license-compliance

v2026.09.24

Open source license compliance and SPDX standards. Covers license types, compatibility, auditing with license-checker, and SBOM generation. USE WHEN: user mentions "license", "SPDX", "GPL", "MIT", "Apache", asks about "license compatibility", "license-checker", "copyleft", "proprietary compliance", "OSI approved" DO NOT USE FOR: dependency vulnerabilities - use `supply-chain`, security scanning - use `owasp-top-10`, secrets - use `secrets-management`

GitHub
安装命令
npx skhub add claude-dev-suite/license-compliance
Markdown
SKILL.md

License Compliance

When NOT to Use This Skill

  • Security vulnerabilities - Use supply-chain skill for dependency security
  • Code quality issues - Use quality skills for linting/complexity
  • Secrets in dependencies - Use secrets-management skill
  • Package integrity - Use supply-chain for SBOM and verification

Deep Knowledge: Use mcp__documentation__fetch_docs with technology: spdx for comprehensive documentation.

Official References

ResourceURL
SPDX License Listhttps://spdx.org/licenses/
SPDX Specificationhttps://spdx.github.io/spdx-spec/
OSI Approved Licenseshttps://opensource.org/licenses/
Choose a Licensehttps://choosealicense.com/
license-checkerhttps://www.npmjs.com/package/license-checker-rseidelsohn

License Categories

By Permissiveness

CategoryLicensesCommercial Use
Public DomainUnlicense, CC0-1.0Unrestricted
PermissiveMIT, Apache-2.0, BSD-3-Clause, ISCAllowed
Weak CopyleftLGPL-3.0, MPL-2.0, EPL-2.0Allowed (with conditions)
Strong CopyleftGPL-3.0, AGPL-3.0Must open source
Network CopyleftAGPL-3.0, SSPL-1.0Network use triggers

Common SPDX Identifiers

LicenseSPDX IDOSIFSF
MIT LicenseMIT✓✓
Apache 2.0Apache-2.0✓✓
BSD 3-ClauseBSD-3-Clause✓✓
ISC LicenseISC✓✓
GPL 3.0GPL-3.0-only✓✓
GPL 3.0+GPL-3.0-or-later✓✓
LGPL 3.0LGPL-3.0-only✓✓
MPL 2.0MPL-2.0✓✓
AGPL 3.0AGPL-3.0-only✓✓
UnlicenseUnlicense✓✓

Compatibility Matrix

Inbound → Outbound

Your ProjectCan Include
MITMIT, BSD, ISC, Unlicense, CC0
Apache-2.0MIT, BSD, ISC, Apache-2.0, Unlicense
LGPL-3.0MIT, BSD, ISC, Apache-2.0, LGPL, GPL (as library)
GPL-3.0Most licenses (output must be GPL)
ProprietaryMIT, BSD, ISC, Apache-2.0 (check attribution)

Incompatibilities

License AIncompatible With
GPL-2.0-onlyApache-2.0 (patent clause conflict)
GPL-3.0GPL-2.0-only
AGPL-3.0Proprietary SaaS (network clause)
SSPL-1.0Not OSI approved, restricted use

NPM License Auditing

license-checker

# Install
npm install -g license-checker-rseidelsohn

# Basic scan
license-checker

# JSON output
license-checker --json > licenses.json

# Summary only
license-checker --summary

# Production only
license-checker --production

# Exclude dev dependencies
license-checker --production --json

Allowlist Configuration

# Only allow specific licenses
license-checker --onlyAllow "MIT;Apache-2.0;BSD-3-Clause;ISC;0BSD"

# Fail on copyleft licenses
license-checker --failOn "GPL-3.0;AGPL-3.0;GPL-2.0"

# Exclude packages
license-checker --excludePackages "internal-pkg@1.0.0"

@onebeyond/license-checker

npm install -g @onebeyond/license-checker

# Scan with allowlist
npx @onebeyond/license-checker scan --allowOnly MIT Apache-2.0 BSD-3-Clause

# Check SPDX compliance
npx @onebeyond/license-checker check "MIT OR Apache-2.0"

license-compliance

npm install -g license-compliance

# Check compliance
license-compliance --production --allow "MIT;ISC;Apache-2.0"

# Generate report
license-compliance --report licenses.csv

SBOM Generation

CycloneDX

# Install
npm install -g @cyclonedx/cyclonedx-npm

# Generate SBOM
cyclonedx-npm --output-file sbom.json

# Specific format
cyclonedx-npm --output-format XML --output-file sbom.xml

# Include dev dependencies
cyclonedx-npm --include-dev --output-file sbom.json

SPDX

# Using Syft
syft . -o spdx-json > sbom-spdx.json

# Verify SBOM
syft validate sbom-spdx.json

SBOM in package.json

{
  "name": "my-package",
  "version": "1.0.0",
  "license": "MIT",
  "licenses": [
    {
      "type": "MIT",
      "url": "https://opensource.org/licenses/MIT"
    }
  ]
}

