dsh-license-obligation-proof
dsh-license-obligation-proof
离线、确定性的证据,证明供应发布决策所需的每一项合规工件均已交付:NOTICE、许可证文本、源代码要约、源代码包或修改通知。输入和报告仅包含哈希、义务代码和受限元数据——绝不包含许可证正文、版权文本、包源代码或机密。
这有意不是另一个许可证扫描器。dsh-license-guard 已经扫描 node_modules、规范化 SPDX 标识符并应用允许/拒绝策略。此插件在扫描和专家审查之后启动:它验证声明的组件集、决策、义务、已交付工件摘要、不同收据和最新的零未解决闭包是否一致。它不扫描包、规范化 SPDX、解释许可证或提供法律建议。
npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.jsonDSH 工具:dsh_license_obligation_inspect 和 dsh_license_obligation_verify。MCP 提供等效的仅证明内联工具。报告明确保留 provesComponentSetExhaustive: false 和 provesLegalCompliance: false。
参考:SPDX License Expressions 和 OpenChain ISO/IEC 5230。
MIT 许可。
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables defining and verifying evidence contracts for claims in READMEs, releases, or product pages using constrained verifiers and generating hash-chained receipts and reports.23MIT
- FlicenseNot gradedqualityCmaintenanceEnforces protocol-driven development by validating requirements, designs, scope, and acceptance evidence, while maintaining immutable, traceable governance archives.
- AlicenseNot gradedqualityCmaintenanceEnables verifying that recorded build accesses stay within a declared closure by inspecting and verifying hash-only receipts, without executing builds or making network requests.MIT
- AlicenseNot gradedqualityCmaintenanceEnables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.MIT
Related MCP Connectors
Generate, audit, and maintain legal policies that match what your code actually does.
Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.
Independent static verification for exact immutable public GitHub commits.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/dongsheng123132/dsh-license-obligation-proof'
If you have feedback or need assistance with the MCP directory API, please join our Discord server