Webhook icon
Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Gate Releases on Dependency License Audit

Audit Python dependency licenses against a denylist and alert Slack before release.

Categories
CloudInfrastructure

One AGPL transitive dep in a proprietary product is a legal meeting nobody scheduled. This blueprint installs the project, runs pip-licenses, and gates on your denylist. The weekly schedule ships disabled.

How it works

  1. audit_licenses (io.kestra.plugin.scripts.shell.Commands on the Python image) clones, installs, runs pip-licenses --format=json, and diffs against the denylist via the ::{"outputs": ...}:: protocol.
  2. denied_found (io.kestra.plugin.core.flow.If) branches to alert_denied or log_clean.
  3. The errors block alerts on failure.
  4. Triggers: a Webhook plus a disabled weekly Schedule.

What you get

  • Flagged packages by name in Slack.
  • A compliance trail per release.

Who it's for

  • Any team shipping a Python service they do not want to open-source.
  • Legal-conscious platform teams.

Why orchestrate this with Kestra

pip-licenses lists licenses; the flow makes it a gate with history. The next step (swap the dep, fail the release, file a ticket) is one task away.

Prerequisites

  • Docker available on the Kestra Worker.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for findings and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set repo_url and denied_licenses.
  3. Run once and read audit_result.
  4. Wire the license-audit webhook into the release pipeline.

How to extend

  • Fail the execution on hits for a hard gate.
  • Emit the full license table as a CSV artifact.
  • Compare against the last accepted list in KV.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.