Skip to content

[Enhancement] Add a dependency-license check to the audit workflow #1031

Description

@RUKAYAT-CODER

Overview

.github/workflows/audit.yml runs npm audit and depcheck but performs no license check. src/audit/analyzers/NetworkAnalyzer.ts contains a checkLicenses code path (with its own console.error at line 488), suggesting the concern was recognised but never wired into CI. A mobile app shipping to the App Store and Play Store with ~120 direct dependencies needs to know if a copyleft-licensed package enters the tree.

Specifications

Features:

  • A license scan over the production dependency tree
  • An allowlist of acceptable licenses, failing on anything outside it
  • A generated attribution file for the app's legal notices screen

Tasks:

  • Add a license-checking step to audit.yml scoped to --production
  • Define the allowlist and document the review process for exceptions
  • Generate an attribution file and surface it in the app settings
  • Reconcile with the checkLicenses path in NetworkAnalyzer.ts — implement it properly or remove it

Impacted Files:

  • .github/workflows/audit.yml
  • src/audit/analyzers/NetworkAnalyzer.ts
  • src/components/settings/

Acceptance Criteria

  • A disallowed license fails CI
  • The allowlist and exception process are documented
  • The app displays third-party attributions

Activity

  1. Nathydre commented on Aug 21, 2026

    @Nathydre

    good day maintain,i would like to handle this issue ....thank you

  2. Peculiarr7 commented on Aug 21, 2026

    @Peculiarr7

    Hi! I came across this issue and would love to work on it. I have experience with similar tasks and I'm confident I can investigate, implement a clean solution, and thoroughly test it before submitting a PR. If the issue is still open, I would appreciate it if you could assign it to me. I’ll prioritize this immediately and ensure a reliable solution is delivered as soon as possible. Thank you!

  3. bellofuad34-ctrl commented on Aug 26, 2026

    @bellofuad34-ctrl

    @bellofuad34-ctrl has applied to work on this issue as part of the Stellar Wave Program's 8th wave.

    Hi Maintainer, please I can solve the issue and submit PR today.

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @bellofuad34-ctrl to this issue.

  4. bigceejay19 commented on Aug 26, 2026

    @bigceejay19

    @bigceejay19 has applied to work on this issue as part of the Stellar Wave Program's 8th wave.

    Hi maintainer, I’m available to work on this issue and can provide a clean solution with proper testing.

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @bigceejay19 to this issue.

  5. usmanimamu17-create commented on Aug 26, 2026

    @usmanimamu17-create
    Contributor

    @usmanimamu17-create has applied to work on this issue as part of the Stellar Wave Program's 8th wave.

    I will add a dependency-license check to the audit workflow that verifies all third-party packages use approved licenses. The core deliverable integrates a license scanner that runs on every pull request and flags any newly introduced dependencies with non-compliant licenses. I will maintain an allow-list for known acceptable licenses and document the process for requesting exceptions.

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @usmanimamu17-create to this issue.

  6. drips-wave commented on Aug 26, 2026

    @drips-wave

    Congratulations, @usmanimamu17-create! 🎉 Your application was accepted by the repo's maintainers, and the issue is due on August 31, 2026.

    🧑‍💻 @usmanimamu17-create: Please resolve the issue such that the repo's maintainers have enough time to review your contribution before the due date. You'll earn Points for completing the issue on-time, which will make you eligible for a share of the Stellar Wave Program's reward pool.

    Warning

    When opening a PR, please link it to this issue to ensure it gets tracked accurately. Points are awarded when this issue is marked as completed by the maintainer.

    🤠 Repo maintainers: Please keep an eye on the contributor's progress and review their work before the due date. You can manage this issue, including adjusting its complexity and points, here.

    🌊 Happy Wave 🌊

  7. grantfox-oss commented on Aug 27, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox as part of the Third Campaign campaign!

    @usmanimamu17-create's PR #1063 was approved and merged by @RUKAYAT-CODER.

    🏆 @usmanimamu17-create: You earned 35 FoxPoints for this contribution! Your current tier: Explorer (802 total points). Track your full progress on GrantFox.

    👏 Great work, @usmanimamu17-create! Keep contributing to rinafcode.

  8. drips-wave commented on Aug 27, 2026

    @drips-wave

    This issue has been completed by @usmanimamu17-create as part of the Stellar Wave Program's 8th Wave 🥳

    😎 @usmanimamu17-create: You earned 200 Points for completing this issue! After the current Wave ends, you'll be eligible for a percentage of the Wave's reward pool based on the percentage of total points you've earned. Learn more here. You can also Leave a review to share your experience working on this issue.

    🧑‍💻 Repo maintainers: How'd the contributor do? Leave a review to share your experience working with them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions