licensee is a free, open source compliance & risk management project written in Ruby and released under MIT. It has 912 GitHub stars, 347 forks and 5 open issues, and was last pushed 6 hours ago. On this registry it ranks #44 of 54 tracked projects in Compliance & Risk Management, with 5 head-to-head comparisons available.

What is licensee?

Licensee is a Ruby gem and command-line tool that automatically determines which open source license a project is distributed under, aimed at developers, compliance teams, and maintainers who need to know what they can and cannot do with a codebase.

What it is

Licensee lives in the Ruby ecosystem and ships both as a gem (gem install licensee) and as a command-line program (bin/licensee), with a public homepage at https://licensee.github.io/licensee/. It reads a project's LICENSE files, package manifests, and READMEs, compares their contents against known licenses, and reports the result as an SPDX identifier. It is MIT-licensed itself, follows semantic versioning, and can also be used programmatically by adding gem 'licensee' to a project's Gemfile.

The concrete problem it addresses is that license information in real-world repositories is manual, ambiguous, and frequently wrong: you have an open source project and do not know what you may do with it, you have many projects and do not know their respective licenses, or you have a license file but cannot tell which license it actually is or whether its text has been modified. Licensee automates that reading and comparison, replacing the human pass over every LICENSE file with a deterministic set of strategies the project calls "Matchers," which run in a defined order: a file containing only a copyright notice such as Copyright (c) 2015 Ben Balter is treated as all rights reserved and therefore unlicensed; an exact match (after stripping whitespace and copyright text) is returned directly; and failing that, the Sørensen–Dice coefficient measures string similarity so a file that is 95% similar to the MIT license can be reported as a possibly modified variant.

Key capabilities

  • Detects licenses from LICENSE files, package manifests, and READMEs, returning SPDX identifiers for the project's distribution terms.
  • Applies a documented matching order: reserved-rights detection for copyright-only files, exact string comparison against known licenses, then Sørensen–Dice similarity scoring.
  • Reports how closely a given file matches a known license, distinguishing a standard license from one that has been edited.
  • Scans projects through the filesystem by default and falls back transparently when native Git bindings are absent.
  • Optionally scans bare Git repositories and repositories without a working tree (such as those on a Git server) by installing the rugged gem, which provides Ruby bindings for libgit2.
  • Ships a Dockerfile so the tool can be run inside a container rather than installed on the host.
  • Exposes behaviour for customisation, documented in customizing.md, alongside usage.md and a what-we-look-at.md page describing what it inspects or ignores and why.

Who uses it and how

  • Compliance and risk-management teams auditing a collection of open source dependencies to establish which licenses apply across a portfolio.
  • Maintainers checking their own repository to confirm the LICENSE file actually corresponds to the license they believe they published.
  • Teams running the tool in CI, as evidenced by the project's CI GitHub Actions workflow badge.
  • Operators of Git servers who need to inspect repositories with no working tree, using rugged for bare-repository scanning.
  • Developers embedding license detection in Ruby applications through Licensee.project rather than shelling out to the CLI.

Getting started

Install the released gem from RubyGems with gem install licensee, or run from source with gem install bundler, bundle install, then bundle exec bin/licensee. To use Docker instead, clone the repository, run docker build . --tag licensee, and start it with docker run licensee [COMMAND].

How it compares

No comparable or superseded products are named in the available facts, so licensee stands alone in this registry.

When to use it — and when not

Optional Git-repository scanning means installing rugged, a native extension that requires cmake and openssl to build (for example apt install cmake libssl-dev), and on Windows the CLI invocation must include the Ruby interpreter explicitly. Because fuzzy matching rests on statistical string similarity, a heavily rewritten license file is reported only as a percentage of similarity rather than a definitive identification, and the project's own docs acknowledge there are things it looks at "or doesn't, and why." Anyone needing authoritative legal conclusions rather than a machine-readable SPDX guess should treat the output as an input to human review.

project readme (upstream, from github) — read inline

Licensee

A Ruby Gem to detect under what license a project is distributed.

Gem Version PRs Welcome OpenSSF Scorecard OpenSSF Best Practices

The problem

  • You've got an open source project. How do you know what you can and can't do with the software?
  • You've got a bunch of open source projects, how do you know what their licenses are?
  • You've got a project with a license file, but which license is it? Has it been modified?

The solution

Licensee automates the process of reading LICENSE files and compares their contents to known licenses using several strategies (which we call "Matchers"). It attempts to determine a project's license in the following order:

  • If the license file has an explicit copyright notice, and nothing more (e.g., Copyright (c) 2015 Ben Balter), we'll assume the author intends to retain all rights, and thus the project isn't licensed.
  • If the license is an exact match to a known license. If we strip away whitespace and copyright notice, we might get lucky, and direct string comparison in Ruby is cheap.
  • If we still can't match the license, we use a fancy math thing called the Sørensen–Dice coefficient, which is really good at calculating the similarity between two strings. By calculating the percent changed from the known license to the license file, you can tell, e.g., that a given license is 95% similar to the MIT license, that 5% likely representing legally insignificant changes to the license text.

Special thanks to @vmg for his Git and algorithmic prowess.

Installation

To use the latest released gem from RubyGems:

gem install licensee

To use licensee programmatically in your own Ruby project, add gem 'licensee' to your project's Gemfile.

To run licensee directly from source:

gem install bundler
bundle install
bundle exec bin/licensee

On Windows, the last line needs to include the Ruby interpreter:

bundle exec ruby bin\licensee

Git repository scanning (optional)

By default, licensee scans projects using the filesystem. If you want to scan bare Git repositories or repositories without a working tree (e.g., on a Git server), install the rugged gem, which provides Ruby bindings for libgit2:

gem install rugged

Or add it to your Gemfile alongside licensee:

gem 'rugged'

When rugged is available, Licensee.project will use it automatically. If rugged is not installed, licensee falls back to filesystem-based scanning transparently.

Note that rugged is a native extension and requires cmake and openssl to build. On most systems these are available via a package manager (e.g., apt install cmake libssl-dev or brew install cmake openssl).

Docker

Licensee also comes with a Dockerfile if you prefer to run Licensee within a Docker container:

  1. git clone https://github.com/licensee/licensee && cd licensee
  2. docker build . --tag licensee
  3. docker run licensee [COMMAND] (see command line usage)

Documentation

See the docs folder for more information. You may be interested in:

Semantic Versioning

This project conforms to semver. As a result of this policy, you can (and should) specify a dependency on this gem using the Pessimistic Version Constraint with two digits of precision. For example:

spec.add_dependency 'licensee', '~> 1.0'

This means your project is compatible with licensee 1.0 up until 2.0. You can also set a higher minimum version:

spec.add_dependency 'licensee', '~> 1.1'

Frequently asked questions

Is licensee free to use?

licensee is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does licensee do?

Ruby gem & CLI to detect a project's open source license (SPDX) from LICENSE files, package manifests, and READMEs

What is licensee written in?

licensee is primarily written in Ruby. Its source is publicly available at https://github.com/licensee/licensee, and it has 912 GitHub stars.