Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .dependency-radar/dependency-radar/import-graph.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
{
"files": {
"src/aggregator.ts": [
"src/license.ts",
"src/types.ts",
"src/utils.ts"
],
Expand All @@ -14,10 +15,14 @@
"src/types.ts",
"src/utils.ts"
],
"src/generated/spdx.ts": [],
"src/index.ts": [
"src/aggregator.ts",
"src/report.ts"
],
"src/license.ts": [
"src/generated/spdx.ts"
],
"src/report-assets.ts": [],
"src/report.ts": [
"src/report-assets.ts",
Expand Down Expand Up @@ -45,7 +50,9 @@
"packages": {
"src/aggregator.ts": [],
"src/cli.ts": [],
"src/generated/spdx.ts": [],
"src/index.ts": [],
"src/license.ts": [],
"src/report-assets.ts": [],
"src/report.ts": [],
"src/runners/importGraphRunner.ts": [],
Expand All @@ -58,7 +65,9 @@
"packageCounts": {
"src/aggregator.ts": {},
"src/cli.ts": {},
"src/generated/spdx.ts": {},
"src/index.ts": {},
"src/license.ts": {},
"src/report-assets.ts": {},
"src/report.ts": {},
"src/runners/importGraphRunner.ts": {},
Expand Down
39 changes: 37 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,18 @@ Dependency Radar is a local-first CLI tool that inspects a Node.js project’s i
- Not a bundler or build tool
- Not a dependency updater


## License Scanning

Dependency Radar validates SPDX licenses declared in `package.json` and can infer licenses from `LICENSE` files when declarations are missing or invalid. It works offline and uses a bundled SPDX identifier list (generated at build time) with no runtime network access. Each dependency gets a structured license record with:

- Declared SPDX validation (including deprecated IDs and `WITH` exceptions)
- Inferred SPDX license (with confidence: `high`, `medium`, `low`) based on deterministic text matching
- A status (`declared-only`, `inferred-only`, `match`, `mismatch`, `invalid-spdx`, `unknown`) to make review decisions easier

This logic applies to all dependencies (direct and transitive). Inferred licenses are never treated as authoritative over valid declared SPDX expressions.


## Setup

```bash
Expand Down Expand Up @@ -158,8 +170,31 @@ export interface DependencyRecord {
};
};
compliance: {
license: string; // License string read from the installed package.json
licenseRisk: 'green' | 'amber' | 'red'; // Risk classification derived from license string
license: {
declared?: {
spdxId: string; // SPDX ID or expression from package.json
expression: boolean; // True when SPDX expression (AND/OR/WITH)
deprecated: boolean; // True if SPDX ID is deprecated
valid: boolean; // True if SPDX ID/expression is valid
};
inferred?: {
spdxId: string; // SPDX ID inferred from LICENSE text
confidence: 'high' | 'medium' | 'low'; // Heuristic confidence
};
exception?: {
id: string; // SPDX exception id
deprecated: boolean; // True if exception is deprecated
valid: boolean; // True if exception id is valid
};
status:
| 'declared-only'
| 'inferred-only'
| 'match'
| 'mismatch'
| 'invalid-spdx'
| 'unknown';
};
licenseRisk: 'green' | 'amber' | 'red'; // Risk classification derived from declared/inferred SPDX ids
};
security: {
summary: {
Expand Down
8 changes: 4 additions & 4 deletions dependency-radar.html

Large diffs are not rendered by default.

Loading