license-compliance
Open source license compliance and SPDX standards. Covers license types, compatibility, auditing with license-checker, and SBOM generation. USE WHEN: user mentions "license", "SPDX", "GPL", "MIT", "Apache", asks about "license compatibility", "license-checker", "copyleft", "proprietary compliance", "OSI approved" DO NOT USE FOR: dependency vulnerabilities - use `supply-chain`, security scanning - use `owasp-top-10`, secrets - use `secrets-management`
What this skill does
# License Compliance ## When NOT to Use This Skill - **Security vulnerabilities** - Use `supply-chain` skill for dependency security - **Code quality issues** - Use quality skills for linting/complexity - **Secrets in dependencies** - Use `secrets-management` skill - **Package integrity** - Use `supply-chain` for SBOM and verification > **Deep Knowledge**: Use `mcp__documentation__fetch_docs` with technology: `spdx` for comprehensive documentation. ## Official References | Resource | URL | |----------|-----| | SPDX License List | https://spdx.org/licenses/ | | SPDX Specification | https://spdx.github.io/spdx-spec/ | | OSI Approved Licenses | https://opensource.org/licenses/ | | Choose a License | https://choosealicense.com/ | | license-checker | https://www.npmjs.com/package/license-checker-rseidelsohn | --- ## License Categories ### By Permissiveness | Category | Licenses | Commercial Use | |----------|----------|----------------| | **Public Domain** | Unlicense, CC0-1.0 | Unrestricted | | **Permissive** | MIT, Apache-2.0, BSD-3-Clause, ISC | Allowed | | **Weak Copyleft** | LGPL-3.0, MPL-2.0, EPL-2.0 | Allowed (with conditions) | | **Strong Copyleft** | GPL-3.0, AGPL-3.0 | Must open source | | **Network Copyleft** | AGPL-3.0, SSPL-1.0 | Network use triggers | ### Common SPDX Identifiers | License | SPDX ID | OSI | FSF | |---------|---------|-----|-----| | MIT License | `MIT` | ✓ | ✓ | | Apache 2.0 | `Apache-2.0` | ✓ | ✓ | | BSD 3-Clause | `BSD-3-Clause` | ✓ | ✓ | | ISC License | `ISC` | ✓ | ✓ | | GPL 3.0 | `GPL-3.0-only` | ✓ | ✓ | | GPL 3.0+ | `GPL-3.0-or-later` | ✓ | ✓ | | LGPL 3.0 | `LGPL-3.0-only` | ✓ | ✓ | | MPL 2.0 | `MPL-2.0` | ✓ | ✓ | | AGPL 3.0 | `AGPL-3.0-only` | ✓ | ✓ | | Unlicense | `Unlicense` | ✓ | ✓ | --- ## Compatibility Matrix ### Inbound → Outbound | Your Project | Can Include | |--------------|-------------| | MIT | MIT, BSD, ISC, Unlicense, CC0 | | Apache-2.0 | MIT, BSD, ISC, Apache-2.0, Unlicense | | LGPL-3.0 | MIT, BSD, ISC, Apache-2.0, LGPL, GPL (as library) | | GPL-3.0 | Most licenses (output must be GPL) | | Proprietary | MIT, BSD, ISC, Apache-2.0 (check attribution) | ### Incompatibilities | License A | Incompatible With | |-----------|-------------------| | GPL-2.0-only | Apache-2.0 (patent clause conflict) | | GPL-3.0 | GPL-2.0-only | | AGPL-3.0 | Proprietary SaaS (network clause) | | SSPL-1.0 | Not OSI approved, restricted use | --- ## NPM License Auditing ### license-checker ```bash # Install npm install -g license-checker-rseidelsohn # Basic scan license-checker # JSON output license-checker --json > licenses.json # Summary only license-checker --summary # Production only license-checker --production # Exclude dev dependencies license-checker --production --json ``` ### Allowlist Configuration ```bash # Only allow specific licenses license-checker --onlyAllow "MIT;Apache-2.0;BSD-3-Clause;ISC;0BSD" # Fail on copyleft licenses license-checker --failOn "GPL-3.0;AGPL-3.0;GPL-2.0" # Exclude packages license-checker --excludePackages "[email