For permissive, the first results are mikepenz/aboutlibraries (AboutLibraries is a developer tool that collects and validates third-party library licenses at compile time, fitting the license compliance aspect well even though it is not a general directory), github/choosealicense.com (This project provides an open-source license selector, comparison tool, and compliance guide to help developers choose and understand software licenses) and google/licenseclassifier (Google licenseclassifier is a specialized developer tool for classifying and identifying software licenses in source trees, making it a relevant component for software compliance despite missing a broader curated directory). aboutcode-org/scancode-toolkit and google/osv-scanner round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
Compare permissive software licenses like MIT, Apache, and BSD. Hand-picked open-source options ranked by terms and restrictions to find the best fit.
AboutLibraries is an open-source license compliance tool designed to collect, validate, and display third-party library licenses within software projects. It functions as a system for gathering dependency metadata at compile time and validating those libraries against a list of approved licenses to ensure legal compliance. The project provides a license validation engine that can enforce compliance by halting the build process when unauthorized licenses are detected. It also includes a set of visual components for rendering dependency and funding information within a user interface for third-
AboutLibraries is a developer tool that collects and validates third-party library licenses at compile time, fitting the license compliance aspect well even though it is not a general directory.
This project provides a set of reference tools and guides designed to help developers select and compare legal licenses for software and content. It includes an open source license selector and a compliance guide that explains copyright and the legal implications of publishing code without a license. The resource includes a legal license comparison tool for evaluating permissions, conditions, and limitations, as well as a directory for non-software licenses applicable to datasets, media, fonts, and hardware designs. It also provides a multi-license compatibility reference to manage mixed lice
This project provides an open-source license selector, comparison tool, and compliance guide to help developers choose and understand software licenses.
Google licenseclassifier is a specialized developer tool for classifying and identifying software licenses in source trees, making it a relevant component for software compliance despite missing a broader curated directory.
ScanCode Toolkit is a software composition analysis tool and scanning framework designed to identify open-source licenses and copyright statements in source code and binary files. It functions as an open-source license detector, a dependency vulnerability scanner, and a generator for standardized software bills of materials in SPDX and CycloneDX formats. The project is built as a plugin-based scanning framework, allowing the integration of custom detection logic, specialized analyzers, and modified scanning behaviors at runtime. It distinguishes itself through the ability to produce formal le
ScanCode Toolkit is a source code analysis and license scanning tool rather than a directory or catalog of licenses, though it handles license identification and SPDX generation for compliance.
osv-scanner is a software composition analysis tool and vulnerability scanner that checks project dependencies and container images against the Open Source Vulnerabilities database. It functions as a dependency remediation tool and can be integrated into custom Go applications as a programmable security library. The project distinguishes itself through a remediation workflow that includes an interactive terminal user interface and automated scripting for upgrading vulnerable packages in lockfiles and manifests. It employs call-graph reachability analysis to determine if vulnerable code is act
This is a vulnerability scanner rather than a license directory or classification tool, making it the wrong category despite including some license validation features.
Snipe-IT is an open-source, web-based inventory management system designed to track organizational assets and digital resources. It functions as a centralized platform for maintaining detailed records of hardware, software licenses, and equipment assignments, providing a structured environment for managing company resources. The system specializes in hardware lifecycle tracking, covering the entire journey of physical equipment from initial procurement and deployment to maintenance, repairs, and eventual retirement. It also includes dedicated functionality for software license compliance, all
Snipe-IT is an IT asset management system designed to track physical hardware and software licenses within an organization, making it a neighbouring business tool rather than a developer-focused software license catalog or compliance tool.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Dependency-Track is a software composition analysis and vulnerability management platform rather than a directory or catalog of open-source licenses, making it a neighbouring security tool rather than the requested collection.
Licensed is a command-line utility for auditing open-source dependencies and validating compliance policies across multi-language packages. Written in Ruby, the tool scans project dependencies to identify external libraries, discovers associated license files and legal notices across directory hierarchies, and caches metadata directly within the repository for historical review. The tool evaluates detected dependencies against defined compliance rules that handle accepted licenses, ignored lists, and configuration settings specified in YAML or JSON formats. It supports custom dependency sour
Licensed is a dependency license auditor rather than a license directory, offering compliance validation and notice generation for projects rather than a catalog of open-source licenses.
govendor is a toolset for Go dependency management that enables the replication of external packages into a local directory to ensure reproducible builds without requiring active network access. It functions as a dependency vendor tool and version manager, fetching specific git revisions, tags, or branches of remote packages. The project includes a dependency auditor to identify missing, modified, or outdated packages compared to their remote sources. It also provides a license extraction utility that discovers and lists the legal licenses associated with project import paths and dependencies
This repository is a Go dependency management tool rather than a comprehensive open-source license directory, though it does include a utility to extract and list dependency licenses.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| mikepenz/aboutlibraries | 4.2K | Kotlin | apache-2.0 | |
| github/choosealicense.com | 4K | Ruby | mit | |
| 0 |
| — |
| — |
| — |
| aboutcode-org/scancode-toolkit | 2.6K | Python | NOASSERTION |
| google/osv-scanner | 10.6K | Go | Apache-2.0 |
| grokability/snipe-it | 13.4K | PHP | agpl-3.0 |
| dependencytrack/dependency-track | 3.6K | Java | apache-2.0 |
| licensee/licensed | 1K | Ruby | MIT |
| kardianos/govendor | 4.9K | Go | BSD-3-Clause |