Interactive and scriptable CLI that generates a correct LICENSE file from the full SPDX catalog, syncs the chosen license into your package.json/composer.json, stamps source-file headers, and verifies everything stays in sync in CI.
The licensing notary: distribute any SPDX license, notarize a project's LICENSE against the canonical text, and gate your own packages with offline signed registration. Deployment identity + license attestation.
npm / node module to transfer dependency information to TrustSource server.
Audit the LICENSE of every npm dependency before you ship. Resolves each dependency's real license from the live npm registry and flags GPL/AGPL/LGPL copyleft, BUSL/SSPL/Elastic source-available, non-commercial and unlicensed packages incompatible with yo
Deterministic validation core for Assisted-By Guard.
Creates CycloneDX Software Bill of Materials (SBOM) from source or container image