rob,
@rob@akrabat.com avatar

For some projects we've needed to control the licenses used for our dependencies. Fortunately Composer has a command the help with this.

https://akrabat.com/check-licenses-of-composer-dependencies/

tvbeek,
@tvbeek@phpc.social avatar

@rob on my previous job we used the package license-checker from madewithlove https://github.com/madewithlove/license-checker-php
And yes it can be useful or needed to check the licenses of your dependencies.

wyri,
@wyri@haxim.us avatar

@rob Are you planning a package or composer plugin to block adding dependecies with a problematic licenses?

heiglandreas,
@heiglandreas@phpc.social avatar

@wyri @rob I know there was versioneye a few years back that did licence managements. As most projects use more than one package-mamager IMO a solution that checks all of them might make more sense. But yeah: That will only work AFTER the package has been included already. Whether via composer or yarn or pip or...

heiglandreas,
@heiglandreas@phpc.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tacticalgear
  • DreamBathrooms
  • cisconetworking
  • magazineikmin
  • InstantRegret
  • Durango
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • mdbf
  • khanakhh
  • kavyap
  • everett
  • JUstTest
  • modclub
  • Leos
  • cubers
  • ngwrru68w68
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • anitta
  • provamag3
  • normalnudes
  • tester
  • megavids
  • lostlight
  • All magazines