dongsheng123132/dsh-license-obligation-proof ↗★ 0
dsh-license-obligation-proof
Offline content-addressed proof for supplied license-obligation delivery closure
AI 분석
核心用途是离线验证发布决策所需的合规件(如 NOTICE、许可证文本、源码包)是否已完整交付。适合需要在软件发布后进行开源许可证合规性最终审计的法务与开发团队。
설치
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:dongsheng123132/dsh-license-obligation-proofdsh-license-obligation-proof
Offline, deterministic evidence that every required compliance artifact for a supplied release decision was delivered: NOTICE, license text, source offer, source bundle, or modification notice. Inputs and reports contain hashes, obligation codes and bounded metadata only—never license bodies, copyright text, package source or secrets.
This is deliberately not another license scanner. dsh-license-guard already scans node_modules, normalizes SPDX identifiers and applies allow/deny policy. This plugin starts after scanning and expert review: it verifies that the declared component set, decisions, obligations, delivered artifact digests, distinct receipts and fresh zero-unresolved closure agree. It does not scan packages, normalize SPDX, interpret a license, or provide legal advice.
npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.json
DSH tools: dsh_license_obligation_inspect and dsh_license_obligation_verify. MCP exposes equivalent proof-only inline tools. Reports explicitly retain provesComponentSetExhaustive: false and provesLegalCompliance: false.
References: SPDX License Expressions and OpenChain ISO/IEC 5230.
MIT licensed.