Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Open-Source Licence Report and NOTICE File Generator

Every dependency’s licence from your lockfiles, classed and checked against your policy.

Developer Uses live data Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: every count by licence class and policy result, with the first packages and licences of each table (up to 10).
  • Locked until you unlock it: download and copy.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Dependency files

Paste a file instead

The name tells the report how to read the text. Leave it empty and the kind is recognised from the content.

Lookups and policy

Only package names and versions are sent, to the npm registry, PyPI and deps.dev. Your files stay in this browser.

For mirrors, proxies and company registries of public packages: their names and versions then go to the public registries too. Git, URL and folder dependencies are never looked up.

Leave off for what you ship. Turn on for a front-end app whose bundler includes packages from devDependencies.

Licence policy: No policy
Deny these licence classes

SPDX ids, one per line; * matches the rest of an id. With ids here, every other licence needs a review.

An id listed exactly wins over a class; a denied id also covers it with a WITH exception.

Your policy is kept in this browser for your next visit.

Next steps

For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.

About the Open-Source Licence Report and NOTICE File Generator

Find out which licences you ship before you release. Add your lockfiles, manifests or SBOM, and the report lists every dependency with its licence as an SPDX identifier, classed as permissive, weak copyleft, strong copyleft, network copyleft, not open source or unknown. It checks them against your own allow and deny lists, and makes a THIRD-PARTY-NOTICES file with the licence texts, a CSV or Excel report and a CycloneDX SBOM with the licences in it.

Licences the files already state (package-lock.json, composer.lock and SBOMs do) are read from them. The rest are looked up in public registries — the npm registry, PyPI, and deps.dev for Go, Cargo, Maven, NuGet and RubyGems — and only each package’s name and version are sent. Your files stay in your browser.

Without a pass the result is a free preview: every count by licence class and policy result, with the first packages and licences of each table (up to 10). The NOTICE file, the CSV, Excel and SBOM files and the copied summary unlock with a Premium pass.

How to use it

  1. Add your dependency files: drop or choose lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, poetry.lock, uv.lock, Pipfile.lock, go.sum, Cargo.lock, composer.lock, Gemfile.lock, gradle.lockfile, NuGet’s packages.lock.json), manifests (package.json, requirements.txt, go.mod) or an SBOM (CycloneDX JSON or XML, SPDX 2 or 3). Several files are merged into one report.
  2. Choose what counts: leave Include development dependencies off for what you ship, and keep Look up the licences the files do not state on unless you want only what the files say.
  3. Set a licence policy if you have one: start from No strong or network copyleft or Permissive only, deny whole classes, or list allowed and denied SPDX ids (GPL-* matches every GPL id). The page keeps it in this browser.
  4. Press Make the report. Packages that need attention come first — denied, then those needing a review, then the most restrictive licences — and the tables filter by class, policy result and ecosystem.
  5. Export the THIRD-PARTY-NOTICES.txt file, a CSV or Excel report or a CycloneDX SBOM, or copy a Markdown summary for a pull request: these unlock with a Premium pass, and without one the page shows the free preview.

Examples

A web shop and its Python worker (the page’s example)
Input
package-lock.json: 13 packages with their licences in the file (and TypeScript as a development dependency)
requirements.txt: 8 pinned packages, looked up on PyPI
Policy: No strong or network copyleft
Result
21 packages under 18 licences: 13 permissive, 4 weak copyleft, 2 strong copyleft, 1 network copyleft, 1 unknown
Denied: pymupdf 1.25.1 (AGPL-3.0-only), mysql-connector-python 9.1.0 (GPL-2.0-only), tinymce 7.6.0 (GPL-2.0-or-later)
Needs review: highcharts 11.4.8 (its licence field is a web address, not an SPDX id)

TypeScript is left out because it is development-only. PyPI writes mysql-connector-python’s licence as “GNU GPLv2 (with FOSS License Exception)” and pymupdf’s as “GNU AFFERO GPL 3.0”; the report reads both as SPDX ids and says so.

A choice of licences
Input
node-forge 1.3.1, licence (BSD-3-Clause OR GPL-2.0)
Result
BSD-3-Clause OR GPL-2.0-only — permissive: you may use it under BSD-3-Clause, so the NOTICE file lists it there

GPL-2.0 is an old SPDX id for GPL-2.0-only. Under OR the least restrictive option counts; under AND, as in (MIT AND Zlib), every part applies.

PyPI classifiers instead of a licence
Input
idna 3.10: no licence field, classifier “License :: OSI Approved :: BSD License”
Result
BSD (the clauses are not stated) — permissive, read from the classifiers

Common uses

  • Checking a release for GPL, AGPL or source-available licences before it ships.
  • Making the third-party notices file a mobile app, desktop installer or web bundle has to include.
  • Answering a customer’s or an acquirer’s request for the licences in your product.
  • Adding licences to an SBOM for a security or procurement review.
  • Reviewing the licences a pull request adds, with the Markdown summary in the review.

