Repository navigation
Conversation
Add a workflow that installs the package into a clean environment and checks every dependency it pulls in against a list of allowed licenses. A dependency passes only if every license it declares, in its License-Expression, its classifiers and its License field, is on the list, so a package that declares two licenses needs both allowed. One that declares none fails. Dependencies reviewed by hand are listed as exceptions together with the licenses they declared at the time of review. When a new release of one of them declares something else, the check fails again and the review is repeated. Exceptions that no longer match an installed package, or that would pass without one, are reported so the list stays short. The job runs on Linux and on Windows, since one dependency is installed on Windows only. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on #61. Based on its branch and kept as a draft until it merges; GitHub then retargets this one to
main.What and why
A CI job checks the licenses of every dependency the package installs, so a dependency under terms the project does not accept cannot land unnoticed.
Dependency licensesruns on pushes and pull requests tomain. It installs the package into a clean virtual environment withpip install ., so the check sees what the package pulls in and nothing else on the runner, and then runs the check script with that environment's interpreter. Two jobs: Ubuntu with Python 3.13 and Windows with Python 3.12, sincewinsdkis installed on Windows only and publishes wheels up to 3.12..github/scripts/check_licenses.py, standard library only, with an allowlist of accepted licenses. A dependency passes only if every license it declares is allowed: itsLicense-Expression, eachLicense ::classifier and its free-textLicensefield. A dependency that declares none fails. Operators in an expression are not interpreted, soA OR Bneeds both allowed.cryptnox-sdk-py,pyscard,soldersandjsonalias. If a later release of one of them declares something else, the check fails again and the review is repeated. Exceptions that match no installed package, or that would pass without the exception, are reported so the list stays short.pipinstalls. A PyInstaller bundle can contain more than that; the bundle is not checked here.Stacked on #61: the dependency set it leaves is the one the check passes on, so this branch is based on it and should merge after it.
How it was tested
ORandWITHexpressions, no metadata at all, bareOSI Approved,UNKNOWN, full license text in the field, and an excepted package that starts declaring a different license. All 39 give the expected verdict.act; the Windows job can only run on GitHub.Third-party and generated code
No third-party code. Substantial parts of this pull request were produced with Claude Code.
🤖 Generated with Claude Code