{"id":28736418,"url":"https://github.com/trustsource/ts-legalcheck","last_synced_at":"2026-02-02T10:37:47.817Z","repository":{"id":298874499,"uuid":"1000782143","full_name":"TrustSource/ts-legalcheck","owner":"TrustSource","description":"A solver allowing to evaluate licenses for obligations based on existing circumstances ","archived":false,"fork":false,"pushed_at":"2026-01-28T14:44:39.000Z","size":214,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-01-29T06:25:56.028Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/TrustSource.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-06-12T10:07:05.000Z","updated_at":"2026-01-28T14:44:45.000Z","dependencies_parsed_at":"2025-09-05T15:13:19.706Z","dependency_job_id":"3ad9e6dc-2627-4a4d-8b01-e2cba4223bc8","html_url":"https://github.com/TrustSource/ts-legalcheck","commit_stats":null,"previous_names":["trustsource/ts-legalcheck"],"tags_count":4,"template":false,"template_full_name":null,"purl":"pkg:github/TrustSource/ts-legalcheck","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TrustSource%2Fts-legalcheck","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TrustSource%2Fts-legalcheck/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TrustSource%2Fts-legalcheck/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TrustSource%2Fts-legalcheck/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/TrustSource","download_url":"https://codeload.github.com/TrustSource/ts-legalcheck/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TrustSource%2Fts-legalcheck/sbom","scorecard":{"id":1237071,"data":{"date":"2025-09-05T13:26:19Z","repo":{"name":"github.com/TrustSource/ts-legalcheck","commit":"cf2fc2d742102765010f8b55377ff54a56dde737"},"scorecard":{"version":"v5.1.1","commit":"cd152cb6742c5b8f2f3d2b5193b41d9c50905198"},"score":4.2,"checks":[{"name":"Maintained","score":0,"reason":"project was created in last 90 days. please review its contents carefully","details":["Warn: Repository was created in last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#binary-artifacts"}},{"name":"Code-Review","score":0,"reason":"Found 1/21 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Info: topLevel 'contents' permission set to 'read': .github/workflows/buildnPushDocker.yml:2","Info: topLevel 'contents' permission set to 'read': .github/workflows/buildnPushPyPi.yml:2","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:18","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#vulnerabilities"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#signed-releases"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/buildnPushDocker.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushDocker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/buildnPushDocker.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushDocker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/buildnPushDocker.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushDocker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/buildnPushDocker.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushDocker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/buildnPushPyPi.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushPyPi.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/buildnPushPyPi.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushPyPi.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/buildnPushPyPi.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/buildnPushPyPi.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scorecard.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/TrustSource/ts-legalcheck/scorecard.yml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating python:3.12-alpine to python:3.12-alpine@sha256:02a73ead8397e904cea6d17e18516f1df3590e05dc8823bd5b1c7f849227d272","Warn: pipCommand not pinned by hash: Dockerfile:11-12","Warn: pipCommand not pinned by hash: Dockerfile:11-12","Warn: pipCommand not pinned by hash: .github/workflows/buildnPushPyPi.yml:21","Info:   2 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   5 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   3 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 2 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#branch-protection"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: GNU Affero General Public License v3.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#license"}},{"name":"Dependency-Update-Tool","score":0,"reason":"no update tool detected","details":["Warn: no dependency update tool configurations found"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dependency-update-tool"}},{"name":"CI-Tests","score":0,"reason":"0 out of 1 merged PRs checked by a CI test -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#ci-tests"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#fuzzing"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/buildnPushPyPi.yml:10"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#packaging"}},{"name":"Contributors","score":3,"reason":"project has 1 contributing companies or organizations -- score normalized to 3","details":["Info: found contributions from: eacg"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#contributors"}}]},"last_synced_at":"2025-09-05T15:31:21.855Z","repository_id":298874499,"created_at":"2025-09-05T15:31:21.855Z","updated_at":"2025-09-05T15:31:21.855Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29010451,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-02T10:37:29.253Z","status":"ssl_error","status_checked_at":"2026-02-02T10:37:28.644Z","response_time":58,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-06-16T01:08:53.871Z","updated_at":"2026-02-02T10:37:47.812Z","avatar_url":"https://github.com/TrustSource.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# TS-Legalcheck\n\n**ts-legalcheck** is a tool for automatically checking legal obligations and violations related to the use of software components licensed under one or more open-source licenses within a project. It consists of a powerful constraints engine leveraging the state-of-the-art SMT solver Z3 and several flexible and easily extendable sets of rules describing constraints and definitions extracted from various open-source licenses. The internal format for constraints and definitions allows formal definitions without limitations, enabling not only switching between different models but also combining them. One great example is the use of the OSADL checklists, available as a model for **ts-legalcheck**, together with a set of violation rules developed by EACG GmbH.\n\n## Introduction\n\nThe following diagram represents the main functional principle of **ts-legalcheck**. The tool accepts as input a model consisting of data extracted from open-source licenses. It contains known *rights*, *obligations*, and *terms*, as well as different rules describing in which situations certain obligations apply and, for example, which conditions may violate license usage.\n\n![alt text](docs/TS-Legalcheck-Diag.svg)\n\nBesides a model, the **ts-legalcheck** engine also expects user input describing the legal settings of a project, which define different aspects such as distribution model, distribution form, or modification of third-party components used in the project. We refer to such input as a use case or legal situation. Based on the model, legal settings, and the set of open-source licenses used in the project, the engine decides whether the usage of certain licenses is possible in the provided use case and, if so, provides a set of obligations that must be fulfilled.\n\nThe different models created by EACG GmbH can be found in the `data/LicenseConstraints_vX.[json|toml]` files, and the OSADL model in the `data/osadl/LicenseConstraints_v1.0.toml` file.\n\n## Installation\n\n**ts-legalcheck** is available as a PyPI package as well as a ready-to-use Docker image.\n\n### PyPI\n\n**Requirements**: Python \u003e= 3.10\n\n```bash\npip install ts-legalcheck\n```\n\n\n\n## Docker\n\n```bash\ndocker pull trustsource/ts-legalcheck\n```\n\n## Usage\n\n### Installed via PyPI\n\nWhen **ts-legalcheck** is installed from PyPI, it can be used directly as a command-line tool from the shell.\n\n#### License Test\n\nThe **test** command is used to check whether a use case violates license usage and, if not, provides a list of obligations that must be fulfilled:\n\n```bash\nts-legalcheck test -l \u003cLICENSE\u003e -d \u003cMODEL LOCATION\u003e \u003cUSE-CASE LOCATION\u003e \n```\n\n##### Example:\n\nThe following example tests if the *Apache-2.0* license can be used in a project with the legal settings from `examples/sc01_ProprietarySoftware.toml` and, if so, which obligations must be fulfilled.\n\n```bash\nts-legalcheck test -l Apache-2.0 -d data/LicenseConstraints_v4.5.toml examples/sc01_ProprietarySoftware.toml\n```\n\n### Installed as a Docker image\n\nWhen **ts-legalcheck** is pulled as a Docker image, it can be executed within a Docker container. For example, the previous example can be executed using Docker as follows:\n\n```bash\ndocker run -it --rm -v ./examples:/examples trustsource/ts-legalcheck test -l Apache-2.0 -d /data/LicenseConstraints_v4.5.toml /examples/sc01_ProprietarySoftware.toml\n```\n\n**NOTE**: No extra installation step is required; by executing this command, the **ts-legalcheck** image is pulled automatically.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrustsource%2Fts-legalcheck","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftrustsource%2Fts-legalcheck","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftrustsource%2Fts-legalcheck/lists"}