How to Enforce License Compliance Across Your Supply Chain

Intermediate 20 minutes Security Engineers / Compliance Teams Security & Policy

Set up SPDX license allowlists and blocklists in policies, monitor license coverage from the dashboard, and handle unknown licenses.

Overview

Open source licenses carry legal obligations. Some licenses (e.g., AGPL-3.0) may be incompatible with your organization’s commercial software. Chainsaw tracks SPDX license identifiers for every package and lets you create policies that block or quarantine packages with restricted licenses.

Prerequisites

  • Admin or Manager role in Chainsaw
  • An understanding of which licenses your organization permits (consult your legal team if unsure)

Step 1: Review Current License Coverage

Navigate to the Overview page. The dashboard shows a License Coverage metric breaking down packages into:

  • Known License — SPDX identifier detected
  • Unknown License — No license metadata available
License coverage metric on the dashboard
Dashboard showing the ratio of known vs unknown licenses across your supply chain
A high percentage of unknown licenses indicates metadata gaps. Consider investigating these packages in the Bill of Materials view.

Step 2: Explore Licenses in the Bill of Materials

Navigate to Bill of Materials to see the license associated with each package version.

BOM page with license column
The BOM shows SPDX identifiers for each package

Common SPDX identifiers you’ll encounter:

LicenseSPDX IDTypical Concern
MITMITPermissive — generally safe
Apache 2.0Apache-2.0Permissive — generally safe
GPL 3.0GPL-3.0-onlyCopyleft — requires source disclosure
AGPL 3.0AGPL-3.0-onlyStrong copyleft — network use triggers disclosure
BSD 3-ClauseBSD-3-ClausePermissive — generally safe
LGPL 2.1LGPL-2.1-onlyWeak copyleft — linking restrictions

Step 3: Create a License Blocklist Policy

Navigate to Policies and click Create Policy.

Block Copyleft Licenses

  1. Name: Block Copyleft Licenses
  2. Action: Block
  3. Condition: License → matches list
  4. License List: AGPL-3.0-only, AGPL-3.0-or-later, GPL-3.0-only, GPL-3.0-or-later
Creating a license blocklist policy
Block packages with copyleft licenses that conflict with your business model

Alternatively: Create a License Allowlist

For stricter environments, only allow specific licenses:

  1. Name: Allow Approved Licenses Only
  2. Action: Allow
  3. Condition: License → matches list
  4. License List: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, 0BSD

Then create a catch-all Block policy at lower precedence to deny everything else.

An allowlist approach is more secure but may block legitimate packages with uncommon licenses. Monitor your violations dashboard after enabling.

Step 4: Handle Unknown Licenses

Packages without license metadata are a compliance blind spot. Create a policy for them:

  1. Name: Quarantine Unknown Licenses
  2. Action: Quarantine
  3. Condition: License → is empty/unknown
Policy for unknown licenses
Quarantine packages with no license information for manual review

Step 5: Monitor License Violations

After enabling license policies, check the Overview dashboard for violations. License violations appear alongside vulnerability violations in the metrics.

License violations on the dashboard
License policy violations appear in the violations metrics

Step 6: Create Exceptions for Approved Packages

If a legitimate package is blocked by a license policy (e.g., an internally approved GPL library):

  1. Navigate to Policies
  2. Create an Allow policy with higher precedence
  3. Scope it to the specific package name and version
Creating a license exception
Allow a specific GPL-licensed package that your legal team has approved

License Compliance Impact on Trust Score

License presence contributes to the composite trust score:

ConditionTrust Score Impact
Valid SPDX license present+10 points
No license detected+0 points

Packages with known licenses are considered more trustworthy than those without.

Next Steps