Dependencies that oblige you to do something — and what that something is.
Most packages do not need a page. A dependency under MIT, Apache-2.0 or BSD carries the same answer no matter what you are building: keep the notice, ship whatever you like. Writing that out once per package would say nothing the license reference does not already say.
The packages below are the other kind. Some are licensed such that the verdict changes with the way the software reaches its users — safe inside a company, an obligation the moment it is hosted or handed to a customer. Others come back allowed everywhere and still oblige you to hand over source for the parts the license covers, which is a very different position to be in than a permissive license that only asks you to keep a notice. Both are worth naming, because the license identifier alone does not tell you which of those you are holding.
@vercel/og — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.faunadb — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.jointjs — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-android-arm64 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-darwin-arm64 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-darwin-x64 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-freebsd-x64 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-linux-arm-gnueabihf — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-linux-arm64-gnu — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-linux-arm64-musl — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-linux-x64-gnu — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-linux-x64-musl — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-win32-arm64-msvc — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.lightningcss-win32-x64-msvc — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.nodebb — GPL-3.0, which applies in 3 of the 5 shipping models.p5 — LGPL-2.1. Nothing is triggered while it is linked dynamically, which is how npm normally loads it — statically linking or bundling it is a different answer.rollup-plugin-dts — LGPL-3.0-only. Nothing is triggered while it is linked dynamically, which is how npm normally loads it — statically linking or bundling it is a different answer.satori — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.certifi — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.mautrix — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.mysql-connector-python — GPL, which applies in 3 of the 5 shipping models.paramiko — LGPL-2.1. Nothing is triggered while it is linked dynamically, which is how PyPI normally loads it — statically linking or bundling it is a different answer.pathspec — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.pikepdf — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.psycopg2 — LGPL. Nothing is triggered while it is linked dynamically, which is how PyPI normally loads it — statically linking or bundling it is a different answer.psycopg2-binary — LGPL. Nothing is triggered while it is linked dynamically, which is how PyPI normally loads it — statically linking or bundling it is a different answer.pyload-ng — AGPL-3.0-only, which applies in 4 of the 5 shipping models.pyqt5 — GPL-v3, which applies in 3 of the 5 shipping models.pyqt6 — GPL-3.0-only, which applies in 3 of the 5 shipping models.pyside2 — LGPL-3.0-only. Nothing is triggered while it is linked dynamically, which is how PyPI normally loads it — statically linking or bundling it is a different answer.pyside6 — LGPL-3.0-only OR GPL-2.0-only OR GPL-3.0-only. Nothing is triggered while it is linked dynamically, which is how PyPI normally loads it — statically linking or bundling it is a different answer.text-unidecode — Artistic-1.0 OR GPL-2.0-or-later, which applies in 3 of the 5 shipping models.tqdm — MPL-2.0 AND MIT. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.weblate — GPL-3.0-or-later, which applies in 3 of the 5 shipping models.cyphar.com/go-pathrs — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/alecthomas/chroma/v2 — MIT AND OFL-1.1. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/canonical/lxd — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/go-sql-driver/mysql — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/grafana/alerting — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/grafana/alerting/apps/historian — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/grafana/grafana — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/grafana/schemads — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/grafana/tempo — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/hashicorp/cap — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul — BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/consul-awsauth — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul-net-rpc — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul/api — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul/envoyextensions — MPL-2.0 AND BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/consul/proto-public — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul/sdk — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/consul/troubleshoot — MPL-2.0 AND BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/errwrap — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-bexpr — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-checkpoint — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-cleanhttp — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-connlimit — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-discover — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-discover/provider/gce — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-immutable-radix — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-immutable-radix/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-memdb — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-multierror — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-plugin — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-raftchunking — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-retryablehttp — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-rootcerts — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-secure-stdlib/awsutil/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-secure-stdlib/parseutil — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-secure-stdlib/strutil — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-sockaddr — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-uuid — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/go-version — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/golang-lru — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/golang-lru/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/hcdiag — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/hcl — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/hcl/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/hil — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/memberlist — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/nomad — BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/raft — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/raft-autopilot — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/raft-boltdb/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/raft-wal — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/serf — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/terraform — BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/vault — BUSL-1.1, which applies in 5 of the 5 shipping models.github.com/hashicorp/vault-plugin-auth-alicloud — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/vault/api — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/vault/api/auth/gcp — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/vault/sdk — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/hashicorp/vic — Apache-2.0 AND BSD-3-Clause AND non-standard AND MIT AND ISC AND BSD-2-Clause AND Zlib AND WTFPL AND CC-BY-4.0 AND CC-BY-3.0 AND TCL AND GPL-2.0-or-later AND bzip2-1.0.6 AND curl AND BSD-4-Clause-UC AND Rdisc AND CC-BY-SA-3.0 AND HPND AND OLDAP-2.8 AND BSD-4-Clause AND RSA-MD AND FSFAP AND FSFULLR AND MPL-1.1 AND GPL-3.0-or-later AND