{"_id":"@bobfromarcher/licsweep","_rev":"2-1080a569567bd69ac650e8728027454f","name":"@bobfromarcher/licsweep","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@bobfromarcher/licsweep","version":"1.0.0","keywords":["license","licenses","compliance","audit","spdx","copyleft","gpl","dependencies","ci","cli","zero-dependency","devtools"],"author":{"name":"bobfromarcher"},"license":"MIT","_id":"@bobfromarcher/licsweep@1.0.0","maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"homepage":"https://github.com/bobfromarcher/licsweep#readme","bugs":{"url":"https://github.com/bobfromarcher/licsweep/issues"},"bin":{"licsweep":"bin/licsweep.js"},"dist":{"shasum":"93c3972cb69c1cf9c7bc5bebfe635b6063de467e","tarball":"https://registry.npmjs.org/@bobfromarcher/licsweep/-/licsweep-1.0.0.tgz","fileCount":4,"integrity":"sha512-KeQovh8+L9g9LsA6cosTlXwELGne3veH0O4MOHiU310DZNnfOrzamClpOQ+wPnUgG48lCGy4K4DPFG5OqtKmfQ==","signatures":[{"sig":"MEQCIG10UC/zlGm/XgjOBPzfmrHzjFNJ7s+dWIz+8BTP8Y/OAiBqD9Bok7e0p08/pWhiLbst8R5hZgal1p2mg7kvR3JLEg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12883},"engines":{"node":">=16"},"gitHead":"928c282cb322a513cf787e0174a5d30152a28c67","scripts":{"test":"node test/test.js","start":"node bin/licsweep.js"},"_npmUser":{"name":"bobfromarcher","email":"chrisbellth@gmail.com"},"repository":{"url":"git+https://github.com/bobfromarcher/licsweep.git","type":"git"},"_npmVersion":"11.11.0","description":"Audit the licenses of your installed npm dependencies — flag copyleft/unknown and fail CI on a deny-list. Zero dependencies.","directories":{},"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/licsweep_1.0.0_1781946487347_0.8733500104544498","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bobfromarcher/licsweep","publishConfig":{"access":"public"},"version":"1.0.1","description":"Audit the licenses of your installed npm dependencies - flag copyleft/unknown and fail CI on a deny-list. Zero dependencies.","bin":{"licsweep":"bin/licsweep.js"},"scripts":{"test":"node test/test.js","start":"node bin/licsweep.js"},"keywords":["license","licenses","compliance","audit","spdx","copyleft","gpl","dependencies","ci","cli","zero-dependency","devtools"],"author":{"name":"bobfromarcher"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/bobfromarcher/licsweep.git"},"bugs":{"url":"https://github.com/bobfromarcher/licsweep/issues"},"homepage":"https://github.com/bobfromarcher/licsweep#readme","engines":{"node":">=16"},"gitHead":"e39a2ab3748fafd9598b02a1a8dc06558bf41827","_id":"@bobfromarcher/licsweep@1.0.1","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-GZKSGrvpLCyms5zHmYkj2ahf4WrANU7cDBM8i/BRSxltA6Ky+gCPbkdDbDJhu7IynZeRkFKcuyq3hPVopOO+CA==","shasum":"587c20c4913a104517affe2a90b17298bb4bdbdc","tarball":"https://registry.npmjs.org/@bobfromarcher/licsweep/-/licsweep-1.0.1.tgz","fileCount":4,"unpackedSize":12794,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICIJkqOpwzw2f8zRkvXX9gMIFMa+1i/0xdJ47SOzivJbAiEA2unA2krKAIVcSnI/veD+nPMXYpiInCGFXqB24xu18k0="}]},"_npmUser":{"name":"bobfromarcher","email":"chrisbellth@gmail.com"},"directories":{},"maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/licsweep_1.0.1_1781948723949_0.710199530960772"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-20T09:08:07.165Z","modified":"2026-06-20T09:45:24.164Z","1.0.0":"2026-06-20T09:08:07.489Z","1.0.1":"2026-06-20T09:45:24.073Z"},"bugs":{"url":"https://github.com/bobfromarcher/licsweep/issues"},"author":{"name":"bobfromarcher"},"license":"MIT","homepage":"https://github.com/bobfromarcher/licsweep#readme","keywords":["license","licenses","compliance","audit","spdx","copyleft","gpl","dependencies","ci","cli","zero-dependency","devtools"],"repository":{"type":"git","url":"git+https://github.com/bobfromarcher/licsweep.git"},"description":"Audit