Manage license risk with confidence—especially in the age of AI-assisted development. As AI-generated code becomes more common, managing open source licenses has grown both more complex and more critical. Heeler now helps teams reduce license risk with:
A global license policy to define what’s allowed
Real-time detection of license violations in dependencies
A guardrail to automatically block risky license usage in pull requests
Customizable License Policy
The default license policy based on OSI or FSF Libire -approved licenses. Admins can customize this policy to align with your organization’s legal or compliance requirements. This policy powers Heeler’s detection and enforcement capabilities, including the Unapproved License guardrail and dependency filter. The license policy export provides a CSV which can be shared with Legal Teams for assisting in setup.
Detecting Dependencies with License Violations
Heeler flags any dependency—direct or transitive—that violates the license policy. This gives developers and security teams immediate visibility into license risk across the codebase.
You can use the Global Dependency view to identify dependencies violating the license policy.
Within a repository or service view, you can view the license of a dependency.
Prevent Dependencies with an Unapproved License
Use the Unapproved License guardrail to automatically prevent risky licenses from being introduced. This guardrail can block pull requests that attempt to add any dependency (direct or transitive) that violates your policy—stopping issues before they reach production.