licensee/licensed
53.0
Adequate · 20 September 2026
4.6k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
Licensed is a command-line tool that detects and reports on the licenses of software dependencies across a wide range of package managers, including Ruby, JavaScript, Go, Java, and .NET. It enumerates dependencies from local project files, caches their metadata for offline compliance checking, and generates structured reports or third-party notice files. The system has evolved to support multiple ecosystems natively without external plugins, while entering low maintenance mode focused on security fixes.
How it got here
2018 — v4 architectural overhaul and multi-ecosystem support
16 changes.
The project underwent a major v4 restructuring, removing legacy commands and GitHub-specific license fetching in favor of a modular architecture with a new DependencyRecord class. This period focused on expanding built-in support for numerous package managers across diverse ecosystems, such as Rust, PHP, and Java, while simultaneously removing non-Ruby dependencies and self-contained executable builds.
2019 — CLI refactoring and reporting infrastructure
11 changes.
This period focused on restructuring the command-line interface into a class-based architecture and introducing a new environment command for configuration inspection. It also established a comprehensive reporting system with structured output formats and automatic notice generation, supported by extensive test coverage and migration logic for the v2 cache format.
2020–2023 — Expanded package manager support and test coverage
11 changes.
The project extended its dependency enumeration capabilities to support newer and diverse package managers, including Yarn Berry, Bundler 2.4+, Swift SPM, Rust Cargo, Go dep, and CocoaPods. This expansion was accompanied by the creation of comprehensive test fixtures and unit tests to ensure accurate license detection across these varied ecosystems.
Features
Add configurable content-based versioning for sources
A new helper module allows sources to determine their version based on file contents rather than Git history. Users can now configure a \version\_strategy\ to use a hash of the file contents (via XXHash64) as the version identifier, providing a stable version even when Git metadata is unavailable or inconsistent, while retaining Git-based versioning as the default for backward compatibility.
lib/licensed/sources/helpers · high confidence
Add source support for multiple package managers
Licensed now includes built-in sources for Bundler, Cargo, CocoaPods, Composer, Dep, Git Submodules, Go, Gradle, Manifest, Mix, NPM, and NuGet, enabling automatic license detection for Ruby, Rust, iOS, PHP, Go, Java, .NET, and JavaScript ecosystems without requiring external plugins or manual configuration.
lib/licensed/sources · high confidence
Add source-setup scripts for multiple package managers
Added new shell scripts in the script/source-setup directory to automate the setup of test fixtures for various package managers, including Bower, Bundler, Cabal, Cargo, CocoaPods, Composer, Go (dep and modules), Git Submodules, Mix, npm, NuGet, pip, pipenv, pnpm, and Swift. These scripts handle environment checks, fixture initialization, and dependency installation, supporting a -f flag to force clean-up and re-installation.
script/source-setup · high confidence
New environment command and refactored reporting infrastructure
Users can now run the new \environment\ command to inspect and report on the current Licensed configuration, including enabled sources, cache paths, and allowed/ignored licenses. This change introduces a new \DependencyRecord\ class to standardize how license and notice data is stored and compared, and replaces the previous reporting mechanism with a structured \Report\ object and a new \Reporter\ base class that uses explicit \begin\\ and \end\\ lifecycle hooks. Additionally, the Bundler source integration has been updated to handle missing specifications more gracefully by monkey-patching \LazySpecification\ to return \MissingSpecification\ objects instead of raising errors, ensuring dependency enumeration continues even when gems are not found.
licensed · high confidence
New reporters for structured output and notices generation
The \lib/licensed/reporters\ directory now includes new reporter implementations that expand how command results are presented and persisted. Users can now generate machine-readable reports in JSON or YAML formats via \JsonReporter\ and \YamlReporter\ (with YAML output sanitized to remove nil values). Additionally, a \NoticesReporter\ has been added to automatically write a THIRD PARTY NOTICES file containing license texts and notices for all dependencies. Existing commands like \list\, \status\, and \cache\ now use dedicated reporters (\ListReporter\, \StatusReporter\, \CacheReporter\) to provide more detailed, structured console output, including specific warnings, errors, and dependency counts.
