Dependency License Auditor
Pricing
from $9.80 / 1,000 target auditeds
Dependency License Auditor
Audit dependency manifests for license types, unknown licenses, and policy risk.
Pricing
from $9.80 / 1,000 target auditeds
Rating
0.0
(0)
Developer
junipr
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 days ago
Last modified
Categories
Share
Store Positioning
Store title: Dependency License Auditor
Short description: Audit dependency manifests for license types, unknown licenses, and policy risk.
SEO title: Dependency License Auditor — API, schema, and developer QA
SEO description: Audit dependency manifests for license types, unknown licenses, and policy risk. Use it to catch contract drift, schema mistakes, unsafe endpoint assumptions, and developer-tool quality issues before release.
Categories: DEVELOPER_TOOLS
Keywords: dependency, license, auditor, api/developer qa
Fixed-Inclusive PPE Pricing
This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.
- Tier: A1 — API/developer QA
- Primary event:
operation-testedat $0.00650 base - Default max charge: $10.00
- Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount
Event set:
actor-start: base $0.00500, GOLD $0.00400. Dependency License Auditor: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.operation-tested: base $0.00650, GOLD $0.00520. Dependency License Auditor: charged when operation tested is completed. The price includes Apify platform usage; no separate usage pass-through is intended.contract-rule-checked: base $0.00390, GOLD $0.00312. Dependency License Auditor: charged when contract rule checked is completed. The price includes Apify platform usage; no separate usage pass-through is intended.report-generated: base $0.05000, GOLD $0.04000. Dependency License Auditor: charged when report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
Public Task Concepts
- Audit Dependency License controls on a capped public sample
- Find high-priority Dependency License issues before release
- Validate Dependency License evidence from supplied pages
- Prioritize Dependency License fixes with severity and proof
- Export Dependency License QA rows for client review
Audit dependency manifests for license types, unknown licenses, and policy risk.
What This Actor Does
Dependency License Auditor turns explicit watchlists or supplied records into structured Apify dataset rows and a concise report. The capped built-in records make the default run deterministic and avoid network, browser, proxy, LLM, or third-party API costs.
The actor checks each supplied record for source identity, matched watch terms, actor-specific metadata, issue signals, severity, recommendations, and pricing metadata. It writes one dataset row per processed record and, when enabled, key-value-store JSON and Markdown summaries for operational workflows.
What This Actor Does Not Do
- It does not provide legal, medical, financial, investment, safety, or compliance advice.
- It does not guarantee completeness of any public source or third-party dataset.
- It does not collect sensitive personal data by default.
- It does not rely on unsupported private APIs.
Best Use Cases
- manifest license checks
- open-source policy reviews
- unknown-license triage
Input Fields Explained
| Field | Type | Default | Notes |
|---|---|---|---|
records | array | two built-in records | Records or snapshots to check. Each item can include title, description, body, entity, category, keywords, and metadata. |
urls | array | [] | Reserved for optional source URLs. Defaults do not fetch URLs. |
fetchUrls | boolean | false | Enables HTTP fetching for records with sourceUrl and no body. Keep false when records already contain the text to analyze. |
watchTerms | array | actor defaults | Terms used to mark relevant records and alerts. |
includeReport | boolean | true | Writes JSON and Markdown report artifacts to the key-value store. |
maxItems | integer | 2 | Caps processed records. Maximum is 50. |
maxTextBytes | integer | 500000 | Caps analyzed text per record. |
debug | boolean | false | Enables debug logging. |
Example Input
{"records": [{"sourceId": "dep-react","sourceUrl": "package.json","title": "react dependency","description": "react dependency in production manifest uses MIT license.","entityName": "react","category": "dependency","keywords": ["MIT"],"metadata": {"packageName": "react","version": "19.0.0","license": "MIT","policy": "allowed"}},{"sourceId": "dep-risk","sourceUrl": "package.json","title": "legacy-report dependency","description": "legacy-report dependency has GPL-3.0 license and unknown policy approval.","entityName": "legacy-report","category": "dependency","keywords": ["GPL"],"metadata": {"packageName": "legacy-report","version": "1.2.3","license": "GPL-3.0","policy": "unknown"}}],"includeReport": true,"maxItems": 2}
