Feluda – A CLI tool to detect restrictive licenses in dependencies
crates.io
crates.io
I built Feluda, a Rust-based CLI tool that scans your project's dependencies and flags restrictive licenses before they become a problem.
It currently supports Rust, Node.js, and Go projects. It checks for GPL, AGPL, SSPL, and other restrictive licenses that may limit how you use your project commercially.
Try it out:
``` cargo install feluda feluda ```
I’d love feedback! Are there specific license edge cases you'd like covered? Features you'd want in a CI/CD setup? Happy to discuss and iterate!
Freedom looks like tyranny, to a tyrant.
I think you're looking for MPL 2.0, which is copyleft while also permitting use by the entire free software ecosystem.
I honestly thought that this was a license scanner for actually restrictive — i.e. non-free-software — licenses until I visited the repo. It would be good to know if I accidentally use some piece of software with some source-available license.
Certainly, if I maintain a repo which calls a function in a GPL library, it would be misleading for me to say that my repo is MIT-licensed. I could potentially say that my specific code bits are MIT-licensed but that (per the FSF's interpretation) if you import my library, your resulting artifacts are GPL.
That is quite hard to communicate, and it also rests on a particular interpretation of the license that is the most common one but isn't universally accepted. It also becomes tricky with distributed copyright ownership without a CLA, the way most open source projects are run. I think that this rises to the level of "impossible to use".
But I guess one specific point here is that if you download my MIT-licensed-but-links-to-GPL repo, and rip out all of the bits that link to GPL libraries, you can use my code under MIT.
Compare this to MPL 2 which has none of these issues, and very little legal uncertainty in general. There is still some uncertainty regarding what constitutes a copyrightable work, though.
[1] https://tech.popdata.org/the-gpl-license-and-linking-still-u...
EDIT: there was a package.json in the same folder, that's what caused the "bug"