liccheck
Check python packages from requirement.txt and report issues
Decision gist · record as of 2026-08-14
Yes. liccheck is a stable, actively maintained tool with low install friction and no security vulnerabilities. It solves a real compliance problem with minimal dependencies and clear output. Install it if your project needs to enforce license policies or audit dependencies for legal compliance.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires all packages from requirements.txt to be installed in the same Python environment; uses pkg_resources to inspect installed package metadata.
- Low friction install with only two lightweight runtime dependencies (semantic-version and toml).
- Actively maintained as of 2026-07-20 with stable status since its 2017 release.
License · maintenance · safety
Apache Software License (permissive) — Licensed under Apache Software License (permissive). No restrictions on commercial or private use.
last release 2023-09-22 (1057 days) · last repo commit 2026-07-20 · 184 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,013,403 downloads/mo, #3,363 on PyPI
Alternatives
Verify before relying
pip install liccheck
Create liccheck.ini with authorized/unauthorized licenses, then:
liccheck -s liccheck.ini -r requirements.txt- Whether regex matching performance scales well with large dependency trees
- How the tool handles packages with missing or malformed license metadata
What it is and what it does
liccheck is a command-line tool that audits Python project dependencies against a license compliance policy. It reads a requirements.txt or pyproject.toml file, inspects the licenses of all installed packages and their transitive dependencies, and reports violations based on three configurable strictness levels: Standard (at least one authorized license), Cautious (no unauthorized licenses even if one authorized exists), and Paranoid (all licenses must be authorized). The tool requires packages to be installed in the same Python environment where it runs, since it uses pkg_resources to access package metadata.
You define compliance rules in an INI or TOML configuration file, listing authorized licenses, unauthorized licenses, and exceptions for specific packages. The tool supports both exact string matching and regex patterns for license names. It outputs a summary of compliant packages, forbidden packages, unknown licenses, and dependency chains for violations, making it useful for legal review, CI/CD pipelines, and pre-commit hooks.
Use it for
- Enforce corporate license policies in CI/CD by blocking builds when dependencies violate approved licenses
- Audit open-source projects before distribution to ensure compliance with GPL, MIT, Apache, or other license requirements
- Detect GPL-licensed transitive dependencies that may trigger copyleft obligations in your project
- Generate license compliance reports for legal review before shipping a product
- Prevent accidental adoption of incompatible licenses by catching violations at pre-commit time
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
liccheck is a stable, actively maintained tool with low install friction and no security vulnerabilities. It solves a real compliance problem with minimal dependencies and clear output. Install it if your project needs to enforce license policies or audit dependencies for legal compliance.
Install
liccheck on PyPI
Before you install
Low friction install with only two lightweight runtime dependencies (semantic-version and toml). Actively maintained as of 2026-07-20 with stable status since its 2017 release.
Requires all packages from requirements.txt to be installed in the same Python environment; uses pkg_resources to inspect installed package metadata.
License in practice
Licensed under Apache Software License (permissive). No restrictions on commercial or private use.
Quickstart
pip install liccheck
Create liccheck.ini with authorized/unauthorized licenses, then:
liccheck -s liccheck.ini -r requirements.txt
Verify before relying
- Whether regex matching performance scales well with large dependency trees
- How the tool handles packages with missing or malformed license metadata
Package facts
| License | Apache Software License permissive |
| Python support | Supports the current Python release >=3.5 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagessemantic-versiontoml |
| Maintenance | Actively maintained 1,057 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 2,013,403 / month, #3,363 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Topic :: Software Development :: Build Tools |
Evidence: liccheck-0.9.2-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “python license compliance checker”
- liccheckScans Python project dependencies in requirements.txt or…
- licensecheckScans a project's dependencies to extract their licenses and checks…
- reusereuse is a command-line tool that validates and enforces REUSE…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also licensecheck · uv-secure · uv-sort · pipreqs · pip-check-reqs · license-expression · shellcheck-py · requirements-detector · pipreqs-fivetran · depgather