Skip to main content

Fast license auditor for uv projects - Extract and analyze license information with uv.lock integration

Project description

py-license-auditor

Crates.io PyPI License

The fastest license auditor for uv projects - Built specifically for the modern Python ecosystem.

🎯 uv-First Strategy: This tool is designed exclusively for uv projects. We focus on providing the best possible experience for uv users rather than supporting all package managers.

✨ Why uv + py-license-auditor?

  • 🚀 Built for Speed: Both tools are written in Rust for maximum performance
  • 🎯 uv-Native: Deep integration with uv.lock and uv workflows
  • 🔧 Zero Config: Works out of the box with uv projects
  • Fast Workflow: uv sync && py-license-auditor - that's it!

🚀 Installation

For uv Users (Recommended)

# Install as a uv tool
uv tool install py-license-auditor

# Use in any uv project
cd my-uv-project
uv tool run py-license-auditor

Manual Installation

Download the binary for your platform from GitHub Releases.

From Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo install --path .

📖 Usage

📚 Quick Start: See QUICKSTART.md for a step-by-step guide

Quick Start

# 1. Setup your uv project
uv init my-project
cd my-project
uv add requests pandas

# 2. Configure license policy (one-time setup)
py-license-auditor --init green

# 3. Run license audit
uv sync
py-license-auditor

Configuration Setup

Initialize with Built-in Policies

# For commercial/enterprise projects (safest)
py-license-auditor --init green

# For balanced development (permissive + weak copyleft)
py-license-auditor --init yellow

# For audit/OSS development (information gathering)
py-license-auditor --init red

This creates a [tool.py-license-auditor] section in your pyproject.toml with appropriate settings.

Basic Usage

# Auto-detect .venv in current directory
py-license-auditor

# Specify site-packages directory
py-license-auditor --path /path/to/site-packages

# Save to file
py-license-auditor --output licenses.json

Output Formats

# JSON (default)
py-license-auditor --format json

# Table for terminal viewing
py-license-auditor --format table

# CSV for spreadsheets
py-license-auditor --format csv

Advanced Options

# Include packages without license info
py-license-auditor --include-unknown

# Combine options
py-license-auditor --format csv --output report.csv --include-unknown

# Interactive mode for handling violations
py-license-auditor --interactive

📊 Output Example

JSON Format

{
  "packages": [
    {
      "name": "requests",
      "version": "2.31.0",
      "license": "Apache-2.0",
      "license_classifiers": [
        "License :: OSI Approved :: Apache Software License"
      ],
      "metadata_source": "METADATA"
    }
  ],
  "summary": {
    "total_packages": 50,
    "with_license": 45,
    "without_license": 5,
    "license_types": {
      "osi_approved": {
        "MIT": 20,
        "Apache-2.0": 15,
        "BSD": 8
      },
      "non_osi": {
        "MIT License": 2
      }
    }
  },
  "violations": {
    "total": 2,
    "errors": 1,
    "warnings": 1,
    "details": [
      {
        "package_name": "some-gpl-lib",
        "package_version": "2.1.0",
        "license": "GPL-3.0",
        "violation_level": "Forbidden",
        "matched_rule": "exact: GPL-3.0",
        "message": "License 'GPL-3.0' is forbidden by policy"
      }
    ]
  }
}

CSV Format

name,version,license,license_classifiers,metadata_source
requests,2.31.0,Apache-2.0,"License :: OSI Approved :: Apache Software License",METADATA
click,8.1.7,BSD-3-Clause,"License :: OSI Approved :: BSD License",METADATA

🎛️ Policy Configuration

Built-in Policies

Three ready-to-use policies are included:

# Green: Safe for commercial use - only permissive licenses
py-license-auditor --init green

# Yellow: Balanced policy - permissive + weak copyleft
py-license-auditor --init yellow

# Red: Audit mode - all licenses allowed for information gathering
py-license-auditor --init red
Policy Allowed Forbidden Review Required Fails on Violation
Green MIT, Apache-2.0, BSD-*, ISC GPL-, AGPL-, LGPL-*, MPL-2.0 None Yes
Yellow MIT, Apache-2.0, BSD-, ISC, LGPL-, MPL-2.0 GPL-, AGPL- None Yes
Red MIT, Apache-2.0, BSD-, ISC, LGPL-, MPL-2.0 None GPL-, AGPL- No