protected]" ``` ### @onebeyond/license-checker ```bash npm install -g @onebeyond/license-checker # Scan with allowlist npx @onebeyond/license-checker scan --allowOnly MIT Apache-2.0 BSD-3-Clause # Check SPDX compliance npx @onebeyond/license-checker check "MIT OR Apache-2.0" ``` ### license-compliance ```bash npm install -g license-compliance # Check compliance license-compliance --production --allow "MIT;ISC;Apache-2.0" # Generate report license-compliance --report licenses.csv ``` --- ## SBOM Generation ### CycloneDX ```bash # Install npm install -g @cyclonedx/cyclonedx-npm # Generate SBOM cyclonedx-npm --output-file sbom.json # Specific format cyclonedx-npm --output-format XML --output-file sbom.xml # Include dev dependencies cyclonedx-npm --include-dev --output-file sbom.json ``` ### SPDX ```bash # Using Syft syft . -o spdx-json > sbom-spdx.json # Verify SBOM syft validate sbom-spdx.json ``` ### SBOM in package.json ```json { "name": "my-package", "version": "1.0.0", "license": "MIT", "licenses": [ { "type": "MIT", "url": "https://opensource.org/licenses/MIT" } ] } ``` --- ## CI Integration ### GitHub Actions ```yaml name: License Compliance on: [push, pull_request] jobs: license-check: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Setup Node.js uses: actions/setup-node@v4 with: node-version: '20' - name: Install dependencies run: npm ci - name: Check licenses run: | npx license-checker-rseidelsohn \ --production \ --onlyAllow "MIT;Apache-2.0;BSD-3-Clause;BSD-2-Clause;ISC;0BSD;Unlicense;CC0-1.0" \ --excludePrivatePackages - name: Generate SBOM run: | npx @cyclonedx/cyclonedx-npm --output-file sbom.json - name: Upload SBOM uses: actions/upload-artifact@v4 with: name: sbom path: sbom.json ``` ### Pre-commit Hook ```json // package.json { "scripts": { "license:check": "license-checker --production --onlyAllow 'MIT;Apache-2.0;BSD-3-Clause;ISC'", "preinstall": "npm run license:check || true" } } ``` --- ## License File Templates ### MIT License ``` MIT License Copyright (c) [year] [fullname] Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ``` ### Apache 2.0 NOTICE ``` MyProject Copyright [year] [owner] This product includes software developed at [Company Name] (https://www.example.com/). Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 ``` --- ## Attribution Requirements ### By License Type | License | Requirements | |---------|--------------| | MIT | Include copyright + license | | Apache-2.0 | Include copyright + license + NOTICE if present | | BSD-3-Clause | Include copyright + license | | LGPL-3.0 | Provide source for modifications | | GPL-3.0 | Provide complete source | ### Generating Attribution ```bash # Generate NOTICES file license-checker --production --customFormat '{"name": "", "version": "", "license": "", "repository": ""}' \ | jq -r '.[] | "- \(.name)@\(.version) - \(.license)\n \(.repository)\n"' \ > NOTICES.md ``` ### NOTICES.md Template ```markdown # Third-Party Notices This project includes the following third-party software: ## MIT License ### lodash (4.17.21) - Repository: https://github.com/lodash/lodash - Copyright (c) JS Foundation and other contributors ### axios (1.6.0) - Repository: https://github.com/axios/axios - Copyright (c) 2014-present Matt Zabriskie ## Apache-2.0 License ### typescript (5.3.0) - Repository: https://github.com/microsoft/TypeScript - Copyright (c) Microsoft Corporation ``` --- ## Risk Assessment ### High Risk (Avoid in Proprietary) | License | Risk | Mitigation | |---------|-----
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.