License Cop

Yet another license checker tool for your dependencies; focused on simplicity.

  • typescript
  • cli
  • ci

License-cop is a command-line tool that analyses all of a developer’s production npm dependencies and verifies that each one has a license type the developer is happy to depend on.

License-cop achieves this by inspecting the SPDX identifier defined in packages’ package.json files and matches it against a predefined list of identifiers the developer has said they’re comfortable with.

Getting Started

After you’ve installed license-cop with your package manager of choice, run the init command in the directory of your project where you keep your package.json file. For example, those using the npm package manager would run:

npx license-cop init

The command above will create a .licenses.json file; however, you can use many different file types, including YAML and JavaScript.

To execute license-cop using this config file, simply run the following command from the same directory:

npx license-cop

Licenses & Packages

The License-cop config file contains two primary config options.

The licenses option should have a string array as its value. These strings should be all of the SPDX Identifiers that you’re allowing your dependencies to be licensed under. For example, if you’re comfortable depending on packages that use either the MIT or Apache-2.0 licenses, then your licenses option would look like this:

{
  "$schema": "https://license-cop.js.org/schema.json",
  "licenses": ["MIT", "Apache-2.0"]
}

When using the configuration above, if all your dependencies use either the MIT or Apache-2.0 license identifier, then license-cop will exit with a 0 exit code. If a dependency happened to be licensed under the GPL-3.0-only identifier, then license-cop would exit with an exit code of 1.

The packages config option, which is also a string array, is a place for you to list the specific npm packages that you’re comfortable depending on, no matter what their license is, e.g.:

{
  "$schema": "https://license-cop.js.org/schema.json",
  "packages": ["lodash", "axios@^2.0.0", "react@<19"]
}

While optional, it’s suggested that you pin any packages to a specific version.

Config Inheritance

If you wish to re-use the same license-cop configuration in multiple locations (perhaps across multiple repositories), then you can make use of the extends config option.

Values can be:

  • The name of an installed npm package (optionally prefixed with npm:) that contains a license-cop config file.
  • The name of a public GitHub repository (prefixed with github:) that contains a license-cop config file. This currently only supports config files called exactly .licenses.json.
  • A URL to a license-cop config file. Currently, this only supports JSON-like config files.
{
  "$schema": "https://license-cop.js.org/schema.json",
  "extends": "npm:your-package",
  // or
  "extends": "github:you/your-repo",
  // or
  "extends": "https://your.path/config.json"
}

@license-cop/permissive

As a reasonable starting point and to help reduce boilerplate, license-cop also publishes the @license-cop/permissive npm package. This package contains a base config that’s a good starting point for both open-source and commercial products. You can see what’s currently included in the permissive configuration here.