# Install licensefinder with Homebrew, Nix

Find licenses for your project's dependencies. Version 7.2.1 via Homebrew; verified 2026-06-22. Also installable with nix: nix profile install nixpkgs#license_finder.

## Install

```sh
sudo av install brew:licensefinder
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install licensefinder
```

  Evidence: local Homebrew formula metadata

### Linux

- Nix (92%):

```sh
nix profile install nixpkgs#license_finder
```

  Evidence: nixpkgs package indexes: pkgs/by-name/li/license_finder/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:licensefinder
- **Package manager:** Homebrew
- **Version:** 7.2.1
- **Source summary:** Find licenses for your project's dependencies
- **Homepage:** <https://github.com/pivotal/LicenseFinder>
- **Repository:** <https://github.com/pivotal/LicenseFinder>
- **Last updated:** 2026-06-22T14:05:10-07:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- license_finder (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 7.2.1
## Project history and usage

LicenseFinder is Pivotal's long-running Ruby CLI for finding dependency licenses, comparing them with approved policies, and reporting unapproved packages. It covers many project types by calling their native package managers rather than treating license scanning as a single-language problem.

### Project history

The public repository was created on 2011-01-17. The README describes a tool that works with package managers to find dependencies, detect licenses, compare them with permitted licenses, and produce actionable exception reports.

The changelog records a broadening scope over time: support for Ruby, Node, Python, Java, Go, CocoaPods, Swift Package Manager, Rust Cargo, PHP Composer, Conda, Flutter, and other ecosystems appears across releases. Release 7.0.0 in 2022 added Ruby 3 support, Flutter scanning, and SPDX identifier reporting.

### Adoption history

LicenseFinder spread through CLI, RubyGems, Homebrew, Docker, and pre-commit workflows. Its Docker image bundles package managers so CI jobs can scan mixed-language repositories without installing every ecosystem tool on the host.

### How it is used

Users run license_finder after installing project dependencies. The tool records approvals and permitted licenses, exits non-zero for unapproved dependencies, and can run in CI to catch new dependency-license work items.

### Why package nerds care

LicenseFinder is important to package people because it exposes the practical mess of license metadata: every package manager has different files, commands, and metadata conventions, so the tool's value is in its adapters and decision record as much as in license detection.

### Timeline

- 2011-01-17: GitHub repository created.
- 2021-06-25: v6.14.1 changelog entry includes a command-injection fix for CocoaPods projects.
- 2022-03-04: v7.0.0 adds Ruby 3 support, Flutter scanning, and SPDX identifier reporting.
- 2022-11-28: v7.1.0 adds a pre-commit hook.
- 2024-05-07: v7.2.0 adds Ruby 3.3 support and several package-manager compatibility updates.

### Related projects

- Related projects include package-manager license commands, SPDX identifiers, pre-commit, and license-policy tools such as Licensed.

### Sources

- <https://api.github.com/repos/pivotal/LicenseFinder>
- <https://formulae.brew.sh/formula/licensefinder>
- <https://github.com/pivotal/LicenseFinder>
- <https://raw.githubusercontent.com/pivotal/LicenseFinder/master/CHANGELOG.md>
- <https://raw.githubusercontent.com/pivotal/LicenseFinder/master/README.md>


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config/license_finder.yml, doc/dependency_decisions.yml
## Other Package-Manager Records

- Nix - license_finder: installed executable or alias match | nixpkgs package indexes: pkgs/by-name/li/license_finder/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1


## Combined YAML source

View the package source record on GitHub. [combined/licensefinder.yml](https://github.com/mxcl/pkgdb/blob/main/combined/licensefinder.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
