Nobuf

Open Source License Compliance Checker

Private SPDX policy review

Review dependency licenses, SPDX expressions, policy decisions and attribution gaps locally.

cyclonedx SPDX Expression Denied component present
Components
5
License IDs
5
Allowed
2
Needs review
2
Denied
1
Missing evidence
1
Dependency evidence stays local
The page does not execute package scripts, query a registry or upload lockfiles and SBOMs.

Dependency, SBOM or CSV evidence

Supports package.json, package-lock, pnpm-lock, Yarn lock, CycloneDX JSON, SPDX 2.x JSON and a named CSV.

How to use it

  1. 01

    Load dependency evidence

    Open a supported lockfile, dependency manifest, SPDX or CycloneDX SBOM, or CSV inventory.

  2. 02

    Evaluate license policy

    Review expressions, categories, obligations, unknown evidence and editable allow-review-deny rules.

  3. 03

    Prepare reviewed artifacts

    Compare a baseline and export reports, policy, CI results or a third-party attribution index.

Frequently asked questions

Does this scan source code or binaries?

No. It analyzes the dependency and license evidence you provide without executing package scripts.

Is this legal advice?

No. Categories and obligations are engineering triage; counsel must interpret the actual licenses and product context.

Why do lockfiles show unknown licenses?

Many lockfiles do not contain license metadata. The tool reports that gap instead of silently querying a registry or guessing.

Is the generated attribution file complete?

It is a review index and explicitly lists missing full license texts and notices that still need to be supplied.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.