lib/licensed/reporters · high confidence
Support for Yarn Berry (v2+) dependency enumeration
The tool now distinguishes between Yarn v1 and Yarn Berry (v2+) when enumerating project dependencies. A new \Yarn::Berry\ source class handles Yarn versions \>= 2.0 by parsing the output of \yarn info --json --manifest --recursive --all\, while the existing \Yarn::V1\ source (for versions \< 2.0) continues to use \yarn list\ and \yarn licenses list\. This ensures accurate dependency and license metadata extraction regardless of which Yarn version is in use.
lib/licensed/sources/yarn · high confidence
Removals
Removal of legacy command implementations
The \cache\, \list\, and \status\ command classes have been removed from the codebase. This eliminates the previous logic for caching license text to \.txt\ files, listing non-ignored dependencies, and checking license status against cached data, indicating a shift to a different implementation strategy for these core functionalities.
lib/licensed/command, lib/licensed/source · high confidence
Behavioural changes
Licensed v4 removes non-Ruby support and self-contained executable
This release marks the v4 update, which removes support for non-Ruby dependency sources and eliminates the self-contained executable build. The project has entered low maintenance mode, focusing only on security fixes. Users migrating from v3 should note that the executable is no longer provided, and those on v2 must use the \licensed migrate\ command to update their configuration files and cached records. The Ruby version has been bumped to 4.0.4, and the CI system has moved from Travis CI to GitHub Actions.
(repo-wide) · high confidence
Major architectural overhaul and CLI restructuring in Licensed
The \lib/licensed\ library has undergone a significant internal restructuring, moving from a flat command structure to a modular \Commands\ and \Reporters\ architecture. The CLI has been updated to support new commands (\notices\, \env\, \migrate\) and options (such as \--sources\ and \--format\), while the \--offline\ flag has been removed. Core classes have been refactored: \License\ is deleted and \Dependency\ now inherits from \Licensee::Projects::FSProject\, introducing version-aware dependency tracking and improved license text handling. Configuration logic has been updated to support a \root\ property and pattern-based matching for reviewed/ignored dependencies. Additionally, shell execution now raises informative errors on failure and handles non-UTF-8 encodings more robustly.
lib/licensed · high confidence
Major library restructuring and removal of GitHub license fetching
The core library has been significantly refactored to support a v2 architecture. The most notable behavioral change for users is the removal of automatic license fetching from GitHub; the code previously using the Octokit gem to retrieve license content from GitHub URLs has been deleted, meaning the tool no longer fetches license data from GitHub repositories directly. Additionally, the internal module structure has been reorganized: individual source loaders (such as Bundler, Bower, NPM, etc.) are now consolidated into a single 'sources' module, the 'License' class has been renamed to 'DependencyRecord', and new infrastructure for commands, reporters, and migrations has been introduced.
lib · high confidence
Migration to v2 cache format and bundler source naming
The v2 migration updates cached records to reflect the bundler source type change from 'rubygem' to 'bundler'. This involves renaming the 'rubygem' configuration key to 'bundler' in the config file, moving cached data from the 'rubygem' folder to 'bundler', and converting individual cached records from .txt files with YAML frontmatter to .dep.yml files. The new format stores license and notice text as structured YAML properties rather than plain text separated by dividers.
lib/licensed/migrations · high confidence
Refactored commands into a class-based architecture with new caching and notice generation capabilities
The command-line interface has been restructured around a new base \Command\ class, introducing distinct command classes for \cache\, \list\, \notices\, and \status\. This change adds a \cache\ command that stores dependency metadata to disk, allowing the \status\ command to optionally check compliance against these cached records (via the new \data\_source\ option) rather than live evaluation, and automatically cleans up stale cache files. A new \notices\ command has been added to generate dependency notice files from either live data or cached records. The \status\ command now provides more detailed error messages, including suggestions for similar reviewed entries when a dependency needs review, and warns about stale cache files. The \list\ command has been updated to support additional output fields like license keys.
