No component carries a licence the team refuses
supply-chain/disallowed-licenses@v1
No component in the bill of materials uses a licence the team has decided it won't ship.
| Id | supply-chain/disallowed-licenses |
| Version | v1 |
| Category | supply-chain |
| Default severity | error |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | sbom |
Collectors
This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.
| Collector | Gathers | Inputs it is given |
|---|---|---|
sbom | The components a build says it ships, read from the bill of materials it already wrote (CycloneDX or SPDX, in JSON, XML or tag-value) and normalized into one list with the licence each component names. | none |
The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.
Configuration
{
"guardrails": {
"failOn": "error",
"checks": [
{
"use": "supply-chain/disallowed-licenses@v1",
"severity": "error",
"with": {
"licenses": "AGPL-1.0,AGPL-3.0,SSPL-1.0,BUSL-1.1,CC-BY-NC,Commons-Clause,Elastic-2.0"
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
licenses | Comma separated SPDX identifiers that are a violation. A component's licence matches when the identifier appears in it, so AGPL-3.0 covers AGPL-3.0-only and AGPL-3.0-or-later. | AGPL-1.0,AGPL-3.0,SSPL-1.0,BUSL-1.1,CC-BY-NC,Commons-Clause,Elastic-2.0 | GUARDRAIL_INPUT_LICENSES |
How to fix
Replace the components named in the violations, or make a deliberate exception by removing that licence from the list this guardrail is configured with.
A copyleft licence in a distributed artifact is a legal obligation, not a preference: some require you to offer the source of the whole work to anyone who receives the binary. Finding one at release time is expensive; finding it in the pull request that added it is not.
More in supply-chain
supply-chain/components-licensed. Enough of the components in the bill of materials name a licence for the inventory to tell you what the artifact may be distributed under.supply-chain/disallowed-components. No component in the bill of materials is one the team has decided it won't ship, however it got there.supply-chain/no-critical-vulnerabilities. No dependency of the build has an open finding at or above the severity the team gates on.supply-chain/sbom-present. An SBOM was produced for this build, so the components that went into the artifact are recorded at build time instead of reconstructed later.supply-chain/sbom-standard-format. The bill of materials uses a standard format other tools can read, and declares which version of that format it follows.