Beerware AND SSH-OpenSSH AND OpenSSL AND BSD-Source-Code AND blessing AND LGPL-2.1-or-later AND BSL-1.0 AND LGPL-2.0-or-later AND LGPL-3.0-or-later AND NCSA AND GPL-2.0-only AND BSD-3-Clause-Clear AND GPL-1.0-or-later AND CC0-1.0 AND GFDL-1.3-no-invariants-or-later AND Spencer-94 AND MPL-2.0 AND BSD-3-Clause-No-Nuclear-Warranty AND HPND-sell-variant AND GPL-2.0 AND GPL-3.0 AND LGPL-2.0 AND LGPL-2.1 AND LGPL-3.0 AND GPL-1.0 AND GFDL-1.1 AND GFDL-1.2 AND GFDL-1.3 AND Artistic-1.0 AND Artistic-2.0 AND MS-PL AND CC-BY-SA-4.0 AND AFL-2.1 AND OFL-1.1 AND LPPL-1.3c AND OSL-1.1 AND CC-BY-SA-2.0, which applies in 5 of the 5 shipping models.github.com/hashicorp/yamux — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/joyent/triton-go — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/juju/juju — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/letsencrypt/challtestsrv — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/letsencrypt/pebble/v2 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/mattermost/mattermost-server — Apache-2.0 AND AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/minio/minio — AGPL-3.0, which applies in 4 of the 5 shipping models.github.com/mitchellh/cli — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/opencontainers/go-digest — Apache-2.0 AND CC-BY-SA-4.0, which applies in 3 of the 5 shipping models.github.com/shoenig/go-m1cpu — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.github.com/syncthing/syncthing — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.pgregory.net/rapid — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.app_units — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.apple-bundles — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.apple-codesign — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.apple-flat-package — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.apple-xar — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.bitmaps — MPL-2.0+. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cbindgen — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.colored — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cooked-waker — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cpio-archive — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cryptographic-message-syntax — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cssparser — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.cssparser-macros — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.dtoa-short — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.dwrote — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.epaint_default_fonts — (MIT OR Apache-2.0) AND OFL-1.1 AND Ubuntu-font-1.0, which applies in 5 of the 5 shipping models.freedesktop_entry_parser — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.helix-core — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.helix-lsp — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.helix-term — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.helix-tui — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.helix-view — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.im — MPL-2.0+. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.im-rc — MPL-2.0+. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.io_plugin — GPL-3.0-only, which applies in 3 of the 5 shipping models.language — GPL-3.0, which applies in 3 of the 5 shipping models.librsvg — LGPL-2.1-or-later, which applies in 5 of the 5 shipping models.mdbook — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.mozjs — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.mozjs_sys — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.nucleo — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.nucleo-matcher — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.nvim-rs — LGPL-3.0, which applies in 5 of the 5 shipping models.option-ext — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.paths — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.perf — GPL-3.0, which applies in 3 of the 5 shipping models.plane-split — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.selectors — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.settings — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.shuffling-allocator — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.sized-chunks — MPL-2.0+. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.smartstring — MPL-2.0+. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.snippet — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.swapper — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-bundle-flac — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-bundle-mp3 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-codec-aac — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-codec-pcm — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-codec-vorbis — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-core — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-format-isomp4 — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-format-ogg — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-format-riff — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-metadata — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.symphonia-utils-xiph — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.tracy-rs — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.tree-house — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.tree-house-bindings — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.uluru — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webdriver — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webpki-root-certs — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webpki-roots — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webrender — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webrender_api — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.webrender_build — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.wr_glyph_rasterizer — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.x509-certificate — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.zeitstempel — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.bundler-audit — GPL-3.0-or-later, which applies in 3 of the 5 shipping models.diff-lcs — MIT AND Artistic-1.0-Perl AND GPL-2.0-or-later, which applies in 5 of the 5 shipping models.domain_name — BSD-2-Clause AND BSD-3-Clause AND MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.llhttp-ffi — MPL-2.0. Allowed in all 5 shipping models, which is not the same as obligation-free: source for the parts this license covers has to reach whoever receives the software, however you ship it.pitchfork — GPL-2.0+ AND Ruby, which applies in 3 of the 5 shipping models.raindrops — LGPL-2.1+. Nothing is triggered while it is linked dynamically, which is how Ruby gem normally loads it — statically linking or bundling it is a different answer.rchardet — LGPL. Nothing is triggered while it is linked dynamically, which is how Ruby gem normally loads it — statically linking or bundling it is a different answer.rdoc — Ruby AND GPL-2.0-only, which applies in 3 of the 5 shipping models.sidekiq — LGPL-3.0. Nothing is triggered while it is linked dynamically, which is how Ruby gem normally loads it — statically linking or bundling it is a different answer.ttfunk — Nonstandard AND GPL-2.0-only AND GPL-3.0-only, which applies in 5 of the 5 shipping models.Entries come from lockfiles that have been scanned here and from packages that have been looked up directly. A package is listed when its license either produces different verdicts across the five shipping models, or obliges you to disclose source in all of them, or restricts what you may use it for at all. Permissive licenses are ruled out by construction: keeping the notice is the whole obligation, and the license page says that better than a page per package could. The per-package pages are generated from the same rules the scanner uses, so a page never disagrees with a scan result.
Your lockfile probably contains one of these. Find out which.
Check your whole manifest →License data last reviewed .
LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.
Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).