dsh-license-obligation-proof
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@dsh-license-obligation-proofverify the license obligation proof for release candidate 3"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
dsh-license-obligation-proof
Offline, deterministic evidence that every required compliance artifact for a supplied release decision was delivered: NOTICE, license text, source offer, source bundle, or modification notice. Inputs and reports contain hashes, obligation codes and bounded metadata only—never license bodies, copyright text, package source or secrets.
This is deliberately not another license scanner. dsh-license-guard already scans node_modules, normalizes SPDX identifiers and applies allow/deny policy. This plugin starts after scanning and expert review: it verifies that the declared component set, decisions, obligations, delivered artifact digests, distinct receipts and fresh zero-unresolved closure agree. It does not scan packages, normalize SPDX, interpret a license, or provide legal advice.
npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.jsonDSH tools: dsh_license_obligation_inspect and dsh_license_obligation_verify. MCP exposes equivalent proof-only inline tools. Reports explicitly retain provesComponentSetExhaustive: false and provesLegalCompliance: false.
References: SPDX License Expressions and OpenChain ISO/IEC 5230.
MIT licensed.
This server cannot be deployed
Maintenance
Related MCP Connectors
- mcpOAuthco.policyforge
Generate, audit, and maintain legal policies that match what your code actually does.
Verify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account.
Independent static verification for exact immutable public GitHub commits.
Stamp content with permanent, verifiable provenance. Hash locally, verify free forever.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables defining and verifying evidence contracts for claims in READMEs, releases, or product pages using constrained verifiers and generating hash-chained receipts and reports.10MIT
- FlicenseNot gradedqualityCmaintenanceEnforces protocol-driven development by validating requirements, designs, scope, and acceptance evidence, while maintaining immutable, traceable governance archives.-
- AlicenseNot gradedqualityCmaintenanceEnables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.MIT
- AlicenseNot gradedqualityCmaintenanceEnables offline verification that a supplied DSH workflow adhered to declared duty-separation constraints, producing a redacted, content-addressed JSON verdict.MIT