aman99dex/Obligo

Deployment-context-aware license compliance scan — fails the build on license obligations your deployment context actually triggers.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 9, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: aman99dex/obligo@b8d91e9b65c6e9b9c51881fbde4261de007802ae # v0.5.1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathDirectory to scan.
context-filePath to context.yaml describing how you deploycontext.yaml
fail-onFindings at or above this severity fail the job: critical|warning|unknown|info|nevercritical
strictAlso fail (exit 2) when any scanner was skipped or degradedfalse
formatOutput format: terminal|json|cyclonedx|sarifterminal
outputFile to write the report to (required for sarif upload)""
versionObligo version to install (PyPI requirement spec)obligo

no outputs