Skip to content

Guardrails / supply-chain

No component carries a licence the team refuses ​

supply-chain/disallowed-licenses@v1

No component in the bill of materials uses a licence the team has decided it won't ship.

Idsupply-chain/disallowed-licenses
Versionv1
Categorysupply-chain
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectssbom

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
sbomThe components a build says it ships, read from the bill of materials it already wrote (CycloneDX or SPDX, in JSON, XML or tag-value) and normalized into one list with the licence each component names.none

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "supply-chain/disallowed-licenses@v1",
              "severity": "error",
              "with": {
                  "licenses": "AGPL-1.0,AGPL-3.0,SSPL-1.0,BUSL-1.1,CC-BY-NC,Commons-Clause,Elastic-2.0"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
licensesComma separated SPDX identifiers that are a violation. A component's licence matches when the identifier appears in it, so AGPL-3.0 covers AGPL-3.0-only and AGPL-3.0-or-later.AGPL-1.0,AGPL-3.0,SSPL-1.0,BUSL-1.1,CC-BY-NC,Commons-Clause,Elastic-2.0GUARDRAIL_INPUT_LICENSES

How to fix ​

Replace the components named in the violations, or make a deliberate exception by removing that licence from the list this guardrail is configured with.

A copyleft licence in a distributed artifact is a legal obligation, not a preference: some require you to offer the source of the whole work to anyone who receives the binary. Finding one at release time is expensive; finding it in the pull request that added it is not.

More in supply-chain ​

All 6 supply-chain guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412