Repository navigation
Check dependency licenses in CI - #27
Merged
Merged
Conversation
Add a workflow that installs the package into a clean environment and checks every dependency it pulls in against a list of allowed licenses. A dependency passes only if every license it declares, in its License-Expression, its classifiers and its License field, is on the list, so a package that declares two licenses needs both allowed. One that declares none fails. Dependencies reviewed by hand are listed as exceptions together with the licenses they declared at the time of review. When a new release of one of them declares something else, the check fails again and the review is repeated. Exceptions that no longer match an installed package, or that would pass without one, are reported so the list stays short. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
A CI job checks the licenses of every dependency the package installs, so a dependency under terms the project does not accept cannot land unnoticed.
Dependency licensesruns on pushes and pull requests tomain. It installs the package into a clean virtual environment withpip install ., so the check sees what the package pulls in and nothing else on the runner, and then runs the check script with that environment's interpreter. Ubuntu, Python 3.12, actions pinned by commit as inci.yml..github/scripts/check_licenses.py, standard library only, with an allowlist of accepted licenses. A dependency passes only if every license it declares is allowed: itsLicense-Expression, eachLicense ::classifier and its free-textLicensefield. A dependency that declares none fails. Operators in an expression are not interpreted, soA OR Bneeds both allowed.pyscardalone. If a later release declares something else, the check fails again and the review is repeated. Exceptions that match no installed package, or that would pass without the exception, are reported so the list stays short.pipinstalls. A PyInstaller bundle can contain more than that; the bundle is not checked here.The same check is proposed for cryptnox-cli in cryptnox/cryptnox-cli#62; the script differs only in the project name and the exception list.
How it was tested
main: 12 distributions, all pass.ORandWITHexpressions, no metadata at all, bareOSI Approved,UNKNOWN, full license text in the field, and an excepted package that starts declaring a different license. All 39 give the expected verdict (run against the cryptnox-cli copy of the script; the checking code is identical).act.ruff checkandruff format --checkwith the repository configuration pass on the script.Third-party and generated code
No third-party code. Substantial parts of this pull request were produced with Claude Code.
🤖 Generated with Claude Code