Auditor
The project declares a licence and no bundled dependency is under a strong copyleft licence (GPL, AGPL, SSPL).
1.0.3: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.2: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative. (1.0.1 parses SPDX expressions: OR accepts a permissive alternative, AND requires every operand, parentheses nest, WITH keeps the licence; empty or UNKNOWN values are unknown-license.))
| const STRONG_COPYLEFT = /^(?:A?GPL-?[23](?:\.0)?(?:-only|-or-later|\+)?|SSPL(?:-1\.0)?|EUPL-1\.[12]|CC-BY-SA-\d(?:\.\d)?|OSL-3\.0|CPAL-1\.0)$/i; |
| // SPDX tree: OR -> every alternative copyleft; AND -> any operand copyleft; WITH keeps the licence |
| function forcesStrongCopyleft(node) { if (node.op === 'OR') return node.operands.every(forcesStrongCopyleft); if (node.op === 'AND') return node.operands.some(forcesStrongCopyleft); return STRONG_COPYLEFT.test(node.id); } |
| // (MIT OR GPL-3.0-or-later) -> accepted; GPL-3.0-only -> FAIL; (MIT AND GPL-2.0) -> FAIL; UNKNOWN or empty -> unknown-license |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.