LicenseGuard

Packages with license obligations

Dependencies whose answer depends on how you ship them.

Most packages do not need a page. A dependency under MIT, Apache-2.0 or BSD carries the same answer no matter what you are building: keep the notice, ship whatever you like. Writing that out once per package would say nothing the license reference does not already say.

The packages below are the other kind. Each one is licensed such that the verdict changes with the way the software reaches its users — safe inside a company, an obligation the moment it is hosted or handed to a customer. Those are the ones worth naming, because the license identifier alone does not tell you which situation you are in.

npm

PyPI

How a package gets on this list

Entries come from lockfiles that have been scanned here. A package is listed only when its license produces different verdicts across the five shipping models, which rules out every permissive license by construction. The per-package pages are generated from the same rules the scanner uses, so a page never disagrees with a scan result.

Your lockfile probably contains one of these. Find out which.

Check your whole manifest →

License data last reviewed .

LicenseGuard reports information derived from published license texts and dependency manifests. It is not legal advice and using it does not create an attorney-client relationship. Results reflect license metadata as declared; they do not identify every obligation or violation. Consult qualified counsel for decisions that matter.

Listed in the official MCP registry, on Glama and on Smithery. Source on GitHub (Apache-2.0).