License Classification

Understand how Sysdig resolves the license of each package to a category, and which categories raise a license finding

Overview

Sysdig reads the license metadata of each package it detects in a scan. It then resolves the license to one of nine categories. The category tells you what kind of obligation or restriction the license carries.

The category is a property of the license, not a judgment about your obligations. Consult your own legal counsel before you act on it.

Feature Availability

License information is in Technical Preview. It is still in active development and can change significantly in future releases.

License Categories

The categories are ordered from least to most restrictive, with the two categories for an undetermined license last. Seven of the nine categories raise a license finding on the Supply Chain Findings page.

CategoryMeaningFindingSeverity
PermissiveFew obligations beyond attribution.NoneNone
Weak CopyleftSharing obligations apply to the component, not to your work.NoneNone
CopyleftSharing obligations extend to work that includes it.Component uses a copyleft licenseMedium
Network CopyleftSharing obligations extend to use over a network.Component uses a network copyleft licenseCritical
Restricted UseThe license restricts how you can use the component.Component uses a license that restricts useMedium
Commercial RestrictionThe license restricts commercial use.Component uses a license that restricts commercial useCritical
ProprietaryThe license is not an open source license.Component uses a proprietary licenseMedium
AmbiguousThe license terms are unclear.Component uses a license with ambiguous termsLow
UnknownSysdig could not recognize the license.Component uses an unrecognized licenseNegligible

Permissive and Weak Copyleft licenses raise no finding. Weak copyleft licenses such as the LGPL appear in most operating system images, so a finding for each one would hide the findings that need your attention.

How Sysdig Resolves a Category

Sysdig gives each package one category, and raises at most one license finding for it:

  • One license: the category of that license applies.
  • More than one license: the most restrictive category applies. The finding still lists every license that Sysdig detected on the package.
  • An unrecognized license: the package gets the Unknown category and a Negligible finding.
  • No license metadata: the package reports no license and raises no finding. This is a gap in the package metadata, not an Unknown license.

Where License Information Appears

SurfaceWhat it shows
Supply Chain FindingsThe license findings across your pipeline, registry, and runtime resources, with filters for category and license name.
CLI ScannerThe license of each package and its category in the JSON scan result, and a license summary in the console output.

Limitations

  • Sysdig reports a license only when the package declares license metadata. Packages that do not declare a license report none.