the licenses of your installed npm dependencies - flag copyleft/unknown and fail CI on a deny-list. Zero dependencies.","maintainers":[{"name":"bobfromarcher","email":"chrisbellth@gmail.com"}],"readme":"# licsweep\n\n[![npm](https://img.shields.io/npm/v/@bobfromarcher/licsweep?color=cb3837&logo=npm)](https://www.npmjs.com/package/@bobfromarcher/licsweep)\n[![CI](https://github.com/bobfromarcher/licsweep/actions/workflows/ci.yml/badge.svg)](https://github.com/bobfromarcher/licsweep/actions/workflows/ci.yml)\n[![license](https://img.shields.io/npm/l/@bobfromarcher/licsweep?color=blue)](LICENSE)\n[![zero deps](https://img.shields.io/badge/dependencies-0-success)](package.json)\n\nAudits the licenses of your installed npm dependencies. It buckets every package by risk and can fail CI when a forbidden license shows up. One copyleft dependency can carry obligations you did not intend to take on, and this catches it before it ships. No dependencies, no AI.\n\n<p align=\"center\"><img src=\"demo.svg\" alt=\"licsweep summarizing dependency licenses\" width=\"500\"></p>\n\n## Install\n\n```bash\nnpm install -g @bobfromarcher/licsweep\n# or once:\nnpx @bobfromarcher/licsweep\n```\n\n## Usage\n\n```bash\nlicsweep [path] [options]\n```\n\n| Option | Description |\n| --- | --- |\n| `--check` | Exit 1 if any dependency matches `--deny` |\n| `--deny <list>` | Comma-separated licenses or categories to forbid |\n| `--flagged` | Show only weak-copyleft, copyleft and unknown packages |\n| `--markdown`, `--md` | Markdown report |\n| `--json` | Raw JSON |\n| `-h, --help` | Show help |\n| `-v, --version` | Show version |\n\n## Examples\n\n```bash\nlicsweep                          # summary of every dependency's license\nlicsweep --flagged                # only the ones worth a second look\nlicsweep --check --deny copyleft  # fail CI if any viral copyleft is present\nlicsweep --deny \"GPL*,AGPL*\"      # forbid specific SPDX ids (globs allowed)\nlicsweep --markdown > LICENSES.md\n```\n\n`--deny` accepts categories (`permissive`, `weak-copyleft`, `copyleft`, `unknown`) and license globs (`GPL*`, `AGPL-3.0`). With `--check` and no explicit list, it defaults to denying `copyleft,unknown`.\n\n## Gate it in CI\n\n```yaml\n# .github/workflows/licenses.yml\n- run: npx @bobfromarcher/licsweep --check --deny copyleft,unknown\n```\n\n## Risk buckets\n\n| Bucket | Examples | Meaning |\n| --- | --- | --- |\n| permissive | MIT, ISC, BSD, Apache-2.0, 0BSD, CC0 | Safe to ship in closed source |\n| weak-copyleft | LGPL, MPL-2.0, EPL, CDDL | File or library level obligations |\n| copyleft | GPL, AGPL, SSPL, OSL, EUPL | Viral, can require you to open-source |\n| unknown | missing or unrecognized | Investigate before shipping |\n\nSPDX expressions like `(GPL-3.0 OR MIT)` are resolved to their most permissive option, which matches how you are actually allowed to use them.\n\n## Development\n\n```bash\ngit clone https://github.com/bobfromarcher/licsweep\ncd licsweep\nnode test/test.js\n```\n\nCI runs the suite on Node 18, 20 and 22 across Linux, macOS and Windows.\n\n## License\n\nMIT, bobfromarcher.\n","readmeFilename":"README.md"}