Scan npm dependencies for license compliance issues. Catch GPL contamination.
MCP server that scans npm project dependencies for license compliance issues. Catch GPL contamination before code ships. Scan a project's npm dependencies against a license policy and get a detailed compliance report. (required) — Absolute path to the project root (optional, default: ) — Policy preset or custom SPDX expression — Only MIT, ISC, BSD, Apache-2.0, etc. — Adds LGPL, MPL-2.0, EPL-2.0…
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat zu diesem Eintrag keinen Scan verzeichnet und hat daher keine Beobachtung seiner Tool-Oberfläche. Das ist das Fehlen eines Belegs, nicht der Beleg, dass er keine Tools offenlegt.
MCP server that scans npm project dependencies for license compliance issues. Catch GPL contamination before code ships. Scan a project's npm dependencies against a license policy and get a detailed compliance report. (required) — Absolute path to the project root (optional, default: ) — Policy preset or custom SPDX expression — Only MIT, ISC, BSD, Apache-2.0, etc. — Adds LGPL, MPL-2.0, EPL-2.0 Custom: — Any valid SPDX expression Get a plain-language explanation of any SPDX license —…