Skip to main content
Glama
dongsheng123132

dsh-license-obligation-proof

dsh-license-obligation-proof

Офлайн-детерминированное доказательство того, что каждый обязательный артефакт соответствия для решения о выпуске поставляемого компонента был доставлен: NOTICE, текст лицензии, предложение исходного кода, пакет исходного кода или уведомление об изменениях. Входные данные и отчёты содержат только хеши, коды обязательств и ограниченные метаданные — никогда не содержат тексты лицензий, тексты авторских прав, исходный код пакетов или секреты.

Это намеренно не ещё один сканер лицензий. dsh-license-guard уже сканирует node_modules, нормализует идентификаторы SPDX и применяет политику разрешения/запрета. Этот плагин начинает работу после сканирования и экспертной проверки: он проверяет, что объявленный набор компонентов, решения, обязательства, дайджесты доставленных артефактов, отдельные квитанции и свежее нулевое незакрытое замыкание согласованы. Он не сканирует пакеты, не нормализует SPDX, не интерпретирует лицензию и не предоставляет юридические консультации.

npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.json

Инструменты DSH: dsh_license_obligation_inspect и dsh_license_obligation_verify. MCP предоставляет эквивалентные встроенные инструменты, ориентированные только на доказательства. В отчётах явно сохраняются provesComponentSetExhaustive: false и provesLegalCompliance: false.

Ссылки: SPDX License Expressions и OpenChain ISO/IEC 5230.

Лицензия MIT.

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables defining and verifying evidence contracts for claims in READMEs, releases, or product pages using constrained verifiers and generating hash-chained receipts and reports.
    23
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enforces protocol-driven development by validating requirements, designs, scope, and acceptance evidence, while maintaining immutable, traceable governance archives.
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables verifying that recorded build accesses stay within a declared closure by inspecting and verifying hash-only receipts, without executing builds or making network requests.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.
    MIT

View all related MCP servers

Related MCP Connectors

  • Generate, audit, and maintain legal policies that match what your code actually does.

  • Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.

  • Independent static verification for exact immutable public GitHub commits.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/dongsheng123132/dsh-license-obligation-proof'

If you have feedback or need assistance with the MCP directory API, please join our Discord server