FARION.AI
  • Home
  • Product
      • Platform
      • Platform overview
      • Exploitability Analysis
      • Supply Chain Security
      • Vulnerability Management
      • Active Verification
      • Software License Compliance
      • Solutions
      • Cyber Resilience Act
      • NIS2 Compliance
      • SaaS Application Security
      • AI-Generated Code Security
      • Container Security
      • Pricing
      • Plans & pricing
      • About
      • Technology overview
      • Contact us
      • Imprint
      • Privacy
      • Farion dashboard
        Start free now
  • About
Sign in
Start free now
Software License Compliance

Know which licenses ship with your software.

Review the licenses in your direct and transitive dependencies, understand their obligations, and check them against your organization’s policy—with the supporting evidence attached.

Inspect what ships

See the evidence behind each detected license.

Package-registry metadata does not always tell the whole story. Farion inspects the license files and contents shipped with a dependency so you can review what the detected license is based on.

Sample data · as of October 2026
License Identity
GPL-2.0-or-later
Registry & scan match
Detected fromScancode
License file
license.md
Confidence96%
Classification
TypeStrong copyleft
Copyleft
strong
Obligations
Disclose SourceSame LicenseState ChangesInclude License
Copyright Holders
Ephox Corporation DBA Tiny Technologies, Inc
License Text
Full details

The licenses for most software are designed to take away your freedom to share and change it. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change free software--to make sure the software is free for all its users.

Package Info
Web based JavaScript HTML WYSIWYG editor control
Repository
https://github.com/tinymce/tinymce
Policy
Verdict
License not on allowlist
Obligations

Understand what a dependency asks of you.

Review attribution, notices, source-disclosure, and redistribution obligations alongside the dependency and the applications that use it.

Policies

Check dependencies against your license policy.

Define which licenses your organization accepts, restricts, or prohibits. Apply those rules to direct and transitive dependencies to identify packages that need review.

Sample data · as of October 2026
License Compliance

87%

compliant

298 of 312 libraries have license data

Total libraries

312

Compliant

271

Non-compliant

3

Unknown license

14
Non-compliant libraries
iText@7.2.5
AGPL-3.0
node-forge@1.3.1
(BSD-3-Clause OR GPL-2.0) — Dual-licensed, selection required
tinymce@7.0.0
GPL-2.0-or-later
Complex licensing

Resolve ambiguous license information.

Review multiple licenses, alternative license expressions, and differences between registry metadata and shipped files. Keep the evidence and dependency context together when making a decision.

Reports

Share the evidence for a license review.

Export a license inventory with detected licenses, supporting files, obligations, policy results, and affected applications. Give reviewers the context behind each entry.

Frequently asked questions

No. Farion analyzes the license files and package contents associated with the dependency and retains the evidence behind the detected license.

Yes. Organizations can classify licenses according to their own accepted, restricted, and prohibited categories and evaluate dependencies against that policy.

Yes. License findings remain connected to the complete dependency path and the application in which the component was discovered.

Review the licenses in your own dependencies.

Walk through detected licenses, supporting evidence, and policy results with our team.

Start free nowNo credit card required
Book a technical demo

FARION.AI

The Farion platform combines native SAST, exploitability-aware SCA with SBOM, VEX and license compliance, and SAST-informed active AI verification.

Platform
Platform overviewExploitability AnalysisSupply Chain SecurityVulnerability ManagementActive VerificationLicense Compliance
Solutions
Cyber Resilience ActNIS2 ComplianceSaaS Application SecurityAI-Generated Code SecurityContainer SecurityCompliance
Scanners
SASTSCADAST
Technology
Technology overviewVulnerability IntelligenceRoute & Data Flow AnalysisLanguages & FrameworksArchitecture & DeploymentIntegrations
Farion
About usPricingFAQsSecurityContact us
Legal
ImprintPrivacyTerms and Conditions (AGB)
Contact
sales@farion.ai

© All rights reserved.