返回目录
模型与 MCP 插件

dsh-license-obligation-proof

dongsheng123132/dsh-license-obligation-proof

Evidence-only DSH plugin for license obligation delivery closure

Stars
0
Forks
0
Issues
0
更新
14 天前

PROJECT TOPICS

项目标签

INSTALL REFERENCE

安装参考

未验证
dsh plugin --profile web add github:dongsheng123132/dsh-license-obligation-proof

该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。

PROJECT README

README

dsh-license-obligation-proof

Offline, deterministic evidence that every required compliance artifact for a supplied release decision was delivered: NOTICE, license text, source offer, source bundle, or modification notice. Inputs and reports contain hashes, obligation codes and bounded metadata only—never license bodies, copyright text, package source or secrets.

This is deliberately not another license scanner. dsh-license-guard already scans node_modules, normalizes SPDX identifiers and applies allow/deny policy. This plugin starts after scanning and expert review: it verifies that the declared component set, decisions, obligations, delivered artifact digests, distinct receipts and fresh zero-unresolved closure agree. It does not scan packages, normalize SPDX, interpret a license, or provide legal advice.

npm test
npm run check
node bin/dsh-license-obligation-proof.mjs verify examples/closed.json

DSH tools: dsh_license_obligation_inspect and dsh_license_obligation_verify. MCP exposes equivalent proof-only inline tools. Reports explicitly retain provesComponentSetExhaustive: false and provesLegalCompliance: false.

References: SPDX License Expressions and OpenChain ISO/IEC 5230.

MIT licensed.

CLASSIFICATION EVIDENCE

分类依据

项目类型插件
功能分类模型与 MCP
规则置信度

系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: audit-evidence、mcp。