This package is under a strong-copyleft license (e.g. GPL/AGPL). Distributing it as part of a closed-source product can require releasing your own source code under the same terms. Flagged as CONFLICT for a proprietary project.
LicenseProof · Dependency license report
License report for acme-video-platform
- Project license
- UNLICENSED
- Scan date
- 2026-07-22T08:37:33.285Z
- Packages
- 121 (npm: 104 · pypi: 17)
- Conflicts
- 1
- Review
- 1
- Unknown
- 1
- Tool version
- 0.3.0
- Data version
- 2026.07.21.2
1 license conflict requires attention before distribution.
Informational license categorization — not legal advice.
Executive summary
This report covers 121 packages resolved from the npm and PyPI dependency trees of acme-video-platform, whose declared project license is UNLICENSED.
1 package was flagged as a license conflict against the project license. 1 package was flagged for manual review. 1 could not be confidently identified. The remaining 118 raised no flags.
Among the packages whose license was identified, the most restrictive category present is strong copyleft.
Findings
Packages that raised a flag against the project license, most restrictive first. Clean packages are listed in the full inventory below.
Conflict (1)
Review (1)
This package is under a weak-copyleft license (e.g. LGPL/MPL). Obligations typically depend on whether you modify the package or merely link/import it dynamically. Flagged for REVIEW, not automatic CONFLICT.
Unknown (1)
LicenseProof could not confidently identify this package's license. Unknown does not mean safe — flagged for manual REVIEW.
Full inventory
Every scanned package, ordered by status then name. Matches the JSON report ordering.
All 121 packages
| Package | Version | Ecosystem | License | Category | Confidence | Source | Status |
|---|---|---|---|---|---|---|---|
| ffmpeg-static | 5.3.0 | npm | GPL-3.0-or-later | strong copyleft | high | metadata | Conflict |
| certifi | 2026.7.22 | pypi | MPL-2.0 | weak copyleft | high | metadata | Review |
| colorama | 0.4.6 | pypi | UNKNOWN | unknown | low | none | Unknown |
| @derhuerst/http-basic | 8.2.4 | npm | MIT | permissive | high | metadata | clean |
| @types/node | 10.17.60 | npm | MIT | permissive | high | metadata | clean |
| accepts | 1.3.8 | npm | MIT | permissive | high | metadata | clean |
| agent-base | 6.0.2 | npm | MIT | permissive | high | metadata | clean |
| annotated-types | 0.7.0 | pypi | MIT | permissive | medium | classifier | clean |
| array-flatten | 1.1.1 | npm | MIT | permissive | high | metadata | clean |
| asynckit | 0.4.0 | npm | MIT | permissive | high | metadata | clean |
| axios | 1.18.1 | npm | MIT | permissive | high | metadata | clean |
| body-parser | 1.20.6 | npm | MIT | permissive | high | metadata | clean |
| buffer-from | 1.1.2 | npm | MIT | permissive | high | metadata | clean |
| bytes | 3.1.2 | npm | MIT | permissive | high | metadata | clean |
| call-bind-apply-helpers | 1.0.2 | npm | MIT | permissive | high | metadata | clean |
| call-bound | 1.0.4 | npm | MIT | permissive | high | metadata | clean |
| caseless | 0.12.0 | npm | Apache-2.0 | permissive | high | metadata | clean |
| chalk | 5.6.2 | npm | MIT | permissive | high | metadata | clean |
| charset-normalizer | 3.4.9 | pypi | MIT | permissive | high | metadata | clean |
| click | 8.4.2 | pypi | BSD-3-Clause | permissive | high | expression | clean |
| combined-stream | 1.0.8 | npm | MIT | permissive | high | metadata | clean |
| concat-stream | 2.0.0 | npm | MIT | permissive | high | metadata | clean |
| content-disposition | 0.5.4 | npm | MIT | permissive | high | metadata | clean |
| content-type | 1.0.5 | npm | MIT | permissive | high | metadata | clean |
| cookie | 0.7.2 | npm | MIT | permissive | high | metadata | clean |
| cookie-signature | 1.0.7 | npm | MIT | permissive | high | metadata | clean |
| cors | 2.8.6 | npm | MIT | permissive | high | metadata | clean |
| dayjs | 1.11.21 | npm | MIT | permissive | high | metadata | clean |
| debug | 4.4.3 | npm | MIT | permissive | high | metadata | clean |
| debug | 2.6.9 | npm | MIT | permissive | high | metadata | clean |
| debug | 4.4.3 | npm | MIT | permissive | high | metadata | clean |
| delayed-stream | 1.0.0 | npm | MIT | permissive | high | metadata | clean |
| depd | 2.0.0 | npm | MIT | permissive | high | metadata | clean |
| destroy | 1.2.0 | npm | MIT | permissive | high | metadata | clean |
| dunder-proto | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| ee-first | 1.1.1 | npm | MIT | permissive | high | metadata | clean |
| encodeurl | 2.0.0 | npm | MIT | permissive | high | metadata | clean |
| env-paths | 2.2.1 | npm | MIT | permissive | high | metadata | clean |