The licence classes

  • Permissive (MIT, BSD, Apache-2.0, ISC and the rest of the Blue Oak Council’s permissive list): use and ship the code in any program; keep its copyright and licence notice.
  • Weak copyleft (LGPL, MPL, EPL, CDDL, CC-BY-SA): changes to the licensed files or library stay under its licence; the rest of your program does not have to. GPL with a linking exception, such as the Classpath exception, also counts here.
  • Strong copyleft (GPL): a program that includes the code and is given to others must be released under the same licence.
  • Network copyleft (AGPL, EUPL, OSL): as strong copyleft, and letting people use the program over a network counts too.
  • Not open source (Business Source, Elastic, SSPL, PolyForm, non-commercial Creative Commons licences): source-available or restricted terms that need the owner’s permission for many uses.
  • Unknown: no licence was found, or its text is not one the report recognises.

The permissive list and the copyleft families follow the Blue Oak Council (copyleft families); SSPL is classed as not open source because the Open Source Initiative has not approved it. Every identifier comes from the SPDX License List.

Where each licence comes from

A licence the file states is used as it is: package-lock.json from npm 7 on, composer.lock and SBOMs carry them. The others are looked up: npm packages in the npm registry, Python packages on PyPI (its licence expression, then its licence field, then its classifiers), and Go, Cargo, Maven, NuGet and RubyGems packages on deps.dev. Licences written in words (“Apache License, Version 2.0”, “GPLv3”, “BSD”) are read as SPDX identifiers, and the report notes every such reading.

Packages from git, a URL, a folder or a private registry are not looked up. A file that names a mirror or company registry of public packages can be looked up in the public registry once you allow it.

Licence expressions and your policy

An SPDX licence expression combines licences: MIT OR Apache-2.0 is a choice, MIT AND Zlib means both apply, GPL-2.0-only WITH Classpath-exception-2.0 adds an exception, and -or-later allows later versions. Your policy reads them the same way: under OR a package passes when one choice is allowed, under AND every part must be.

An id you list exactly (with its exception, if any) wins over a class rule, a denied id beats an allowed one, and patterns such as BSD-* work in both lists. With an allow list, every licence not on it needs a review. A package without a recognised licence always needs a review.

What the NOTICE file contains

Every package with its version, licence and source repository; then each licence used once, with its standard text from the SPDX License List and the packages under it. Templates such as MIT and BSD leave out their placeholder copyright line, because each package has its own.

For npm packages, tick Put each npm package’s own licence file in the NOTICE file: the page then fetches each package’s licence file from unpkg.com (by name and version) and includes it as published, copyright line and all — packages with the same file share one copy — together with the NOTICE files of Apache-2.0 packages, which the Apache License 2.0 (section 4(d)) asks you to pass on. Packages whose files cannot be fetched keep the standard text.

The file also lists the packages to check before you ship (no recognised licence) and the Apache-2.0 packages whose NOTICE files still need a look.

Limitations

  • The report reads declared licences — what package metadata and SBOMs state. It does not scan source code, so it cannot find licences of copied files, vendored code or bundled binaries.
  • A version range (package.json, an unpinned requirement) is looked up as the newest release. Add the lockfile for the versions you really install.
  • Registry metadata can be incomplete or out of date, and a licence can change between versions: check the packages that matter.
  • Packagist (PHP) cannot be asked from a browser; composer.lock already states each package’s licence.
  • Packages’ own licence files can be included for npm only; for other ecosystems the NOTICE file uses the standard licence texts, without each package’s copyright line. Licences outside the bundled texts are named with a link instead of their text.
  • Not legal advice: what a licence requires depends on how you use and distribute the software. Have a lawyer review decisions that matter.

Privacy

Your files are read in this browser and never uploaded. For licences the files do not state, the page sends each package’s name and version — nothing else from your files — to the npm registry, PyPI or deps.dev, and to unpkg.com for npm packages’ own licence files when you ask for them; switch lookups off and nothing is sent. Your policy and options are kept in this browser for your next visit.

Frequently asked questions

What do I get without a pass?

Without a pass, Open-Source Licence Report and NOTICE File Generator shows every count by licence class and policy result, with the first packages and licences of each table (up to 10). Until you unlock it, the result can’t be downloaded or copied. A Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

Why is a package listed as “Unknown”?

Its file and the registry give no licence, the licence is not written as an SPDX identifier (a web address, “SEE LICENSE IN LICENSE.txt”, a custom text), or the lookup was not made or failed. The notes under the package say which; read its licence file and add a rule to your policy if you accept it.

What does (MIT OR Apache-2.0) mean for my policy?

OR is a choice: you may use the package under either licence, so it passes when one of them is allowed, and the report classes it by the least restrictive one. AND means every licence applies, so the strictest part decides.

Does the THIRD-PARTY-NOTICES file cover every attribution requirement?

It names every package and includes the licence texts, which the MIT, BSD and Apache licences ask to pass on. Most of them also ask for the copyright notice: for npm packages, tick the option to include each package’s own licence file (copyright line included) and the NOTICE files of Apache-2.0 packages. For other ecosystems, add the copyright lines from each package’s licence file; the file lists the Apache-2.0 packages whose NOTICE files need a look.

What exactly is sent to the registries?

For each package the file does not give a licence for, your browser asks the registry for that package’s name and version, as any package manager does. Nothing else from your files is sent, the requests carry no cookies, and switching lookups off sends nothing.

Can other tools read the SBOM?

Yes: it is CycloneDX 1.6 JSON, with each package’s purl, version, scope and declared licences, which SBOM and dependency tools such as OWASP Dependency-Track import.

Why does a package show its newest version?

Its file gives a version range (package.json, a requirement without ==), so the report looks up the newest release. A lockfile gives the exact versions you install.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.