Sign inSign up

getreadystack/spdx-license-field-lint

By getreadystack

Updated about 3 hours ago

Reads the licence field in the open manifest and names every deprecated SPDX id, invalid string, PEP

Image
0

39

getreadystack/spdx-license-field-lint repository overview

SPDX License Field Lint for package.json, pyproject.toml and Cargo.toml

Reads the licence field in the open manifest and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation - with the exact replacement text.

Run

docker run --rm -v "$PWD":/work getreadystack/spdx-license-field-lint /work/file

The same 73 rules as the VS Code extension, in a container. Mount a folder on /work.

Free

  • Lints the licence declarations in the manifest you have open against all 73 rules and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation, with the exact replacement text.
  • --rules lists every rule

With a licence ($29 once)

  • Runs the same 73 rules over every manifest in the repository in one pass, exports the licence inventory as CSV, JSON or HTML for your SBOM, and rewrites a wrong identifier in place across files.
docker run --rm -e READYSTACK_LICENSE=<key> -v "$PWD":/work getreadystack/spdx-license-field-lint --dir /work --ci

An open-source licence audit runs 40-160 hours and thousands to tens of thousands of dollars per program; commercial SCA licence-compliance subscriptions start around $1,500/year.

Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

{ "mcpServers": { "spdx-license-field-lint": { "command": "npx", "args": ["-y", "@readystack/spdx-license-field-lint", "--mcp"] } } }

Tools: check_text and check_file (free) · check_dir (licence; the full sweep is free for 7 days). The agent gets every finding with the line number.

Use in CI

- name: SPDX License Field Lint for package.json, pyproject.toml and Cargo.toml
  run: npx -y @readystack/spdx-license-field-lint --dir . --ci

(container: docker run --rm -v "$PWD:/work" getreadystack/spdx-license-field-lint --dir /work --ci)

Try the full run free for 7 days — no key needed. Then one licence, 7-day refund, no questions. Set READYSTACK_LICENSE=<key> or run --license <key> once.

Get a licence

Tag summary

Content type

Image

Digest

sha256:3954ad757

Size

46.1 MB

Last updated

about 3 hours ago

docker pull getreadystack/spdx-license-field-lint