License Classification
Overview
Sysdig reads the license metadata of each package it detects in a scan. It then resolves the license to one of nine categories. The category tells you what kind of obligation or restriction the license carries.
The category is a property of the license, not a judgment about your obligations. Consult your own legal counsel before you act on it.
Feature Availability
License information is in Technical Preview. It is still in active development and can change significantly in future releases.License Categories
The categories are ordered from least to most restrictive, with the two categories for an undetermined license last. Seven of the nine categories raise a license finding on the Supply Chain Findings page.
| Category | Meaning | Finding | Severity |
|---|---|---|---|
| Permissive | Few obligations beyond attribution. | None | None |
| Weak Copyleft | Sharing obligations apply to the component, not to your work. | None | None |
| Copyleft | Sharing obligations extend to work that includes it. | Component uses a copyleft license | Medium |
| Network Copyleft | Sharing obligations extend to use over a network. | Component uses a network copyleft license | Critical |
| Restricted Use | The license restricts how you can use the component. | Component uses a license that restricts use | Medium |
| Commercial Restriction | The license restricts commercial use. | Component uses a license that restricts commercial use | Critical |
| Proprietary | The license is not an open source license. | Component uses a proprietary license | Medium |
| Ambiguous | The license terms are unclear. | Component uses a license with ambiguous terms | Low |
| Unknown | Sysdig could not recognize the license. | Component uses an unrecognized license | Negligible |
Permissive and Weak Copyleft licenses raise no finding. Weak copyleft licenses such as the LGPL appear in most operating system images, so a finding for each one would hide the findings that need your attention.
How Sysdig Resolves a Category
Sysdig gives each package one category, and raises at most one license finding for it:
- One license: the category of that license applies.
- More than one license: the most restrictive category applies. The finding still lists every license that Sysdig detected on the package.
- An unrecognized license: the package gets the Unknown category and a Negligible finding.
- No license metadata: the package reports no license and raises no finding. This is a gap in the package metadata, not an Unknown license.
Where License Information Appears
| Surface | What it shows |
|---|---|
| Supply Chain Findings | The license findings across your pipeline, registry, and runtime resources, with filters for category and license name. |
| CLI Scanner | The license of each package and its category in the JSON scan result, and a license summary in the console output. |
Limitations
- Sysdig reports a license only when the package declares license metadata. Packages that do not declare a license report none.