check_license_compliance
Aggregate SPDX licenses across Maven transitive dependencies and flag risky or incompatible ones against a project license or disallow list. Missing metadata returns review, never a false ok.
Instructions
Aggregate SPDX licenses across the transitive closure of one or more Maven GAVs (deps.dev GetDependencies + GetVersion) and flag risky/incompatible licenses against a projectLicense posture or an explicit disallow list (SPDX ids and/or categories). Verdicts: ok / review / violation. Missing license metadata degrades to review, never a false ok. Heuristic policy signal — not legal advice; see notes[].
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| disallow | No | Optional override: SPDX ids and/or category names to flag as violation. When set, replaces the default disallow set entirely. | |
| dependencies | Yes | Root GAVs whose transitive graphs are scanned. Version is required. Capped at MAX_LICENSE_COMPLIANCE_ROOTS. | |
| projectLicense | No | Optional project SPDX id or license name. A permissive posture (or omitted projectLicense) defaults to disallowing strong-copyleft, network-copyleft, and proprietary. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| notes | Yes | ||
| errors | No | ||
| policy | Yes | ||
| partial | Yes | ||
| results | Yes | ||
| summary | Yes | ||
| capabilityUnavailable | No |