OSS Licence Gate · v0.1 (npm · permissive licences)

Know what your dependencies require before you distribute them.

ShipGate identifies the components in your release's distribution closure, maps their licences to your declared distribution model, checks required notices, and prepares the mechanical fixes it safely can. No licence-risk score — every result shows what was observed, what you declared, what rule was derived, and what still needs human review.

Artifact Witness (beta) — inspect what actually ships

Witness an already-published npm package tarball by SHA-256. ShipGate downloads the exact .tgz, opens it without executing it, and reports what is physically inside — bundled components are Observed in artifact; runtime dependencies named but not carried stay Assumed. This is where a licence blocker is backed by the distributed bytes, not a lockfile guess.

Or witness a GitHub Release asset by SHA-256 — one asset, one receipt (a release label is intent; the artifact hash is evidence). Archive assets only in v0.1 (.zip, .tar.gz).