Generate a third-party IP (TPIP) and licence report
Problem and when to use it
Use cd-generate-spdx to document dependency licences for a third-party IP
(TPIP) review and to check them against the project's accepted-licence policy.
It can support an OpenChain compliance workflow; a generated report alone does
not certify compliance. For the SPDX documents produced by the same command,
see SPDX generation.
Inputs and example
Configure your language plugin and set ACCEPTED_THIRD_PARTY_LICENCES and any
documented manual checks in pyproject.toml. Choose an existing output
directory:
mkdir -p licensing
cd-generate-spdx --output-dir licensing
The selected plugin must support metadata extraction. It uses tools suited to
the project's language to obtain dependency and licence information for the
shared report and accepted-licence policy. Check the
plugin documentation
for language-specific prerequisites and support.
An audit covers the installed environment, so run it for each supported
platform if dependencies differ by operating system. Review unknown licences
and packaged notices rather than assuming a missing value means permission.
For Go projects, CDS downloads module dependencies automatically before the
scan. Pass --skip-dependency-download when those dependencies have already
been prefetched and you want to skip that extra work.
Output
Find third_party_IP_report.html, .csv, .json and .txt in the output directory,
alongside SPDX documents when generation is enabled. In this repository the
HTML report is published to GitHub Pages after a release regenerates docs/.
The HTML report has download links for the accompanying CSV, JSON and text
reports when these files are kept together in the same directory.
Each dependency also has an advisory ALLOW, REVIEW, DENY or UNKNOWN
licence assessment with a reason and rule ID. Documented REVIEW findings
are shown as MANUALLY_REVIEWED with the review explanation. The assessment is separate from
the configured accepted-licence check. See
dependency licence assessment for the
embedded rules, SPDX expression handling, optional project overrides and the
opt-in --lookup-scancode option for missing licence information.
GitHub Actions example
Once the project and its dependencies are installed:
- run: mkdir -p licensing && cd-generate-spdx --output-dir licensing
- uses: actions/upload-artifact@v4
with:
name: third-party-ip-report
path: licensing/
Related commands: cd-check-licence-compliance
for reports without SPDX documents, cd-generate-spdx
and cd-license-files.