LPM CLI

lpm licenses

List declared dependency licenses and enforce license policies in CI.

List the licenses declared by installed dependencies, or reject packages that violate a license policy.

lpm licenses [OPTIONS]

Quickstart

lpm install
lpm licenses

Use the inventory for dependency reviews. Add a policy to stop CI when dependencies contain copyleft licenses, missing declarations, or denied declarations.

LPM CLI supports npm, private registries, and the LPM.dev Registry. This command reads local files and makes no registry requests.

Examples

# Save a machine-readable inventory
lpm licenses --json > licenses.json

# Reject copyleft licenses and missing declarations
lpm licenses --fail-on copyleft,missing

# Reject specific declarations
lpm licenses --deny GPL-3.0-only,AGPL-3.0-only

# Write the full report and fail CI on policy violations
lpm licenses --json --fail-on missing --deny GPL-3.0-only > licenses.json

For a reusable policy, define an uncached task:

lpm.json
{
  "tasks": {
    "deps:licenses": {
      "command": "lpm licenses --fail-on copyleft,missing",
      "cache": false
    }
  }
}
lpm run deps:licenses

There is no dedicated license configuration in lpm.json. The task's command holds the policy. cache: false checks the current installation each time.

For a different policy on one run, run the command directly. An explicit lpm.json task command takes precedence in lpm run.

Inventory and project scope

The command selects the applicable lpm.lock and project manifest. A nested directory uses the same project as its parent.

Inside a workspace member, the inventory uses that member's dependencies. Dependencies used only by siblings do not appear.

Installed manifests supply the license declarations. LPM CLI follows aliases and separate dependency instances through the installation.

Missing or invalid required manifests stop the command. Packages omitted for platform compatibility, and dependencies reachable only through them, do not appear.

ScopeMeaning
requiredRequired through a production or peer dependency path
optionalRequired only through optional paths
excludedRequired only through development paths

Required paths take precedence over optional paths. Optional paths take precedence over development paths.

All listed dependency packages participate in policy checks, including development packages marked excluded. The root project's license appears in JSON for context only.

The inventory records declarations. It does not inspect license-file contents or establish legal permission.

License declarations

LPM CLI trims license text and removes empty or duplicate declarations. It accepts string declarations and legacy object or array forms.

JSON retains individual declarations in licenses. The license_expression field joins multiple declarations with AND, with parentheses that preserve compound expressions.

For example, separate BSD-3-Clause and MIT OR Apache-2.0 declarations produce:

BSD-3-Clause AND (MIT OR Apache-2.0)

Policy checks

Copyleft licenses

lpm licenses --fail-on copyleft

The copyleft check recognizes GPL-family and other known reciprocal identifiers inside license expressions. It uses the same classification as lpm audit.

Missing declarations

lpm licenses --fail-on missing

A package has missing license metadata when its declarations are empty or contain only these markers:

  • NOASSERTION
  • UNLICENSED
  • NONE
  • PROPRIETARY
  • SEE LICENSE IN ...

Comparisons ignore case and surrounding whitespace. A license-file reference counts as missing because the command does not read that file.

Denied declarations

lpm licenses --deny GPL-3.0-only
lpm licenses --deny GPL-3.0-only --deny AGPL-3.0-only
lpm licenses --deny 'MIT OR GPL-3.0-only'

--deny compares each complete declaration after trimming whitespace and ignoring case. It does not search for individual identifiers inside an expression.

For example, --deny GPL-3.0-only does not match MIT OR GPL-3.0-only. Deny the complete expression or use the copyleft policy.

The check uses individual declarations in licenses. It does not compare the combined license_expression generated from several declarations.

Repeat --fail-on or --deny, or separate values with commas. Any matching policy causes exit code 1.

JSON and CI output

Without --json, the command prints a dependency table. With --json, standard output contains one object:

FieldContents
successfalse when a license policy fails
rootProject name, version, and declared licenses
packagesDependency identities, scopes, declarations, and policy results
countNumber of dependency entries
summaryCounts for copyleft, missing, and denied declarations
policyActive policies and their combined failure result

On a policy failure, the JSON report remains complete and the command exits 1. File or manifest errors use the JSON error format.

Fix common problems

If a lockfile or required manifest is missing, repair the installation:

lpm install
lpm licenses --json

If a policy fails, inspect packages and the summary counts. Use lpm graph to find the dependency path.

For a release document that includes relationships and provenance, use lpm sbom.

Flags

FlagEffect
--fail-on <copyleft|missing>Fail on matching dependency packages. Repeatable and comma-separated.
--deny <LICENSE>Fail on an exact declared license expression. Repeatable and comma-separated.

See the global flags for --json and other shared options.

See also

  • lpm install — prepare installed manifests and the lockfile
  • lpm sbom — export CycloneDX or SPDX
  • lpm query — select packages with :copyleft or :no-license
  • lpm audit — inspect vulnerabilities and package behavior
  • lpm graph — find dependency paths