| es-define-property | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| es-errors | 1.3.0 | npm | MIT | permissive | high | metadata | clean |
| es-object-atoms | 1.1.2 | npm | MIT | permissive | high | metadata | clean |
| es-set-tostringtag | 2.1.0 | npm | MIT | permissive | high | metadata | clean |
| escape-html | 1.0.3 | npm | MIT | permissive | high | metadata | clean |
| etag | 1.8.1 | npm | MIT | permissive | high | metadata | clean |
| express | 4.22.2 | npm | MIT | permissive | high | metadata | clean |
| finalhandler | 1.3.2 | npm | MIT | permissive | high | metadata | clean |
| follow-redirects | 1.16.0 | npm | MIT | permissive | high | metadata | clean |
| form-data | 4.0.6 | npm | MIT | permissive | high | metadata | clean |
| forwarded | 0.2.0 | npm | MIT | permissive | high | metadata | clean |
| fresh | 0.5.2 | npm | MIT | permissive | high | metadata | clean |
| function-bind | 1.1.2 | npm | MIT | permissive | high | metadata | clean |
| get-intrinsic | 1.3.0 | npm | MIT | permissive | high | metadata | clean |
| get-proto | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| gopd | 1.2.0 | npm | MIT | permissive | high | metadata | clean |
| has-symbols | 1.1.0 | npm | MIT | permissive | high | metadata | clean |
| has-tostringtag | 1.0.2 | npm | MIT | permissive | high | metadata | clean |
| hasown | 2.0.4 | npm | MIT | permissive | high | metadata | clean |
| http-errors | 2.0.1 | npm | MIT | permissive | high | metadata | clean |
| http-response-object | 3.0.2 | npm | MIT | permissive | high | metadata | clean |
| https-proxy-agent | 5.0.1 | npm | MIT | permissive | high | metadata | clean |
| iconv-lite | 0.4.24 | npm | MIT | permissive | high | metadata | clean |
| idna | 3.18 | pypi | BSD-3-Clause | permissive | high | expression | clean |
| inherits | 2.0.4 | npm | ISC | permissive | high | metadata | clean |
| ipaddr.js | 1.9.1 | npm | MIT | permissive | high | metadata | clean |
| lodash | 4.18.1 | npm | MIT | permissive | high | metadata | clean |
| markdown-it-py | 4.2.0 | pypi | MIT | permissive | medium | classifier | clean |
| math-intrinsics | 1.1.0 | npm | MIT | permissive | high | metadata | clean |
| mdurl | 0.1.2 | pypi | MIT | permissive | medium | classifier | clean |
| media-typer | 0.3.0 | npm | MIT | permissive | high | metadata | clean |
| merge-descriptors | 1.0.3 | npm | MIT | permissive | high | metadata | clean |
| methods | 1.1.2 | npm | MIT | permissive | high | metadata | clean |
| mime | 1.6.0 | npm | MIT | permissive | high | metadata | clean |
| mime-db | 1.52.0 | npm | MIT | permissive | high | metadata | clean |
| mime-types | 2.1.35 | npm | MIT | permissive | high | metadata | clean |
| ms | 2.1.3 | npm | MIT | permissive | high | metadata | clean |
| ms | 2.1.3 | npm | MIT | permissive | high | metadata | clean |
| ms | 2.0.0 | npm | MIT | permissive | high | metadata | clean |
| ms | 2.1.3 | npm | MIT | permissive | high | metadata | clean |
| negotiator | 0.6.3 | npm | MIT | permissive | high | metadata | clean |
| object-assign | 4.1.1 | npm | MIT | permissive | high | metadata | clean |
| object-inspect | 1.13.4 | npm | MIT | permissive | high | metadata | clean |
| on-finished | 2.4.1 | npm | MIT | permissive | high | metadata | clean |
| parse-cache-control | 1.0.1 | npm | BSD-3-Clause | permissive | medium | license-file | clean |
| parseurl | 1.3.3 | npm | MIT | permissive | high | metadata | clean |
| path-to-regexp | 0.1.13 | npm | MIT | permissive | high | metadata | clean |
| progress | 2.0.3 | npm | MIT | permissive | high | metadata | clean |
| proxy-addr | 2.0.7 | npm | MIT | permissive | high | metadata | clean |
| proxy-from-env | 2.1.0 | npm | MIT | permissive | high | metadata | clean |
| pydantic | 2.13.4 | pypi | MIT | permissive | high | expression | clean |
| pydantic-core | 2.46.4 | pypi | MIT | permissive | high | expression | clean |
| pygments | 2.20.0 | pypi | BSD-2-Clause | permissive | high | expression | clean |
| python-dotenv | 1.2.2 | pypi | BSD-3-Clause | permissive | high | metadata | clean |
| qs | 6.15.3 | npm | BSD-3-Clause | permissive | high | metadata | clean |
| range-parser | 1.2.1 | npm | MIT | permissive | high | metadata | clean |
| raw-body | 2.5.3 | npm | MIT | permissive | high | metadata | clean |
| readable-stream | 3.6.2 | npm | MIT | permissive | high | metadata | clean |
| requests | 2.34.2 | pypi | Apache-2.0 | permissive | high | metadata | clean |
| rich | 15.0.0 | pypi | MIT | permissive | high | metadata | clean |
| safe-buffer | 5.2.1 | npm | MIT | permissive | high | metadata | clean |
| safer-buffer | 2.1.2 | npm | MIT | permissive | high | metadata | clean |
| send | 0.19.2 | npm | MIT | permissive | high | metadata | clean |
| serve-static | 1.16.3 | npm | MIT | permissive | high | metadata | clean |
