This is a real report generated by licenseproof Get yours  ·  Back to site

LicenseProof · Dependency license report

License report for acme-video-platform

Project license
UNLICENSED
Scan date
2026-07-22T08:37:33.285Z
Packages
121 (npm: 104 · pypi: 17)
Conflicts
1
Review
1
Unknown
1
Tool version
0.3.0
Data version
2026.07.21.2

1 license conflict requires attention before distribution.

Informational license categorization — not legal advice.

Executive summary

This report covers 121 packages resolved from the npm and PyPI dependency trees of acme-video-platform, whose declared project license is UNLICENSED.

1 package was flagged as a license conflict against the project license. 1 package was flagged for manual review. 1 could not be confidently identified. The remaining 118 raised no flags.

Among the packages whose license was identified, the most restrictive category present is strong copyleft.

Findings

Packages that raised a flag against the project license, most restrictive first. Clean packages are listed in the full inventory below.

Conflict (1)

Conflict ffmpeg-static@5.3.0 npm direct · production dependency
License
GPL-3.0-or-later
Category
strong copyleft
Confidence
high
Source
metadata
Dependency
via ffmpeg-static

This package is under a strong-copyleft license (e.g. GPL/AGPL). Distributing it as part of a closed-source product can require releasing your own source code under the same terms. Flagged as CONFLICT for a proprietary project.

Review (1)

Review certifi@2026.7.22 pypi transitive · production dependency
License
MPL-2.0
Category
weak copyleft
Confidence
high
Source
metadata
Dependency
via requests → certifi

This package is under a weak-copyleft license (e.g. LGPL/MPL). Obligations typically depend on whether you modify the package or merely link/import it dynamically. Flagged for REVIEW, not automatic CONFLICT.

Unknown (1)

Unknown colorama@0.4.6 pypi transitive · production dependency
License
UNKNOWN
Category
unknown
Confidence
low
Source
none
Dependency
via click → colorama

LicenseProof could not confidently identify this package's license. Unknown does not mean safe — flagged for manual REVIEW.

Full inventory

Every scanned package, ordered by status then name. Matches the JSON report ordering.

