New to Kestra?
Use blueprints to kickstart your first workflows.
Audit Python dependency licenses against a denylist and alert Slack before release.
One AGPL transitive dep in a proprietary product is a legal meeting nobody scheduled. This blueprint installs the project, runs pip-licenses, and gates on your denylist. The weekly schedule ships disabled.
audit_licenses (io.kestra.plugin.scripts.shell.Commands on the Python image) clones, installs, runs pip-licenses --format=json, and diffs against the denylist via the ::{"outputs": ...}:: protocol.denied_found (io.kestra.plugin.core.flow.If) branches to alert_denied or log_clean.errors block alerts on failure.Webhook plus a disabled weekly Schedule.pip-licenses lists licenses; the flow makes it a gate with history. The next step (swap the dep, fail the release, file a ticket) is one task away.
SLACK_WEBHOOK_URL: webhook for findings and failure alerts.repo_url and denied_licenses.audit_result.license-audit webhook into the release pipeline.