| setprototypeof | 1.2.0 | npm | ISC | permissive | high | metadata | clean |
| side-channel | 1.1.1 | npm | MIT | permissive | high | metadata | clean |
| side-channel-list | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| side-channel-map | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| side-channel-weakmap | 1.0.2 | npm | MIT | permissive | high | metadata | clean |
| statuses | 2.0.2 | npm | MIT | permissive | high | metadata | clean |
| string_decoder | 1.3.0 | npm | MIT | permissive | high | metadata | clean |
| toidentifier | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| type-is | 1.6.18 | npm | MIT | permissive | high | metadata | clean |
| typedarray | 0.0.6 | npm | MIT | permissive | high | metadata | clean |
| typing-extensions | 4.16.0 | pypi | PSF-2.0 | permissive | high | expression | clean |
| typing-inspection | 0.4.2 | pypi | MIT | permissive | high | expression | clean |
| unpipe | 1.0.0 | npm | MIT | permissive | high | metadata | clean |
| urllib3 | 2.7.0 | pypi | MIT | permissive | high | expression | clean |
| util-deprecate | 1.0.2 | npm | MIT | permissive | high | metadata | clean |
| utils-merge | 1.0.1 | npm | MIT | permissive | high | metadata | clean |
| uuid | 9.0.1 | npm | MIT | permissive | high | metadata | clean |
| vary | 1.1.2 | npm | MIT | permissive | high | metadata | clean |
| zod | 3.25.76 | npm | MIT | permissive | high | metadata | clean |
Methodology & limitations
How licenses were resolved, what confidence means, and known limitations
How each package's license is resolved
LicenseProof reads only files already present on disk from the scanned project and its installed dependencies. It never contacts a network, registry, or remote service. The two ecosystems use different resolution orders:
npm packages
The first step that yields a license wins (later steps are not consulted):
- Declared metadata — the
licensefield in the package'spackage.json, parsed as an SPDX id or expression (OR / AND / WITH preserved). Confidence: high. npm'sUNLICENSEDconvention is not treated as an SPDX id and falls through. - License file — the text of an on-disk
LICENSE/COPYINGfile, matched by fingerprint against known license texts. Confidence: medium for a close match, low for a modified or partial match. - README mention — a
License:line near the top of the README. Confidence: low. - Unknown — no signal resolved; the package is reported as
UNKNOWNand flagged for review. Unknown does not mean safe.
PyPI packages
The metadata signals are read together so a disagreement between them can be surfaced; the on-disk steps run only when no metadata signal resolved:
- License-Expression — the PEP 639
License-Expressionmetadata field. Confidence: high. - License — the legacy
Licensemetadata field, used when noLicense-Expressionis present. Confidence: high. - Trove classifiers — the
License ::classifiers, mapped to a representative SPDX id. Confidence: medium (classifiers are coarser than an explicit id — e.g. "BSD License" cannot distinguish BSD-2 from BSD-3). - License file — on-disk license text, fingerprint-matched. Confidence: medium / low, as for npm.
- README mention — a
License:line. Confidence: low. - Unknown — reported as
UNKNOWN, flagged for review.
When a PyPI package's declared license field and its Trove classifiers resolve to different licenses (and not merely to different variants of the same license family), the package is additionally flagged for review as an internal metadata inconsistency.
What the confidence levels mean
- high — the license came from an explicit, declared SPDX id or expression in package or project metadata.
- medium — the license was inferred from a close license-file text match or from a coarse Trove classifier.
- low — the license came from a modified/partial license-file match, a README mention, or could not be determined at all (Unknown).
Limitations
- The category assigned to each license is an informational classification, not a legal determination of your obligations.
- Only declared and detectable license signals are used. No manual legal review is performed, and no upstream registry is consulted (the tool runs fully offline).
- Dependency paths are enumerated up to a cap; a "+at least N other paths" note is a floor, not an exact total.
- A package's resolved license reflects the metadata and files present on disk at scan time; it is not verified against any external source of truth.
- Unknown does not mean safe — it means the license could not be identified confidently and needs a human to look.
Not legal advice
This report is an informational license categorization produced by automated analysis of declared package metadata and license files. It is not legal advice and is not a substitute for review by qualified counsel.