All 121 packages
PackageVersionEcosystemLicense CategoryConfidenceSourceStatus
ffmpeg-static 5.3.0 npm GPL-3.0-or-later strong copyleft high metadata Conflict
certifi 2026.7.22 pypi MPL-2.0 weak copyleft high metadata Review
colorama 0.4.6 pypi UNKNOWN unknown low none Unknown
@derhuerst/http-basic 8.2.4 npm MIT permissive high metadata clean
@types/node 10.17.60 npm MIT permissive high metadata clean
accepts 1.3.8 npm MIT permissive high metadata clean
agent-base 6.0.2 npm MIT permissive high metadata clean
annotated-types 0.7.0 pypi MIT permissive medium classifier clean
array-flatten 1.1.1 npm MIT permissive high metadata clean
asynckit 0.4.0 npm MIT permissive high metadata clean
axios 1.18.1 npm MIT permissive high metadata clean
body-parser 1.20.6 npm MIT permissive high metadata clean
buffer-from 1.1.2 npm MIT permissive high metadata clean
bytes 3.1.2 npm MIT permissive high metadata clean
call-bind-apply-helpers 1.0.2 npm MIT permissive high metadata clean
call-bound 1.0.4 npm MIT permissive high metadata clean
caseless 0.12.0 npm Apache-2.0 permissive high metadata clean
chalk 5.6.2 npm MIT permissive high metadata clean
charset-normalizer 3.4.9 pypi MIT permissive high metadata clean
click 8.4.2 pypi BSD-3-Clause permissive high expression clean
combined-stream 1.0.8 npm MIT permissive high metadata clean
concat-stream 2.0.0 npm MIT permissive high metadata clean
content-disposition 0.5.4 npm MIT permissive high metadata clean
content-type 1.0.5 npm MIT permissive high metadata clean
cookie 0.7.2 npm MIT permissive high metadata clean
cookie-signature 1.0.7 npm MIT permissive high metadata clean
cors 2.8.6 npm MIT permissive high metadata clean
dayjs 1.11.21 npm MIT permissive high metadata clean
debug 4.4.3 npm MIT permissive high metadata clean
debug 2.6.9 npm MIT permissive high metadata clean
debug 4.4.3 npm MIT permissive high metadata clean
delayed-stream 1.0.0 npm MIT permissive high metadata clean
depd 2.0.0 npm MIT permissive high metadata clean
destroy 1.2.0 npm MIT permissive high metadata clean
dunder-proto 1.0.1 npm MIT permissive high metadata clean
ee-first 1.1.1 npm MIT permissive high metadata clean
encodeurl 2.0.0 npm MIT permissive high metadata clean
env-paths 2.2.1 npm MIT permissive high metadata clean
es-define-property 1.0.1 npm MIT permissive high metadata clean
es-errors 1.3.0 npm MIT permissive high metadata clean
es-object-atoms 1.1.2 npm MIT permissive high metadata clean
es-set-tostringtag 2.1.0 npm MIT permissive high metadata clean
escape-html 1.0.3 npm MIT permissive high metadata clean
etag 1.8.1 npm MIT permissive high metadata clean
express 4.22.2 npm MIT permissive high metadata clean
finalhandler 1.3.2 npm MIT permissive high metadata clean
follow-redirects 1.16.0 npm MIT permissive high metadata clean
form-data 4.0.6 npm MIT permissive high metadata clean
forwarded 0.2.0 npm MIT permissive high metadata clean
fresh 0.5.2 npm MIT permissive high metadata clean
function-bind 1.1.2 npm MIT permissive high metadata clean
get-intrinsic 1.3.0 npm MIT permissive high metadata clean
get-proto 1.0.1 npm MIT permissive high metadata clean
gopd 1.2.0 npm MIT permissive high metadata clean
has-symbols 1.1.0 npm MIT permissive high metadata clean
has-tostringtag 1.0.2 npm MIT permissive high metadata clean
hasown 2.0.4 npm MIT permissive high metadata clean
http-errors 2.0.1 npm MIT permissive high metadata clean
http-response-object 3.0.2 npm MIT permissive high metadata clean
https-proxy-agent 5.0.1 npm MIT permissive high metadata clean
iconv-lite 0.4.24 npm MIT permissive high metadata clean
idna 3.18 pypi BSD-3-Clause permissive high expression clean
inherits 2.0.4 npm ISC permissive high metadata clean
ipaddr.js 1.9.1 npm MIT permissive high metadata clean
lodash 4.18.1 npm MIT permissive high metadata clean
markdown-it-py 4.2.0 pypi MIT permissive medium classifier clean
math-intrinsics 1.1.0 npm MIT permissive high metadata clean
mdurl 0.1.2 pypi MIT permissive medium classifier clean
media-typer 0.3.0 npm MIT permissive high metadata clean
merge-descriptors 1.0.3 npm MIT permissive high metadata clean
methods 1.1.2 npm MIT permissive high metadata clean
mime 1.6.0 npm MIT permissive high metadata clean
mime-db 1.52.0 npm MIT permissive high metadata clean
mime-types 2.1.35 npm MIT permissive high metadata clean
ms 2.1.3 npm MIT permissive high metadata clean
ms 2.1.3 npm MIT permissive high metadata clean
ms 2.0.0 npm MIT permissive high metadata clean
ms 2.1.3 npm MIT permissive high metadata clean
negotiator 0.6.3 npm MIT permissive high metadata clean
object-assign 4.1.1 npm MIT permissive high metadata clean
object-inspect 1.13.4 npm MIT permissive high metadata clean
on-finished 2.4.1 npm MIT permissive high metadata clean
parse-cache-control 1.0.1 npm BSD-3-Clause permissive medium license-file clean
parseurl 1.3.3 npm MIT permissive high metadata clean
path-to-regexp 0.1.13 npm MIT permissive high metadata clean
progress 2.0.3 npm MIT permissive high metadata clean
proxy-addr 2.0.7 npm MIT permissive high metadata clean
proxy-from-env 2.1.0 npm MIT permissive high metadata clean
pydantic 2.13.4 pypi MIT permissive high expression clean
pydantic-core 2.46.4 pypi MIT permissive high expression clean
pygments 2.20.0 pypi BSD-2-Clause permissive high expression clean
python-dotenv 1.2.2 pypi BSD-3-Clause permissive high metadata clean
qs 6.15.3 npm BSD-3-Clause permissive high metadata clean
range-parser 1.2.1 npm MIT permissive high metadata clean
raw-body 2.5.3 npm MIT permissive high metadata clean
readable-stream 3.6.2 npm MIT permissive high metadata clean
requests 2.34.2 pypi Apache-2.0 permissive high metadata clean
rich 15.0.0 pypi MIT permissive high metadata clean
safe-buffer 5.2.1 npm MIT permissive high metadata clean
safer-buffer 2.1.2 npm MIT permissive high metadata clean
send 0.19.2 npm MIT permissive high metadata clean
serve-static 1.16.3 npm MIT permissive high metadata clean
setprototypeof 1.2.0 npm ISC permissive high metadata clean
side-channel 1.1.1 npm MIT permissive high metadata clean
side-channel-list 1.0.1 npm MIT permissive high metadata clean
side-channel-map 1.0.1 npm MIT permissive high metadata clean
side-channel-weakmap 1.0.2 npm MIT permissive high metadata clean
statuses 2.0.2 npm MIT permissive high metadata clean
string_decoder 1.3.0 npm MIT permissive high metadata clean
toidentifier 1.0.1 npm MIT permissive high metadata clean
type-is 1.6.18 npm MIT permissive high metadata clean
typedarray 0.0.6 npm MIT permissive high metadata clean
typing-extensions 4.16.0 pypi PSF-2.0 permissive high expression clean
typing-inspection 0.4.2 pypi MIT permissive high expression clean
unpipe 1.0.0 npm MIT permissive high metadata clean
urllib3 2.7.0 pypi MIT permissive high expression clean
util-deprecate 1.0.2 npm MIT permissive high metadata clean
utils-merge 1.0.1 npm MIT permissive high metadata clean
uuid 9.0.1 npm MIT permissive high metadata clean
vary 1.1.2 npm MIT permissive high metadata clean
zod 3.25.76 npm MIT permissive high metadata clean

