Dependency License Auditor avatar

Dependency License Auditor

Pricing

from $9.80 / 1,000 target auditeds

Go to Apify Store
Dependency License Auditor

Dependency License Auditor

Audit dependency manifests for license types, unknown licenses, and policy risk.

Pricing

from $9.80 / 1,000 target auditeds

Rating

0.0

(0)

Developer

junipr

junipr

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

5 days ago

Last modified

Categories

Share

Store Positioning

Store title: Dependency License Auditor

Short description: Audit dependency manifests for license types, unknown licenses, and policy risk.

SEO title: Dependency License Auditor — API, schema, and developer QA

SEO description: Audit dependency manifests for license types, unknown licenses, and policy risk. Use it to catch contract drift, schema mistakes, unsafe endpoint assumptions, and developer-tool quality issues before release.

Categories: DEVELOPER_TOOLS

Keywords: dependency, license, auditor, api/developer qa

Fixed-Inclusive PPE Pricing

This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.

  • Tier: A1 — API/developer QA
  • Primary event: operation-tested at $0.00650 base
  • Default max charge: $10.00
  • Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount

Event set:

  • actor-start: base $0.00500, GOLD $0.00400. Dependency License Auditor: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • operation-tested: base $0.00650, GOLD $0.00520. Dependency License Auditor: charged when operation tested is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • contract-rule-checked: base $0.00390, GOLD $0.00312. Dependency License Auditor: charged when contract rule checked is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • report-generated: base $0.05000, GOLD $0.04000. Dependency License Auditor: charged when report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.

Public Task Concepts

  • Audit Dependency License controls on a capped public sample
  • Find high-priority Dependency License issues before release
  • Validate Dependency License evidence from supplied pages
  • Prioritize Dependency License fixes with severity and proof
  • Export Dependency License QA rows for client review

Audit dependency manifests for license types, unknown licenses, and policy risk.

What This Actor Does

Dependency License Auditor turns explicit watchlists or supplied records into structured Apify dataset rows and a concise report. The capped built-in records make the default run deterministic and avoid network, browser, proxy, LLM, or third-party API costs.

The actor checks each supplied record for source identity, matched watch terms, actor-specific metadata, issue signals, severity, recommendations, and pricing metadata. It writes one dataset row per processed record and, when enabled, key-value-store JSON and Markdown summaries for operational workflows.

What This Actor Does Not Do

  • It does not provide legal, medical, financial, investment, safety, or compliance advice.
  • It does not guarantee completeness of any public source or third-party dataset.
  • It does not collect sensitive personal data by default.
  • It does not rely on unsupported private APIs.

Best Use Cases

  • manifest license checks
  • open-source policy reviews
  • unknown-license triage

Input Fields Explained

FieldTypeDefaultNotes
recordsarraytwo built-in recordsRecords or snapshots to check. Each item can include title, description, body, entity, category, keywords, and metadata.
urlsarray[]Reserved for optional source URLs. Defaults do not fetch URLs.
fetchUrlsbooleanfalseEnables HTTP fetching for records with sourceUrl and no body. Keep false when records already contain the text to analyze.
watchTermsarrayactor defaultsTerms used to mark relevant records and alerts.
includeReportbooleantrueWrites JSON and Markdown report artifacts to the key-value store.
maxItemsinteger2Caps processed records. Maximum is 50.
maxTextBytesinteger500000Caps analyzed text per record.
debugbooleanfalseEnables debug logging.

Example Input

{
"records": [
{
"sourceId": "dep-react",
"sourceUrl": "package.json",
"title": "react dependency",
"description": "react dependency in production manifest uses MIT license.",
"entityName": "react",
"category": "dependency",
"keywords": [
"MIT"
],
"metadata": {
"packageName": "react",
"version": "19.0.0",
"license": "MIT",
"policy": "allowed"
}
},
{
"sourceId": "dep-risk",
"sourceUrl": "package.json",
"title": "legacy-report dependency",
"description": "legacy-report dependency has GPL-3.0 license and unknown policy approval.",
"entityName": "legacy-report",
"category": "dependency",
"keywords": [
"GPL"
],
"metadata": {
"packageName": "legacy-report",
"version": "1.2.3",
"license": "GPL-3.0",
"policy": "unknown"
}
}
],
"includeReport": true,
"maxItems": 2
}

Output Fields Explained

FieldMeaning
auditIdStable hash for the checked record.
sourceId, sourceUrlSource identifiers for traceability.
status, severity, scoreNormalized outcome and 0-100 quality/risk score.
matchedKeywordsWatch terms found in the record text or metadata.
issues, issueCodesActor-specific findings with severity and messages.
recommendationsNext actions for the operator or content/data owner.
metadataOriginal metadata plus derived helper fields when applicable.
pricingTemplate, pricingEventNamePricing source and primary PPE event used by the actor.

