dsh-license-obligation-proof
dsh-license-obligation-proof
オフラインで決定的な証拠:供給されたリリース決定に必要なすべてのコンプライアンス成果物(NOTICE、ライセンス文、ソース提供、ソースバンドル、修正通知)が提供されたことを示します。入力とレポートには、ハッシュ、義務コード、および制限されたメタデータのみが含まれ、ライセンス本文、著作権テキスト、パッケージソース、シークレットは含まれません。
これは意図的に別のライセンススキャナではありません。dsh-license-guard はすでに node_modules をスキャンし、SPDX識別子を正規化し、許可/拒否ポリシーを適用します。このプラグインはスキャンと専門家レビューの後に開始されます:宣言されたコンポーネントセット、決定、義務、提供された成果物のダイジェスト、個別の受領書、および新規の未解決ゼロクロージャが一致することを検証します。パッケージのスキャン、SPDXの正規化、ライセンスの解釈、法的アドバイスの提供は行いません。
npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.jsonDSHツール:dsh_license_obligation_inspect と dsh_license_obligation_verify。MCPは同等の証明専用インラインツールを公開します。レポートは明示的に provesComponentSetExhaustive: false と provesLegalCompliance: false を保持します。
参照:SPDX License Expressions と OpenChain ISO/IEC 5230。
MITライセンス。
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables defining and verifying evidence contracts for claims in READMEs, releases, or product pages using constrained verifiers and generating hash-chained receipts and reports.23MIT
- FlicenseNot gradedqualityCmaintenanceEnforces protocol-driven development by validating requirements, designs, scope, and acceptance evidence, while maintaining immutable, traceable governance archives.
- AlicenseNot gradedqualityCmaintenanceEnables verifying that recorded build accesses stay within a declared closure by inspecting and verifying hash-only receipts, without executing builds or making network requests.MIT
- AlicenseNot gradedqualityCmaintenanceEnables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.MIT
Related MCP Connectors
Generate, audit, and maintain legal policies that match what your code actually does.
Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.
Independent static verification for exact immutable public GitHub commits.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/dongsheng123132/dsh-license-obligation-proof'
If you have feedback or need assistance with the MCP directory API, please join our Discord server