Open Source License Compliance Checker
Private SPDX policy reviewReview dependency licenses, SPDX expressions, policy decisions and attribution gaps locally.
Dependency, SBOM or CSV evidence
Supports package.json, package-lock, pnpm-lock, Yarn lock, CycloneDX JSON, SPDX 2.x JSON and a named CSV.
How to use it
- 01
Load dependency evidence
Open a supported lockfile, dependency manifest, SPDX or CycloneDX SBOM, or CSV inventory.
- 02
Evaluate license policy
Review expressions, categories, obligations, unknown evidence and editable allow-review-deny rules.
- 03
Prepare reviewed artifacts
Compare a baseline and export reports, policy, CI results or a third-party attribution index.
Frequently asked questions
Does this scan source code or binaries?
No. It analyzes the dependency and license evidence you provide without executing package scripts.
Is this legal advice?
No. Categories and obligations are engineering triage; counsel must interpret the actual licenses and product context.
Why do lockfiles show unknown licenses?
Many lockfiles do not contain license metadata. The tool reports that gap instead of silently querying a registry or guessing.
Is the generated attribution file complete?
It is a review index and explicitly lists missing full license texts and notices that still need to be supplied.
Related tools
Keep working with other focused browser utilities.