๐ Feluda is a Rust-based command-line tool that analyzes the dependencies of a project, notes down their licenses, and flags any permissions that restrict personal or commercial usage.
๐ It's still highly experimental, but fast iterating. Welcoming contributors and support to help bring out this project even better!
- Parse your project to identify dependencies and their licenses.
- Classify licenses into permissive, restrictive, or unknown categories.
- Flag dependencies with licenses that may restrict personal or commercial use.
- Output results in plain text, JSON or TUI formats. There's also a gist format which is available in strict mode to output a single line only.
- CI/CD support for Github Actions and Jenkins.
- Verbose mode gives an enhanced view of all licenses.
Feluda supports analyzing dependencies across multiple languages simultaneously. You can also filter the analysis to a specific language using the --language flag.
feluda --language {rust|node|go|python}If your fav language or framework isn't supported, feel free to open an feature request issue! ๐
Rust (Crate)
- Rust installed on your system.
If you already had it, make sure it's up-to-date and update if needed. (Optional) Set rust path if not set already.
cargo install feludaHomebrew (maintained by @chenrui333)
feluda is available in the Homebrew. You can install it using brew:
brew install feludaArch Linux (maintained by @adamperkowski)
feluda is available in the AUR. You can install it using an AUR helper (e.g. paru):
paru -S feludaNetBSD (maintained by @0323pin)
On NetBSD a package is available from the official repositories. To install it, simply run:
pkgin install feludaTrack releases on github releases or via release feed.
Build from Source (advanced users)
Note: This might have experimental features which might not work as intended.
First, clone the repository:
git clone https://github.com/anistark/feluda.git
cd feludaThen, build the project using Cargo:
cargo build --releaseFinally, to make feluda available globally, move the binary to a directory in your PATH. For example:
sudo mv target/release/feluda /usr/local/bin/Run the tool in the project directory:
feludafeluda --path /path/to/project/If you're using Feluda, feel free to grab a Scanned with Feluda badge for your project:
[](https://github.com/anistark/feluda)
- Default: Plain text.
- JSON: Use the
--jsonflag for JSON output.
feluda --jsonSample Output for a sample cargo.toml file containing serde and tokio dependencies:
[
{
"name": "serde",
"version": "1.0.151",
"license": "MIT",
"is_restrictive": false
},
{
"name": "tokio",
"version": "1.0.2",
"license": "MIT",
"is_restrictive": false
}
]For detailed information about each dependency:
feluda --verboseIn case you strictly need only the restrictive dependencies:
feluda --strictWe've an awesome โจ TUI mode available to browse through the dependencies in a visually appealing way as well:
feluda --guiFeluda provides several options for CI integration:
--ci-format <github|jenkins>: Generate output compatible with the specified CI system--fail-on-restrictive: Make the CI build fail when restrictive licenses are found--output-file <path>: Write the output to a file instead of stdout
Feluda can be easily integrated into your CI/CD pipelines with built-in support for GitHub Actions and Jenkins.
To use Feluda with GitHub Actions, create a .github/workflows/feluda.yml file with the following content:
name: License Check
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
jobs:
check-licenses:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v3
- name: Install Rust
uses: actions-rs/toolchain@v1
with:
profile: minimal
toolchain: stable
override: true
- name: Install Feluda
run: cargo install feluda
- name: Check licenses
run: feluda --ci-format github --fail-on-restrictiveCheckout contributing guidelines if you are looking to contribute to this project.
Currently, using choosealicense license directory for source of truth.
Feluda allows you to customize which licenses are considered restrictive through configuration. This can be done in three ways, listed in order of precedence (highest to lowest):
- Environment variables
.feluda.tomlconfiguration file- Default values
By default, Feluda considers the following licenses as restrictive:
- GPL-3.0
- AGPL-3.0
- LGPL-3.0
- MPL-2.0
- SEE LICENSE IN LICENSE
- CC-BY-SA-4.0
- EPL-2.0
Create a .feluda.toml file in your project root to override the default restrictive licenses:
[licenses]
# Override the default list of restrictive licenses
restrictive = [
"GPL-3.0", # GNU General Public License v3.0
"AGPL-3.0", # GNU Affero General Public License v3.0
"Custom-1.0", # Your custom license identifier
]You can also override the configuration using environment variables:
# Override restrictive licenses list
export FELUDA_LICENSES_RESTRICTIVE='["GPL-3.0","AGPL-3.0","Custom-1.0"]'The environment variables take precedence over both the configuration file and default values.
Feluda is licensed under the MIT License.
Happy coding with Feluda! ๐



