Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Nifty Licenses: Dependency License Checker & SBOMNew to Visual Studio Code? Get it now.
Nifty Licenses: Dependency License Checker & SBOM

Nifty Licenses: Dependency License Checker & SBOM

Nifty

| (0) | Free
See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Nifty Licenses

See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices.

Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.

Features

The license issues in the status bar clicked: the Licenses view groups dependencies by risk, and the AGPL and unknown licenses show up as problems in package.json

The Licenses view with an AGPL and an unknown license flagged, and the same problems on their lines in package.json

A CycloneDX 1.5 SBOM exported for the project

  • Know what you ship. The Licenses view in the Explorer lists every dependency, direct and transitive, grouped by risk: network copyleft (AGPL, SSPL), copyleft (GPL), weak copyleft (LGPL, MPL), permissive (MIT, Apache, BSD), public domain and unknown.
  • All the usual lockfiles: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt (pinned), poetry.lock, uv.lock, Cargo.lock, go.sum, packages.lock.json (NuGet) and composer.lock, including monorepos with several of them.
  • Accurate licenses. Read from installed packages and lockfiles first, then looked up on deps.dev (only package names and versions are sent; turn it off with nifty.licenses.online). Results are cached. Messy strings like "Apache 2.0" or "MIT/Apache-2.0" are cleaned up into SPDX.
  • Your policy, enforced. Deny licenses by SPDX id (AGPL-3.0-only), wildcard (GPL-*) or category (copyleft), or allow only a list. Dual licenses are handled properly: MIT OR GPL-3.0 passes because you can choose MIT. Problems appear on the dependency's line in package.json, pyproject.toml, Cargo.toml, go.mod or composer.json, and as a count in the status bar.
  • Export a CSV of every dependency, its license and category.
  • SBOM export in CycloneDX 1.5 or SPDX 2.3 JSON, with package URLs, for security reviews, customers and the EU Cyber Resilience Act.
  • Third-party notices: a THIRD_PARTY_NOTICES.md listing the packages you ship, grouped by license.

Example policies

// Flag GPL-family licenses too, not only AGPL:
"nifty.licenses.deny": ["copyleft", "network-copyleft"]

// Or allow only a known list:
"nifty.licenses.allow": ["MIT", "ISC", "Apache-*", "BSD-*", "0BSD", "Unlicense"]

Commands

Command What it does
Nifty Licenses: Check Dependency Licenses Scan again (it also rescans when lockfiles change)
Nifty Licenses: Export License List (CSV)… Every dependency and its license
Nifty Licenses: Export SBOM (CycloneDX / SPDX)… CycloneDX 1.5 or SPDX 2.3 JSON
Nifty Licenses: Export Third-Party Notices… A THIRD_PARTY_NOTICES.md grouped by license
Nifty Licenses: Forget Cached Licenses and Recheck Clear the cache

Settings

Setting Default What it does
nifty.licenses.deny ["network-copyleft"] Licenses or categories to flag
nifty.licenses.allow [] If set, flag anything not on this list
nifty.licenses.flagUnknown true Flag dependencies without license information
nifty.licenses.includeDev false Include development dependencies
nifty.licenses.online true Look up missing licenses on deps.dev
nifty.licenses.showInStatusBar true Show the issue count

This is a tool, not legal advice. Check anything important with your lawyer.

Install

  • VS Code: search for "Nifty Licenses" in the Extensions view, or install from the Visual Studio Marketplace.
  • Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.

Privacy

This extension collects no telemetry and needs no account.

More Nifty tools

  • Nifty Code Metrics: Complexity & Hotspots: Complexity and size for every function in any language, as CodeLens and warnings, plus a hotspots view of the complex files that change most often. (Open VSX)
  • Nifty Node Search: Search Files in node_modules: Fuzzy-find and open files inside node_modules, jump to a package's README, and see installed versions. (Open VSX)
  • Nifty Pretty Errors: Readable Error Messages: Readable error messages for every language: TypeScript types formatted as code, long C++ and Rust types folded, and a docs link for every error code, in the hover and a side panel. (Open VSX)
  • Nifty Problems: Project-Wide TypeScript Errors: See TypeScript and ESLint errors for your whole project in the Problems panel, not just open files. (Open VSX)
  • Nifty Whitespace: Indent Rainbow, Invisible Characters & Trim: Indent rainbow, invisible and confusable characters with quick fixes, mixed line endings and tabs, and trimming trailing whitespace only on the lines you changed. (Open VSX)
  • Nifty XML: XPath, Formatter & XML to JSON: Evaluate XPath with namespaces, copy the XPath of any element, format, minify, check well-formedness and convert XML to JSON. (Open VSX)

See all 56 Nifty tools at https://getnifty.dev

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft