name: License Check (Node) on: pull_request: branches: [main] paths: - 'osprey_ui/package.json' - 'osprey_ui/pnpm-lock.yaml' - '.github/allowed-licenses.txt' permissions: contents: read jobs: check: runs-on: ubuntu-24.04 steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 with: persist-credentials: false - run: corepack enable pnpm - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: node-version: "22" - name: Format license list run: | SPDX=$(tr '\n' ';' < .github/allowed-licenses.txt | sed 's/;$//') # highcharts uses a custom proprietary license; allowed for now pending #319 echo "ALLOWED_LICENSES=${SPDX};Custom: https://www.npmjs.com/package/highcharts-export-server" >> "$GITHUB_ENV" - name: Install dependencies working-directory: osprey_ui run: pnpm install --prod --frozen-lockfile --ignore-scripts - name: Check licenses working-directory: osprey_ui run: pnpm dlx license-checker@25.0.1 --production --excludePrivatePackages --onlyAllow "$ALLOWED_LICENSES"