Custom Policy Configuration

After running py-license-auditor --init, you can customize the generated configuration in pyproject.toml:

[tool.py-license-auditor]
format = "json"
include_unknown = true
fail_on_violations = true

[tool.py-license-auditor.policy]
name = "Custom License Policy"
description = "Tailored policy for our project"

[tool.py-license-auditor.policy.allowed_licenses]
exact = ["MIT", "Apache-2.0", "BSD-3-Clause", "ISC"]
patterns = ["BSD-*"]

[tool.py-license-auditor.policy.forbidden_licenses]
exact = ["GPL-3.0", "AGPL-3.0"]
patterns = ["GPL-*", "AGPL-*"]

[tool.py-license-auditor.policy.review_required]
exact = ["MPL-2.0"]
patterns = ["LGPL-*"]

[[tool.py-license-auditor.policy.exceptions]]
name = "legacy-package"
version = "1.0.0"
reason = "Approved by legal team for legacy compatibility"

Policy Rules

  • allowed_licenses: Licenses that are automatically approved
  • forbidden_licenses: Licenses that cause build failures
  • review_required: Licenses that need manual review (warnings)
  • exceptions: Package-specific overrides with justification

Pattern Matching

Use glob patterns for flexible license matching:

  • "GPL-*" matches GPL-2.0, GPL-3.0, etc.
  • "BSD-*" matches BSD-2-Clause, BSD-3-Clause, etc.

🎯 Use Cases

License Compliance

Generate comprehensive reports for legal review and compliance auditing.

# Generate compliance report
py-license-auditor --format json --output compliance-report.json

CI/CD Integration

Automate license checking in your deployment pipeline.

# GitHub Actions example
- name: Setup License Policy
  run: py-license-auditor --init green
  
- name: License Check  
  run: py-license-auditor
    
- name: Generate License Report
  run: py-license-auditor --format json --output license-report.json

Dependency Auditing

Understand your project's license obligations and risks.

# Focus on potential issues
py-license-auditor --format json

🔍 License Categories

The tool categorizes licenses into two groups:

  • OSI Approved: Licenses approved by the Open Source Initiative (legally vetted)
  • Non-OSI: Custom licenses, proprietary licenses, or unrecognized formats

This helps you quickly identify which licenses need manual legal review.

🛠️ Development

Building from Source

git clone https://github.com/yayami3/py-license-auditor
cd py-license-auditor
cargo build --release

Running Tests

cargo test

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

📄 License

This project is licensed under either of

at your option.

🙏 Acknowledgments

  • Built with Clap for CLI parsing
  • Uses Serde for serialization
  • Inspired by the need for better Python license compliance tools

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_license_auditor-0.4.2.tar.gz (2.6 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_license_auditor-0.4.2-py3-none-any.whl (2.6 MB view details)

Uploaded Python 3

File details

Details for the file py_license_auditor-0.4.2.tar.gz.

File metadata

  • Download URL: py_license_auditor-0.4.2.tar.gz
  • Upload date:
  • Size: 2.6 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for py_license_auditor-0.4.2.tar.gz
Algorithm Hash digest
SHA256 eab62250d206b284fccbb930aff78a40abd70e13a0ece0bda70567f6294eab34
MD5 7859e0cc3b30278246299184bec0d323
BLAKE2b-256 598f2f236480ea76a225639b5705b77b129f81592237c2cc06f7a8ed9ce1a26a

See more details on using hashes here.

File details

Details for the file py_license_auditor-0.4.2-py3-none-any.whl.

File metadata

File hashes

Hashes for py_license_auditor-0.4.2-py3-none-any.whl
Algorithm Hash digest
SHA256 1af8ca4d106c0d98ce31235efb13a1808647c3300ea369546eceefb30e30d293
MD5 0d89500d9e989a84498f158974363488
BLAKE2b-256 a8242c76da7627f5e973ff4cc02ae9cea8af5fb3752929686a776d26ead2bc05

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page