feat(repo-health): add dependency-license-audit skill with eval suite - #814
Merged
Merged
Conversation
Member
Author
|
@sebbASF you might be interested in taking a look at this |
Adds the dependency-license-audit skill: a read-only license audit of a project's direct and transitive dependency tree. Detects the dependency manager(s), resolves each dependency's declared license from ecosystem metadata, classifies each against a configured policy (ASF three-category A/B/X model or a custom allowlist), and surfaces incompatible, forbidden, and unknown-license dependencies for maintainer review. Never modifies manifests or lock files. Ships mode: Triage + experimental with a four-step eval suite (scope selection, license normalization, license classification, license report) covering compound AND/OR expressions, or-later, classpath exceptions, category-B binary-only handling, unknown licenses, and prompt-injection resistance. Registers the skill across docs/modes.md, the capability map, the repo-health family README, the spec-loop spec, and the adopter-config scaffold. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
potiuk
force-pushed
the
dependency-license-audit
branch
from
July 11, 2026 15:07
df1fec5 to
1f03343
Compare
Member
|
Reviewed and merging — the skill and eval suite are solid. I pushed one small doc-only reconciliation on top: the PR shipped the skill but |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
magpie-dependency-license-auditskill (Triage mode): a read-only audit of a project's direct and transitive dependency tree. It detects the dependency manager(s), resolves each dependency's declared license from ecosystem metadata, classifies each against a configured policy (the ASF three-category A/B/X model or a custom allowlist), and surfaces incompatible, forbidden, and unknown-license dependencies for maintainer review. It never modifies manifests or lock files.--policy asf|allowlist; scope via--repo owner/nameor--path.tools/spec-loop/specs/repo-health-family.mdspec to describe the new skill.Type of change
.claude/skills/<name>/) — eval fixtures updated belowtools/<system>/*.md)tools/*/withpyproject.toml)docs/,README.md,CONTRIBUTING.md)projects/_template/)prek, workflows, validators)Test plan
prek run --all-filespassesuv run pytest/ruff check/mypypasses(
PYTHONPATH=tools/skill-evals/src python3 -m skill_evals.runner tools/skill-evals/evals/<skill>/)(a regression test for the bug fixed / the behaviour added — see CONTRIBUTING.md)