lib/licensed/commands · high confidence
Separate setup scripts for Yarn v1 and Yarn Berry
The source-setup tooling now distinguishes between Yarn v1 and Yarn Berry (v2+). Two new scripts, script/source-setup/yarn/v1 and script/source-setup/yarn/berry, have been added to handle test fixture setup for each respective version, allowing developers to run yarn install in the correct fixture directory for the version they are testing.
script/source-setup/yarn · high confidence
Simplified bootstrap and added standard development scripts
The repository now provides a streamlined \script/bootstrap\ that configures Bundler to install gems into \vendor/gems\ and runs \bundle install\, replacing the previous complex logic that attempted to install fixtures for Bower, npm, Go, and Haskell. Additionally, new scripts are introduced to standardize development workflows: \script/setup\ delegates to the Rake setup task, \script/test\ allows running all tests or specific test files/suites via arguments, \script/bump-production-gems\ updates a specific list of production dependencies conservatively, and \script/verify-gem-version\ ensures the built gem's metadata matches the source code version and git tags.
script · high confidence
Support for Bundler 2.4.1+ local search behavior
The Bundler source adapter now includes a new definition extension that overrides the \specs\ and \bundler\_query\ methods to ensure compatibility with Bundler 2.4.1 and higher. This change adapts to internal implementation changes in newer Bundler versions, specifically handling how the \bundler\ gem itself is resolved and preventing \Gem::NotFound\ errors during license detection.
lib/licensed/sources/bundler · high confidence
Test coverage
Add test fixtures for new and updated dependency sources; Added Cabal test fixtures; Added CocoaPods test fixture; Added NuGet test fixture with source configuration; Added Rust/Cargo test fixture; Added Swift test fixtures and initial SPM support; Added test coverage for command execution, caching, listing, status, and notices; Added test coverage for dependency source implementations; Added test coverage for the reporter subsystem; Added test fixtures and configuration for bundler tests; Added test fixtures for Go dep dependency management; Added test fixtures for Gradle multi-project builds; Added test fixtures for Mix-based Elixir projects; Added test fixtures for Yarn Berry (v3.1.1); Added test fixtures for license manifest validation; Added test helpers for command, reporter, shell, and source testing; Added tests for V2 migration logic; Added tests for Yarn v1 and Yarn Berry source enumerators; Added tests for content versioning helper; Expanded test coverage for core dependency and configuration logic; Removed legacy command tests; Removed test suite for source detection modules; Updated Go test fixture to include vendored dependencies and module structure.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 53.
Lenses
- Code Health 98
- Architecture 38
- Maturity 52
- Readiness 82
- Security 73
Changes since last survey
- 300 commits — 288 feature/other, 12 fixes
By area
- (repo) — 132 commits
- .github/workflows — 67 commits
- (root) — 46 commits
- .licenses/bundler — 38 commits
- lib/licensed — 11 commits
- .github/dependabot.yml — 3 commits
- test/commands — 1 commit
- test/fixtures — 1 commit
- test/sources — 1 commit
Notable commits
- fix: Fix another test
- fix: Fix assertions in status tests
- fix: Fix compatibility with bundler 4.x
- fix: Fix error message for pip list command
- fix: Fix for pip packages
- fix: Fix lint issue
- fix: Fix test failure
- fix: Merge pull request #856 from TailorBrands/fix/pip-separator-issue
- fix: Merge pull request #953 from Bo98/status-test-fix
- fix: Revert Ruby version to 3.2.10
- fix: Revert Ruby version to 3.2.9
- fix: Various release fixes
- change: Add Brewfile and accordingly bump ruby-version
- change: Add Ruby 4 to the GitHub workflow
- change: Add license file for ostruct
- change: Allow lowercase paths for .dist-info
- change: Auto-update license files
- change: Auto-update license files
- change: Auto-update license files
- change: Auto-update license files for PR #876
- …and 280 more
Architecture
- 0 containers · 1 bounded contexts · 0 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
licensee/licensed was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2a1d6c185a1934d388751d2936b0bed2fd42764a — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.