Output Fields Explained
| Field | Meaning |
|---|---|
auditId | Stable hash for the checked record. |
sourceId, sourceUrl | Source identifiers for traceability. |
status, severity, score | Normalized outcome and 0-100 quality/risk score. |
matchedKeywords | Watch terms found in the record text or metadata. |
issues, issueCodes | Actor-specific findings with severity and messages. |
recommendations | Next actions for the operator or content/data owner. |
metadata | Original metadata plus derived helper fields when applicable. |
pricingTemplate, pricingEventName | Pricing source and primary PPE event used by the actor. |
Example Output
{"auditId": "dependen_a82e804f031934c4","actorSlug": "dependency-license-auditor","actorName": "Dependency License Auditor","sourceType": "fixture","sourceId": "dep-react","sourceUrl": "package.json","title": "react dependency","status": "pass","severity": "none","score": 100,"matchedKeywords": [],"primaryEntity": "react","category": "dependency","publishedAt": null,"summary": "react dependency in production manifest uses MIT license.","issueCount": 0,"issues": [],"issueCodes": [],"recommendations": ["Dependency License Auditor did not find immediate risk signals for this record. Re-run after source data changes."],"metadata": {"packageName": "react","version": "19.0.0","license": "MIT","policy": "allowed","sourceSpecific": {"licenseRows": [{"packageName": "react","license": "MIT","policyStatus": "allowed"}]},"normalizedTextPreview": "dep-react package.json react dependency react dependency in production manifest uses MIT license. react dependency MIT {\"packageName\":\"react\",\"version\":\"19.0.0\",\"license\":\"MIT\",\"policy\":\"allowed\"}"},"textBytes": 197,"checkedAt": "2026-07-02T00:00:00.000Z","pricingTemplate": "A1 — API/developer QA","pricingEventName": "operation-tested"}
Cost-Control Tips
- Keep
maxItemssmall for default and scheduled checks. - Use supplied records or snapshots for deterministic QA runs.
- Leave
fetchUrlsoff unless live source fetching is explicitly needed. - Review warning rows before increasing caps.
- Schedule small frequent runs instead of broad one-off sweeps.
Scheduling Examples
- Daily watchlist check with two to five high-value records.
- Weekly QA run before publishing a site, data, or actor update.
- Post-migration or post-release validation using a saved record set.
Public Task Examples
tiny-default-check- Run a two-record dependency license auditor check with report artifacts enabled.watchlist-digest- Process a small supplied watchlist and summarize matched terms.risk-triage-report- Return only records with warning or fail status for operator follow-up.scheduled-monitor- Run Dependency License Auditor on a daily or weekly schedule with tight caps.schema-and-billing-preflight- Validate output shape and PPE event names before live setup.
FAQ
Can I schedule recurring checks?
Yes. Save a capped input and use Apify schedules to run it daily or weekly.
Can I use this with live URLs?
Yes. Set fetchUrls to true and provide urls or records with sourceUrl. Failed fetches produce explicit diagnostic rows.
Why does it charge before pushing output?
Pay-per-event actors must charge before paid output is written. If the charge limit is reached, processing stops before another paid row is emitted.
What happens on charge limits?
The actor stops gracefully and writes a summary instead of pushing unpaid result rows.
Is this legal, financial, safety, or compliance advice?
No. The actor produces operational signals and structured data for review. Human owners remain responsible for decisions.
Troubleshooting
- If the dataset is empty, check that
maxItemsis greater than zero and that records are supplied or defaults are enabled. - If a record is flagged unexpectedly, inspect
issueCodes,matchedKeywords, and the normalized metadata preview. - If live fetching fails, rerun with supplied record bodies or snapshots and keep
fetchUrlsfalse.
Limitations
This actor only sees the records, snapshots, or URLs supplied to it. It does not guarantee complete public-source coverage, private-source access, or all edge-case parsing. Browser and proxy flows are not used by default.
Source And Safety Notes
The built-in records are labeled through sourceType: "fixture" and are intended to show the output contract. When connecting public sources, use official or permissioned endpoints where possible and avoid sensitive personal data. Do not use the output as a substitute for professional advice.
Changelog
- 2026-07-02: Initial actor package with schemas, capped defaults, pricing controls, and runtime validation.