ThemisDB implements an automated license compliance process to ensure that all dependencies are compatible with the project license (MIT with Government Clause) and do not pose legal risks.
The License Compliance workflow (.github/workflows/license-compliance.yml) runs automatically on:
- Pull Requests: Checks all dependency changes
- Push to permanent branches: Validates license compliance on
develop,community,enterprise,hyperscaler,military, andminimal - Monthly Audit: Automatic check on the first day of each month
- Manual Trigger: Can be started anytime via GitHub Actions UI
The workflow monitors changes to:
vcpkg.json- C++ dependencies (vcpkg)package.json/package-lock.json- Node.js/JavaScript dependenciespom.xml- Java Maven dependenciesbuild.gradle- Java Gradle dependenciesCargo.toml- Rust dependenciesgo.mod- Go dependenciesrequirements.txt/Pipfile- Python dependenciescomposer.json- PHP dependencies.license-policy.json- License policy changes
The license policy is defined in .license-policy.json and categorizes licenses into three groups:
These licenses are permitted without restrictions:
- MIT - Maximum freedom, minimal restrictions
- Apache-2.0 - Permissive with patent protection
- BSD-2-Clause / BSD-3-Clause - Permissive with attribution
- ISC - Functionally identical to MIT
- Unlicense / 0BSD / CC0-1.0 - Public domain-like
- BSL-1.0 - Boost Software License
- MPL-2.0 - Mozilla Public License (file-based copyleft)
These licenses are blocked as they require derivative works to be published under the same license:
- GPL-2.0 / GPL-3.0 - GNU General Public License
- AGPL-3.0 - GNU Affero General Public License
Action: Pull request will be blocked, dependency must be replaced.
These licenses are accepted with warning when using dynamic linking:
- LGPL-2.1 / LGPL-3.0 - GNU Lesser General Public License
- EPL-1.0 / EPL-2.0 - Eclipse Public License
- CDDL-1.0 / CDDL-1.1 - Common Development and Distribution License
Action: Warning displayed, but pull request is not blocked.
Example: FFmpeg uses LGPL-2.1, which is acceptable as ThemisDB links FFmpeg as a dynamic library.
- Proprietary / Commercial / UNLICENSED
Action: Pull request will be blocked.
Licenses not defined in the policy are treated as non-whitelisted and require manual review.
Action: Pull request is blocked until the dependency is approved or replaced.
For each pull request, automatically:
- License Scan: All direct and transitive packages declared through
vcpkg.jsonare checked - Policy Validation: SPDX license expressions are evaluated against
.license-policy.json - License SBOM Generated:
vcpkg-license-sbom.jsonandlicense-summary.mdare uploaded as artifacts - Status Check: PR status is set to
failedfor blocked or non-whitelisted licenses
## 📋 License Compliance Check
### ✅ Check Passed
All dependencies comply with the license policy.
**Summary:**
- 🔴 Blocked: 0
- 🟡 Warnings: 1
[Download the license SBOM and summary artifacts](...)When a license violation is detected:
- ❌ The PR check fails
- 📝
license-summary.mdlists the affected packages, SPDX expressions, and policy decisions - 🚫 The PR must not merge until the status check is green again
- 📋
vcpkg-license-sbom.jsonrecords the full package inventory for audits and releases
When the license check fails:
-
Review the violation:
- Open the workflow run and check details
- Identify the problematic dependency
-
Actions:
Option A: Replace dependency (preferred)
- Search for an alternative with compatible license
- Update dependencies
- Push changes
Option B: Request exception
- Create an issue with label
license-exception - Justify why the dependency is necessary
- Wait for review by compliance team
-
Re-Check:
- Workflow runs automatically on every push
- Verify that the violation has been resolved
For exception requests:
- Review: Check justification and legal risks
- Decision: Approve or deny
- Documentation: On approval:
- Add exception to
.license-policy.jsonunderexceptions.list - Include package, exact license expression, override action, justification, approval date, and approver
- Document justification
- Update compliance documentation
- Add exception to
On the first day of each month (3:00 AM UTC), a full license audit is automatically performed:
- Scans all dependencies
- Creates a detailed report
- Stores artifacts for 90 days
- Notifies on violations
Run a manual audit anytime:
# Via GitHub Actions UI
# 1. Go to Actions → Compliance — License Policy Gate
# 2. Click "Run workflow"
# 3. Select branch
# 4. Click "Run workflow"All audit reports are stored as artifacts:
license-summary.md- review and audit summaryvcpkg-license-sbom.json- license SBOM for direct and transitive vcpkg dependencies
Retention: 90 days
- Check license: Verify the dependency's license
- Consult policy: Ensure the license is allowed
- Documentation: Add license information to your PR
Prefer dependencies with these licenses:
- MIT
- Apache-2.0
- BSD-3-Clause
- ISC
Avoid dependencies with:
- GPL (all versions) - except for dynamic linking
- AGPL - always avoid
- Proprietary licenses
- Unclear or missing license information
The license compliance workflow works together with the SBOM workflow:
- SBOM contains license information for all dependencies
- Generated with every release
- See
.github/workflows/sbom-ci.yml
The security scan workflow (.github/workflows/security-scan.yml) includes a basic license check:
- Validates presence of license files
- References the detailed license compliance workflow
- Part of overall security strategy
During code reviews:
- Check the
Compliance — License Policy Gatestatus - Download
license-summary.mdorvcpkg-license-sbom.jsonwhen deeper review is needed - Manually review warnings and exceptions
- Document license decisions in the PR
This process meets the following standards and regulations:
- BSI C5 (SSO-02): Software Supply Chain Security
- NIS2: Network and Information Security
- GDPR: General Data Protection Regulation
- Executive Order 14028: Improving the Nation's Cybersecurity (SBOM)
- ISO 27001: Information Security Management System
A: The license check found a dependency with an incompatible license. Check the workflow report for details and either replace the dependency or request an exception.
A: Weak copyleft (e.g., LGPL) requires that changes to the library itself be published under the same license. However, with dynamic linking this is acceptable as your code is not considered a derivative work.
A: GPL libraries are only acceptable with dynamic linking and will generate a warning. Static linking or embedding GPL code is not allowed as it would make ThemisDB a derivative work under GPL.
A: Create an issue with:
- Title: "License Exception Request: [Dependency Name]"
- Label:
license-exception - Description: Justification and legal analysis
- Wait for review by compliance team
A: Edit .license-policy.json and create a PR. Policy changes require detailed justification and review by maintainers.
For license compliance questions:
- Issues: Create an issue with label
license-compliance - Discussions: Start a discussion in the "Compliance" section
- Email: Contact the compliance team (see SUPPORT.md)
- License Policy (.license-policy.json)
- License Compliance Workflow
- Security Scanning Workflow
- SBOM Workflow
- CONTRIBUTING.md
- SECURITY.md
Version: 1.0.0
Last Updated: 2026-04-06
Status: ✅ Active