LicenseGuard

Packages with license obligations

Dependencies that oblige you to do something — and what that something is.

Most packages do not need a page. A dependency under MIT, Apache-2.0 or BSD carries the same answer no matter what you are building: keep the notice, ship whatever you like. Writing that out once per package would say nothing the license reference does not already say.

The packages below are the other kind. Some are licensed such that the verdict changes with the way the software reaches its users — safe inside a company, an obligation the moment it is hosted or handed to a customer. Others come back allowed everywhere and still oblige you to hand over source for the parts the license covers, which is a very different position to be in than a permissive license that only asks you to keep a notice. Both are worth naming, because the license identifier alone does not tell you which of those you are holding.

npm

PyPI

Go module

Rust crate

Ruby gem

How a package gets on this list

Entries come from lockfiles that have been scanned here and from packages that have been looked up directly. A package is listed when its license either produces different verdicts across the five shipping models, or obliges you to disclose source in all of them, or restricts what you may use it for at all. Permissive licenses are ruled out by construction: keeping the notice is the whole obligation, and the license page says that better than a page per package could. The per-package pages are generated from the same rules the scanner uses, so a page never disagrees with a scan result.

Your lockfile probably contains one of these. Find out which.

Check your whole manifest →

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).