Permissive
Use, modify, ship. Keep the notice, nothing else is owed.
MITApache-2.0BSD-3-ClauseISC0BSDWe use analytics and ad-measurement cookies (Google, Meta). Nothing is sold, and you can decline.
Every dependency, direct and transitive, classified and overridable to match your legal posture.
Every SPDX identifier maps to a family your legal team owns. Expressions are resolved, overrides are yours.
Use, modify, ship. Keep the notice, nothing else is owed.
MITApache-2.0BSD-3-ClauseISC0BSDChanges to the library go back. Your own code stays yours.
LGPL-2.1MPL-2.0EPL-2.0Linking it means opening your product. Blocked by default, transitive included.
GPL-2.0GPL-3.0AGPL-3.0No SPDX in the metadata, a custom text, a broken field. Somebody has to read it.
no SPDXSEE LICENSE INcustomOR picks the least restrictive option, AND keeps the strictest, WITH applies the exception.
MIT OR GPL-3.0-only(Apache-2.0 AND MIT)GPL-2.0-only WITH Classpath-exception-2.0Legal cleared LGPL-2.1 for the whole org? Set it once, every project follows.
LGPL-2.1 → permissiveorg-wideSPDX extraction, expression-aware risk, org overrides and per-package ignore.
express4.21.2"license": "MIT"MITpermissiveRead from package.json during the SCA scan: MIT is permissive.
License extraction shares the manifest parse step that the SCA scan already performs.
Every SPDX identifier maps to a category your team owns. Override defaults, add custom proprietary licenses, reset whenever policy changes.
MPL-2.0weak copyleftdefaultLicenseRef-acme-eulapermissivecustomEPL-2.0permissiveoverrideEngineering filters by branch and ecosystem to focus on what they own.
express4.21.2MITallowedaxe-core4.10.0MPL-2.0reviewffmpeg-static5.2.0GPL-3.0-or-laterblockedLicense extraction runs on every SCA scan, in each of these ecosystems.
package.json"express": "^4.21.2"express4.21.2MITallowedPoint at an ecosystem to see a real dependency and its license.Tap an ecosystem to see a real dependency and its license.
The documentation walks you through setup, configuration and every option.
Read the docsPlatform Overview / Key Features
License Compliance
License categories, SPDX expressions, manual overrides, organization-wide classifications and supported ecosystems.
Every SPDX identifier maps to one of four categories. Permissive, Weak Copyleft, Strong Copyleft or Unknown. Based on a built-in classification covering 100+ licenses. Organisations can override any classification to match their legal policy; overrides apply immediately to every project in the org.
The package lands in the Unknown bucket. From the license summary you can open the package and assign the correct SPDX identifier manually; the package then re-categorises and feeds the right counters in the summary. Unknown licenses are surfaced first in the dashboard so they don't quietly accumulate.
No. License extraction reuses the manifest parse step the SCA scan already performs. There's no separate job, no second pipeline, no incremental scan window. License data appears in the same dashboard alongside vulnerability findings.
Yes. The organisation-level configuration accepts custom entries with a chosen classification (Permissive, Weak Copyleft, Strong Copyleft or Unknown). Useful for in-house licenses or vendor agreements that aren't part of SPDX but still need to be tracked alongside open-source licenses.
OR picks the least restrictive option (`MIT OR GPL-3.0-only` → effective risk None). AND picks the most restrictive option (`MIT AND GPL-3.0-only` → effective risk High). WITH evaluates the base license with the exception applied (`GPL-2.0-only WITH Classpath-exception-2.0` → GPL-2.0 with Classpath exception). The dashboard shows both the raw expression and the resolved category.
One command wires every coding agent on your machine to CybeDefend: your business rules, your compliance frameworks, and guards that block destructive calls before they fire.
npx -y @cybedefend/vibedefend@latest install