Check project and dependency licence compliance
Problem and when to use it
Use cd-check-licence-compliance as a CI gate or local check when you need to
assess the project and its dependencies against the configured licence policy
without generating SPDX documents. The command writes no files by default.
Inputs and example
Select a language plugin that provides project metadata. Configure
ACCEPTED_THIRD_PARTY_LICENCES and any documented manual reviews in
[ProjectConfig] in pyproject.toml. Then run:
cd-check-licence-compliance
To keep the third-party IP summaries for review, create an output directory and pass it to the command:
mkdir -p licensing
cd-check-licence-compliance --output-dir licensing
The optional --output-dir (-o) writes third_party_IP_report.html, .csv,
.txt and .json. It does not create .spdx files. The reports are written
before the compliance check, so they remain available if the check fails.
For Go projects, CDS downloads module dependencies automatically before running
licence analysis so CI does not need a separate go mod download all step.
Pass --skip-dependency-download when your environment already prefetches the
required dependencies and you want to skip that extra work.
Result
The command succeeds when the discovered project and dependency licences meet
the configured policy, including documented manual reviews. It fails if a
licence does not meet that policy, the selected plugin cannot supply metadata,
or report generation fails. If FAIL_ON_INCOMPLETE_LICENCE_AUDIT is enabled,
missing dependencies, unknown licences and undocumented exemptions also fail
the check. Results depend on the dependencies installed in the audited
environment.
The command also prints ALLOW, REVIEW, MANUALLY_REVIEWED, DENY and UNKNOWN dependency
counts. These advisory results do not change exit codes unless a project
explicitly opts into assessment gating.
Pass --lookup-scancode to consult
ScanCode LicenseDB for exact
identifiers whose category or assessment rule is missing. The lookup is opt-in; see
dependency licence assessment
for the limits and report provenance.
To generate SPDX tag-value documents as well as reports, use
cd-generate-spdx. See
third-party IP reporting for more on reviewing
the summaries and project configuration
for the shared settings.