Skip to content

License policy ​

A license policy fails the scan when a direct dependency is under a license you don't allow. It's off until you add one.

For pull requests: .dagsec.toml ​

Add .dagsec.toml to the root of the repository, on the default branch:

toml
[licenses]
block = ["GPL-3.0", "AGPL-3.0"]

A pull request that adds a dependency under a blocked license gets a failing check and a Licenses section in the comment:

md
### Licenses

| Package | Ecosystem | License |
|---|---|---|
| `some-gpl-lib` | npm | GPL-3.0-only |

`.dagsec.toml` blocks GPL-3.0, AGPL-3.0. Replace these packages or change the policy on the default branch.

On pull requests the file is read from the base branch, like .dagsecignore, so a pull request can't loosen the policy it's checked against. A malformed file prints a warning and is ignored rather than failing the scan.

For AI agents: team policy ​

Team owners can list blocked licenses on the dashboard's Team page, under Stop packages under these licenses. Members' AI agents are then stopped from installing a package under one of them, and told to pick another package. See Teams.

How licenses are matched ​

dagsec understands SPDX license expressions, as registries report them:

BlocklistPackage licenseBlocked?Why
GPL-3.0GPL-3.0-onlyYesVariants of an ID are covered: -only, -or-later, +
GPL-3.0GPL-3.0-or-laterYes
GPL-3.0LGPL-3.0NoLGPL is a different license
GPL-3.0AGPL-3.0NoAGPL is a different license
GPLGPL-2.0-onlyYesA family name covers every version
GPL-3.0MIT OR GPL-3.0NoYou may choose MIT
GPL-3.0MIT AND GPL-3.0YesYou must comply with both
GPL-2.0GPL-2.0-only WITH Classpath-exception-2.0YesAn exception doesn't change the license

Comparisons ignore case. A package whose registry reports no license is never blocked.

Limits ​

  • The policy covers direct dependencies of npm, PyPI and crates.io, whose registries report licenses. Transitive dependencies and Go, Maven and NuGet packages are not checked yet.
  • Registries report what package authors declare. dagsec doesn't read license files.