Example Output

{
"auditId": "dependen_a82e804f031934c4",
"actorSlug": "dependency-license-auditor",
"actorName": "Dependency License Auditor",
"sourceType": "fixture",
"sourceId": "dep-react",
"sourceUrl": "package.json",
"title": "react dependency",
"status": "pass",
"severity": "none",
"score": 100,
"matchedKeywords": [],
"primaryEntity": "react",
"category": "dependency",
"publishedAt": null,
"summary": "react dependency in production manifest uses MIT license.",
"issueCount": 0,
"issues": [],
"issueCodes": [],
"recommendations": [
"Dependency License Auditor did not find immediate risk signals for this record. Re-run after source data changes."
],
"metadata": {
"packageName": "react",
"version": "19.0.0",
"license": "MIT",
"policy": "allowed",
"sourceSpecific": {
"licenseRows": [
{
"packageName": "react",
"license": "MIT",
"policyStatus": "allowed"
}
]
},
"normalizedTextPreview": "dep-react package.json react dependency react dependency in production manifest uses MIT license. react dependency MIT {\"packageName\":\"react\",\"version\":\"19.0.0\",\"license\":\"MIT\",\"policy\":\"allowed\"}"
},
"textBytes": 197,
"checkedAt": "2026-07-02T00:00:00.000Z",
"pricingTemplate": "A1 — API/developer QA",
"pricingEventName": "operation-tested"
}

Cost-Control Tips

  • Keep maxItems small for default and scheduled checks.
  • Use supplied records or snapshots for deterministic QA runs.
  • Leave fetchUrls off unless live source fetching is explicitly needed.
  • Review warning rows before increasing caps.
  • Schedule small frequent runs instead of broad one-off sweeps.

Scheduling Examples

  • Daily watchlist check with two to five high-value records.
  • Weekly QA run before publishing a site, data, or actor update.
  • Post-migration or post-release validation using a saved record set.

Public Task Examples

  • tiny-default-check - Run a two-record dependency license auditor check with report artifacts enabled.
  • watchlist-digest - Process a small supplied watchlist and summarize matched terms.
  • risk-triage-report - Return only records with warning or fail status for operator follow-up.
  • scheduled-monitor - Run Dependency License Auditor on a daily or weekly schedule with tight caps.
  • schema-and-billing-preflight - Validate output shape and PPE event names before live setup.

FAQ

Can I schedule recurring checks?

Yes. Save a capped input and use Apify schedules to run it daily or weekly.

Can I use this with live URLs?

Yes. Set fetchUrls to true and provide urls or records with sourceUrl. Failed fetches produce explicit diagnostic rows.

Why does it charge before pushing output?

Pay-per-event actors must charge before paid output is written. If the charge limit is reached, processing stops before another paid row is emitted.

What happens on charge limits?

The actor stops gracefully and writes a summary instead of pushing unpaid result rows.

No. The actor produces operational signals and structured data for review. Human owners remain responsible for decisions.

Troubleshooting

  • If the dataset is empty, check that maxItems is greater than zero and that records are supplied or defaults are enabled.
  • If a record is flagged unexpectedly, inspect issueCodes, matchedKeywords, and the normalized metadata preview.
  • If live fetching fails, rerun with supplied record bodies or snapshots and keep fetchUrls false.

Limitations

This actor only sees the records, snapshots, or URLs supplied to it. It does not guarantee complete public-source coverage, private-source access, or all edge-case parsing. Browser and proxy flows are not used by default.

Source And Safety Notes

The built-in records are labeled through sourceType: "fixture" and are intended to show the output contract. When connecting public sources, use official or permissioned endpoints where possible and avoid sensitive personal data. Do not use the output as a substitute for professional advice.

Changelog

  • 2026-07-02: Initial actor package with schemas, capped defaults, pricing controls, and runtime validation.