CI Integration

GitHub Actions

name: License Compliance

on: [push, pull_request]

jobs:
  license-check:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: '20'

      - name: Install dependencies
        run: npm ci

      - name: Check licenses
        run: |
          npx license-checker-rseidelsohn \
            --production \
            --onlyAllow "MIT;Apache-2.0;BSD-3-Clause;BSD-2-Clause;ISC;0BSD;Unlicense;CC0-1.0" \
            --excludePrivatePackages

      - name: Generate SBOM
        run: |
          npx @cyclonedx/cyclonedx-npm --output-file sbom.json

      - name: Upload SBOM
        uses: actions/upload-artifact@v4
        with:
          name: sbom
          path: sbom.json

Pre-commit Hook

// package.json
{
  "scripts": {
    "license:check": "license-checker --production --onlyAllow 'MIT;Apache-2.0;BSD-3-Clause;ISC'",
    "preinstall": "npm run license:check || true"
  }
}

License File Templates

MIT License

MIT License

Copyright (c) [year] [fullname]

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

Apache 2.0 NOTICE

MyProject
Copyright [year] [owner]

This product includes software developed at
[Company Name] (https://www.example.com/).

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Attribution Requirements

By License Type

LicenseRequirements
MITInclude copyright + license
Apache-2.0Include copyright + license + NOTICE if present
BSD-3-ClauseInclude copyright + license
LGPL-3.0Provide source for modifications
GPL-3.0Provide complete source

Generating Attribution

# Generate NOTICES file
license-checker --production --customFormat '{"name": "", "version": "", "license": "", "repository": ""}' \
  | jq -r '.[] | "- \(.name)@\(.version) - \(.license)\n  \(.repository)\n"' \
  > NOTICES.md

NOTICES.md Template

# Third-Party Notices

This project includes the following third-party software:

## MIT License

### lodash (4.17.21)
- Repository: https://github.com/lodash/lodash
- Copyright (c) JS Foundation and other contributors

### axios (1.6.0)
- Repository: https://github.com/axios/axios
- Copyright (c) 2014-present Matt Zabriskie

## Apache-2.0 License

### typescript (5.3.0)
- Repository: https://github.com/microsoft/TypeScript
- Copyright (c) Microsoft Corporation

Risk Assessment

High Risk (Avoid in Proprietary)

LicenseRiskMitigation
GPL-3.0CopyleftUse LGPL version or alternatives
AGPL-3.0Network copyleftAvoid in SaaS products
SSPL-1.0Service restrictionUse alternatives (MongoDB)
CPAL-1.0Attribution in UICheck UI requirements

Medium Risk (Review Carefully)

LicenseRiskMitigation
LGPL-3.0Dynamic linkingEnsure dynamic linking
MPL-2.0File-level copyleftKeep modifications separate
EPL-2.0Patent grantsReview patent clauses

Low Risk (Generally Safe)

LicenseNotes
MITInclude license/copyright
Apache-2.0Include license + NOTICE
BSD-3-ClauseInclude license/copyright
ISCInclude license/copyright

Checklist

Initial Setup

  • Choose appropriate license for project
  • Add LICENSE file to repository
  • Add license field to package.json
  • Configure license-checker in CI

Ongoing Compliance

  • Audit new dependencies before adding
  • Reject incompatible licenses in PR review
  • Generate SBOM for releases
  • Maintain NOTICES file
  • Review license changes in updates

Release

  • License file included in distribution
  • Third-party notices generated
  • SBOM attached to release
  • No copyleft violations

Anti-Patterns

Anti-PatternWhy It's BadCorrect Approach
Not checking licenses before adding depsLegal risk, copyleft violationsUse license-checker in CI
Using GPL in proprietary softwareMust open source entire appUse MIT/Apache or LGPL as library
No NOTICES file for attributionViolates license termsGenerate NOTICES from dependencies
Ignoring license changes in updatesNew version may have different licenseReview license in Dependabot PRs
Using unlicensed packagesUnclear legal statusOnly use packages with explicit licenses
Mixing GPL-2.0 and Apache-2.0Incompatible licensesChoose compatible stack

Quick Troubleshooting

IssueLikely CauseSolution
license-checker fails on installMissing package.json license fieldAdd "license": "MIT" to package.json
GPL dependency found in proprietaryTransitive dependencyFind alternative or use as separate service
Multiple licenses for same packageDual-licensedChoose compatible license (usually MIT/Apache)
SPDX validation failsInvalid SPDX identifierUse exact ID from spdx.org/licenses
License allowlist too strictBlocks common licensesAdd ISC, 0BSD to allowlist
No license file in distributionMissing LICENSE fileCopy LICENSE to dist/ in build

Related Skills

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/security/license-compliance

默认分支

main

最新提交

9496306

Tree SHA

fe4e2f1