New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@readystack/spdx-license-field-lint

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@readystack/spdx-license-field-lint

Reads the licence field in the open manifest and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation - with the exact replacement text.

latest
Source
npmnpm
Version
0.1.5
Version published
Maintainers
1
Created
Source

SPDX License Field Lint for package.json, pyproject.toml and Cargo.toml

Reads the licence field in the open manifest and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation - with the exact replacement text.

Install

npx @readystack/spdx-license-field-lint file

Node 18+. The same 73 rules as the VS Code extension, from a terminal or CI.

Free

  • Lints the licence declarations in the manifest you have open against all 73 rules and names every deprecated SPDX id, invalid string, PEP 639 leftover and copyleft obligation, with the exact replacement text.
  • --rules lists every rule

With a licence ($29 once)

  • Runs the same 73 rules over every manifest in the repository in one pass, exports the licence inventory as CSV, JSON or HTML for your SBOM, and rewrites a wrong identifier in place across files.
@readystack/spdx-license-field-lint --dir ./templates --report html --out report.html

An open-source licence audit runs 40-160 hours and thousands to tens of thousands of dollars per program; commercial SCA licence-compliance subscriptions start around $1,500/year.

Use from an AI agent (MCP)

Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:

{ "mcpServers": { "spdx-license-field-lint": { "command": "npx", "args": ["-y", "@readystack/spdx-license-field-lint", "--mcp"] } } }

Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.

Use in CI

- name: SPDX License Field Lint for package.json, pyproject.toml and Cargo.toml
  run: npx -y @readystack/spdx-license-field-lint --dir . --ci

(container: docker run --rm -v "$PWD:/work" getreadystack/spdx-license-field-lint --dir /work --ci)

The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.

Get a licence

Keywords

spdx

FAQs

Package last updated on 25 Sep 2026

Related posts