Methodology & limitations

How licenses were resolved, what confidence means, and known limitations

How each package's license is resolved

LicenseProof reads only files already present on disk from the scanned project and its installed dependencies. It never contacts a network, registry, or remote service. The two ecosystems use different resolution orders:

npm packages

The first step that yields a license wins (later steps are not consulted):

  1. Declared metadata — the license field in the package's package.json, parsed as an SPDX id or expression (OR / AND / WITH preserved). Confidence: high. npm's UNLICENSED convention is not treated as an SPDX id and falls through.
  2. License file — the text of an on-disk LICENSE/COPYING file, matched by fingerprint against known license texts. Confidence: medium for a close match, low for a modified or partial match.
  3. README mention — a License: line near the top of the README. Confidence: low.
  4. Unknown — no signal resolved; the package is reported as UNKNOWN and flagged for review. Unknown does not mean safe.

PyPI packages

The metadata signals are read together so a disagreement between them can be surfaced; the on-disk steps run only when no metadata signal resolved:

  1. License-Expression — the PEP 639 License-Expression metadata field. Confidence: high.
  2. License — the legacy License metadata field, used when no License-Expression is present. Confidence: high.
  3. Trove classifiers — the License :: classifiers, mapped to a representative SPDX id. Confidence: medium (classifiers are coarser than an explicit id — e.g. "BSD License" cannot distinguish BSD-2 from BSD-3).
  4. License file — on-disk license text, fingerprint-matched. Confidence: medium / low, as for npm.
  5. README mention — a License: line. Confidence: low.
  6. Unknown — reported as UNKNOWN, flagged for review.

When a PyPI package's declared license field and its Trove classifiers resolve to different licenses (and not merely to different variants of the same license family), the package is additionally flagged for review as an internal metadata inconsistency.

What the confidence levels mean

  • high — the license came from an explicit, declared SPDX id or expression in package or project metadata.
  • medium — the license was inferred from a close license-file text match or from a coarse Trove classifier.
  • low — the license came from a modified/partial license-file match, a README mention, or could not be determined at all (Unknown).

Limitations

  • The category assigned to each license is an informational classification, not a legal determination of your obligations.
  • Only declared and detectable license signals are used. No manual legal review is performed, and no upstream registry is consulted (the tool runs fully offline).
  • Dependency paths are enumerated up to a cap; a "+at least N other paths" note is a floor, not an exact total.
  • A package's resolved license reflects the metadata and files present on disk at scan time; it is not verified against any external source of truth.
  • Unknown does not mean safe — it means the license could not be identified confidently and needs a human to look.

Not legal advice

This report is an informational license categorization produced by automated analysis of declared package metadata and license files. It is not legal advice and is not a substitute for review by qualified counsel.