License Lantern
Build reviewable dependency-license inventories, SPDX drafts, and attribution drafts locally without guessing legal compatibility.
The problem it solves
License Lantern License Lantern builds a reviewable dependency-license inventory, SPDX 2.3 draft, and third-party attribution draft from local project files.
Who License Lantern is for
- Developers and maintainers who need reviewable evidence before changing or releasing software.
- Users working with licenses, SPDX, SBOM who want the documented v1.0.0 behavior.
- People who prefer an open-source release with visible limitations, source, and license terms.
Intended result
Build reviewable dependency-license inventories, SPDX drafts, and attribution drafts locally without guessing legal compatibility.
This summary is reconciled from the current catalog and repository documentation.
Features in v1.0.0
Capabilities below come from the current project README and release documentation.
License Lantern builds a reviewable dependency-license inventory, SPDX 2.3 draft, and third-party attribution draft from local project files.
Version 1 reads npm package-lock.json, Python pyproject.toml, requirements files, and CycloneDX JSON. It preserves unresolved licenses as NOASSERTION instead of guessing and can fail CI when human review remains.
Verified examples
Screenshots are shown only when the current README references a local source image. Otherwise, repository example files are linked directly.
Verified release evidence
This project does not currently publish a screenshot or dedicated example folder. The current README, tests, changelog, tagged release, and source repository remain the verified examples of its behavior.
Platforms and implementation
The public release claims only the cataloged platforms and technologies.
Supported platforms
- Windows
- macOS
- Linux
Built with
- Python
- SPDX
- CycloneDX
Quick start
The shortest documented path into the current release.
python -m pip install .
license-lantern package-lock.json --inventory licenses.json --spdx sbom.spdx.json --notice THIRD-PARTY.txt
license-lantern requirements.txt --fail-unresolvedCurrent limitations
These boundaries are part of the product and prevent the page from implying unverified capability.
- Output is an evidence draft, not legal advice, a compatibility ruling, or proof that an upstream declaration is correct.
- Lockfiles often omit license text and copyright notices; those must be verified and added before distribution.
- Python requirement specifications normally lack license metadata and remain unresolved without a supplied SBOM.
- No package registry, network service, vulnerability database, telemetry, or source-code scanner is used.
- Input files are read-only and outputs cannot replace them.
Python 3.11+ on Windows, macOS, and Linux. Current release: v1.0.0. Pull requests are reviewed. MIT licensed.
Privacy and licensing
Review the actual data boundary before using a tool with sensitive inputs.
Privacy and safety
No privacy behavior beyond the current repository documentation is claimed. Review the source, security policy, and input/output behavior before using sensitive material.
License and release
License Lantern is published under MIT. The current cataloged release is v1.0.0, published 2026-08-10.
Related projects
Related projects are selected deterministically from shared catalog tags, category, and implementation technologies—not popularity or paid placement.
License Lantern v1.0.0
Use the tagged release for downloads and release notes. Use the repository for source, issues, contribution guidance, security reporting, and complete documentation.
Page source: current Forge catalog plus README and CHANGELOG from the canonical local repository. Fingerprint: d3c53519acb59f30.