: Deep integration with uv.lock and uv workflows
  • 🔧 Zero Config: Works out of the box with uv projects
  • Fast Workflow: uv sync && py-license-auditor - that's it!

🚀 Installation

For uv Users (Recommended)

# Install as a uv tool
uv tool install py-license-auditor

# Use in any uv project
cd my-uv-project
uv tool run py-license-auditor

Manual Installation

Download the binary for your platform from GitHub Releases.

From Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo install --path .

📖 Usage

📚 Quick Start: See QUICKSTART.md for a step-by-step guide

Quick Start

# 1. Setup your uv project
uv init my-project
cd my-project
uv add requests pandas

# 2. Configure license policy (one-time setup)
py-license-auditor --init green

# 3. Run license audit
uv sync
py-license-auditor

Configuration Setup

Initialize with Built-in Policies

# For commercial/enterprise projects (safest)
py-license-auditor --init green

# For balanced development (permissive + weak copyleft)
py-license-auditor --init yellow

# For audit/OSS development (information gathering)
py-license-auditor --init red

This creates a [tool.py-license-auditor] section in your pyproject.toml with appropriate settings.

Basic Usage

# Auto-detect .venv in current directory
py-license-auditor

# Specify site-packages directory
py-license-auditor --path /path/to/site-packages

# Save to file
py-license-auditor --output licenses.json

Output Formats

# JSON (default)
py-license-auditor --format json

# Table for terminal viewing
py-license-auditor --format table

# CSV for spreadsheets
py-license-auditor --format csv

Advanced Options

# Include packages without license info
py-license-auditor --include-unknown

# Combine options
py-license-auditor --format csv --output report.csv --include-unknown

# Interactive mode for handling violations
py-license-auditor --interactive

📊 Output Example

JSON Format

{
  "packages": [
    {
      "name": "requests",
      "version": "2.31.0",
      "license": "Apache-2.0",
      "license_classifiers": [
        "License :: OSI Approved :: Apache Software License"
      ],
      "metadata_source": "METADATA"
    }
  ],
  "summary": {
    "total_packages": 50,
    "with_license": 45,
    "without_license": 5,
    "license_types": {
      "osi_approved": {
        "MIT": 20,
        "Apache-2.0": 15,
        "BSD": 8
      },
      "non_osi": {
        "MIT License": 2
      }
    }
  },
  "violations": {
    "total": 2,
    "errors": 1,
    "warnings": 1,
    "details": [
      {
        "package_name": "some-gpl-lib",
        "package_version": "2.1.0",
        "license": "GPL-3.0",
        "violation_level": "Forbidden",
        "matched_rule": "exact: GPL-3.0",
        "message": "License 'GPL-3.0' is forbidden by policy"
      }
    ]
  }
}

CSV Format

name,version,license,license_classifiers,metadata_source
requests,2.31.0,Apache-2.0,"License :: OSI Approved :: Apache Software License",METADATA
click,8.1.7,BSD-3-Clause,"License :: OSI Approved :: BSD License",METADATA

🎛️ Policy Configuration

Built-in Policies

Three ready-to-use policies are included:

# Green: Safe for commercial use - only permissive licenses
py-license-auditor --init green

# Yellow: Balanced policy - permissive + weak copyleft
py-license-auditor --init yellow

# Red: Audit mode - all licenses allowed for information gathering
py-license-auditor --init red
Policy Allowed Forbidden Review Required Fails on Violation
Green MIT, Apache-2.0, BSD-*, ISC GPL-, AGPL-, LGPL-*, MPL-2.0 None Yes
Yellow MIT, Apache-2.0, BSD-, ISC, LGPL-, MPL-2.0 GPL-, AGPL- None Yes
Red MIT, Apache-2.0, BSD-, ISC, LGPL-, MPL-2.0 None GPL-, AGPL- No

Custom Policy Configuration

After running py-license-auditor --init, you can customize the generated configuration in pyproject.toml:

[tool.py-license-auditor]
format = "json"
include_unknown = true
fail_on_violations = true

[tool.py-license-auditor.policy]
name = "Custom License Policy"
description = "Tailored policy for our project"

[tool.py-license-auditor.policy.allowed_licenses]
exact = ["MIT", "Apache-2.0", "BSD-3-Clause", "ISC"]
patterns = ["BSD-*"]

[tool.py-license-auditor.policy.forbidden_licenses]
exact = ["GPL-3.0", "AGPL-3.0"]
patterns = ["GPL-*", "AGPL-*"]

[tool.py-license-auditor.policy.review_required]
exact = ["MPL-2.0"]
patterns = ["LGPL-*"]

[[tool.py-license-auditor.policy.exceptions]]
name = "legacy-package"
version = "1.0.0"
reason = "Approved by legal team for legacy compatibility"

Policy Rules

  • allowed_licenses: Licenses that are automatically approved
  • forbidden_licenses: Licenses that cause build failures
  • review_required: Licenses that need manual review (warnings)
  • exceptions: Package-specific overrides with justification

Pattern Matching

Use glob patterns for flexible license matching:

  • "GPL-*" matches GPL-2.0, GPL-3.0, etc.
  • "BSD-*" matches BSD-2-Clause, BSD-3-Clause, etc.

🎯 Use Cases

License Compliance

Generate comprehensive reports for legal review and compliance auditing.

# Generate compliance report
py-license-auditor --format json --output compliance-report.json

CI/CD Integration

Automate license checking in your deployment pipeline.

# GitHub Actions example
- name: Setup License Policy
  run: py-license-auditor --init green
  
- name: License Check  
  run: py-license-auditor
    
- name: Generate License Report
  run: py-license-auditor --format json --output license-report.json

Dependency Auditing

Understand your project's license obligations and risks.

# Focus on potential issues
py-license-auditor --format json

🔍 License Categories

The tool categorizes licenses into two groups:

  • OSI Approved: Licenses approved by the Open Source Initiative (legally vetted)
  • Non-OSI: Custom licenses, proprietary licenses, or unrecognized formats

This helps you quickly identify which licenses need manual legal review.

🛠️ Development

Building from Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo build --release

Running Tests

cargo test

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

📄 License

This project is licensed under either of

at your option.

🙏 Acknowledgments

  • Built with Clap for CLI parsing
  • Uses Serde for serialization
  • Inspired by the need for better Python license compliance tools

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_license_auditor-0.4.1.tar.gz (2.5 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_license_auditor-0.4.1-py3-none-any.whl (2.6 MB view details)

Uploaded Python 3

File details

Details for the file py_license_auditor-0.4.1.tar.gz.

File metadata

  • Download URL: py_license_auditor-0.4.1.tar.gz
  • Upload date:
  • Size: 2.5 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for py_license_auditor-0.4.1.tar.gz
Algorithm Hash digest
SHA256 4a221f4df5b89e5789df970c4efa48a5dbed2198c35c4cedd8b92dc595ba9c0d
MD5 14bffdd96c55dc6b87c5a4250ff157b7
BLAKE2b-256 5e47299319e44afbc8c099a2a3c09e888e76a9df309d5912b7fbe51060ab6b6c

See more details on using hashes here.

File details

Details for the file py_license_auditor-0.4.1-py3-none-any.whl.

File metadata

File hashes

Hashes for py_license_auditor-0.4.1-py3-none-any.whl
Algorithm Hash digest
SHA256 55b700f04e023308cf90eeaeadab745a773d7010d28dade3bbe1568d91fdf502
MD5 44d9da447f407db16dc0f1806171dd1b
BLAKE2b-256 f6255eacf59403c87b7d79b22f14bf84d42740a6fd4a3444fbc8542f1dcd18f8

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page