Pre-release · v0.4.0 · Unity 2022.3 LTS

Know every license before you ship.

A shipped game carries hundreds of licenses nobody read. The Unity License Toolkit scans packages, assets, fonts and binaries, gives each one a plain-English verdict with its evidence, and exports the credits and notices your release needs. Informational only — not legal advice.

156 EditMode + 1 PlayMode tests passing at v0.4.0 on Unity 2022.3.62f1 and 6000.3.11f1 Verdicts come from a classifier pinned to the official SPDX corpus, not from an LLM The scan never needs the network; fetching a missing license is always a click you make Editor-only: nothing ships in your player unless you include CREDITS.json
CreditsLoader.cs
using ShipIt.LicenseAudit;

// CREDITS.json, exported by the auditor and
// placed in a Resources folder.
var json = Resources.Load<TextAsset>("CREDITS").text;
var credits = AttributionRegistry.FromJson(json);

foreach (var entry in credits.Entries)
    Debug.Log($"{entry.Name}: {entry.LicenseId}");

// Or drop the CreditsScreen component into a scene:
// it builds its own scrollable UI at runtime.
7plain-English verdicts, each with an evidence path
739SPDX license ids, with 699 canonical texts
0network calls in a scan
2022.3LTS minimum; runtime helper runs anywhere

What you get, how long it takes, and what you need.

What you get

Project-wide license scans, evidence paths, plain-language verdicts, fix guidance, CREDITS exports, SPDX and CycloneDX SBOMs, VEX, history, and an optional release gate.

Setup time

About 2 minutes from importing the package to your first audit. Open the License Auditor window and scan; no setup asset is required.

Unity & prerequisites

Unity 2022.3 or newer for the editor scan. Local scanning needs no network; registry lookup is opt-in. The separate CI command-line scanner requires .NET 8.

Read the License Auditor quick startBrowse FAQs

Your whole dependency graph, not just the manifest.

Open Tools → ShipIt → License Auditor and click Scan Project. No configuration: the scanner reads your manifest, the PackageCache and Assets/ directly, sliced across editor frames so the window keeps painting on large projects.

Packages and code

  • UPM — direct dependencies from Packages/manifest.json, plus transitive and embedded packages.
  • Source headers — SPDX-License-Identifier comments in Assets/**.cs, one entry per license with a file count.
  • Manifests and lockfiles — every shape of npm license field, yarn, Cargo and poetry lockfiles, and NuGet references resolved from your local cache.
  • SPDX expressions — OR, AND, WITH exceptions and parentheses.

Assets and binaries

  • License files — LICENSE, COPYING and NOTICE files in packages and under Assets/, matched against canonical texts; a NOTICE bundle yields one entry per license.
  • Fonts — OFL and Apache hints plus the copyright line.
  • Prebuilt binaries — vendor information from DLLs and native libraries.
  • Asset Store content — a curated map for common packages such as DOTween, Mirror and FishNet; everything unmapped goes to the manual review queue.
Unknown stays visible. When a license has no machine-readable source, the entry stays Unknown until you resolve it: the Fix tab can fetch it from GitHub, GitLab, Bitbucket, npm, PyPI, crates.io or NuGet, but only when you click Fetch.

Ship it, credit it, review it, replace it.

VerdictWhat it coversWhat to do
OKPermissive: MIT, Apache-2.0, BSD, ISC, Zlib, CC0Ship it
AttributionFree to use commercially, but you must credit: CC-BY, SIL OFL fontsShip it after exporting CREDITS
ReviewWeak copyleft (MPL-2.0, LGPL) or proprietary termsUsually fine as a library; read the summary
Copyleft riskStrong copyleft: GPL, AGPL, CC-BY-SAReplace it in a closed-source game, or relicense
Non-commercialCC-BY-NC variantsHard stop for any commercial release
ProprietaryCustom vendor terms: Asset Store EULA, SEE LICENSE IN filesRead the evidence
UnknownNo machine-readable license foundResolve it by hand or with Fetch

Every verdict carries its evidence path, so you can open the file it came from. Cached verdicts go stale after a set number of days and block the release gate until re-confirmed.

The files your release and your publisher ask for.

Credits

CREDITS.md for humans and CREDITS.json for the game, with a runtime credits screen sample that builds its own UI.

Notices and report

Third-Party Notices.md and an HTML report of the whole inventory.

SBOMs

SPDX 2.3 and CycloneDX 1.4, plus a VEX sidecar that states which entries need action.

Evidence pack

One zip with every artifact, a manifest of headline counts and SHA-256 hashes, for due-diligence requests.

History

Past scans with drift between runs, so a new dependency shows up as a change, not a surprise.

Policy templates

Default, Permissive only, Permissive + attribution and Strict. Templates are policy choices, not legal advice.

A release gate that fails for a reason.

Tools → ShipIt → License Auditor → Verify Release Readiness fails on non-commercial licenses, strong copyleft, unresolved unknowns, a missing CREDITS file, policy violations, project-license conflicts and stale cached resolutions.

In the build

Two opt-in switches on the settings asset: Write License Manifest On Build puts CREDITS, both SBOMs, the VEX sidecar and the raw report next to the build output, and Fail Build On Blocking Licenses runs the gate before the build. Both are off until you turn them on.

In batch mode

The same gate runs headless, so a CI machine with a Unity licence can call it on every build with the command below. The self-test entry point, LicenseAuditSelfTest.Run, runs a live scan, the exports and the gate in one pass.

Unity.exe -batchmode -nographics -quit -projectPath . \
  -executeMethod ShipIt.LicenseAudit.EditorTools.LicenseReleaseReadiness.VerifyStrict
v0.4.0 adds a severity floor and a minimum quality score to the gate, and a Vetting tab that grades each entry Pass, Review or Block for publisher due diligence. Scores are triage heuristics: a score of 100 does not mean safe to ship.

Two minutes from import to your first audit.

01

Open the window

Tools → ShipIt → License Auditor. Nothing to configure first.

02

Scan

Click Scan Project, then filter by verdict or search. Repeat scans reuse a fingerprint cache and only re-read changed files.

03

Fix what blocks

Open the Fix tab for Copyleft risk, Non-commercial and Unknown entries: obligations, remediation hints, and which build scenes actually ship each one.

04

Export credits

Export CREDITS.md and CREDITS.json from the Export tab and check both into version control.

05

Verify

Run Verify Release Readiness. Fix what it lists, then run it again until it is clean.

06

Show credits in game

Tools → ShipIt → License Auditor → Create Credits Demo Scene builds a working credits screen from your latest scan.

What has been run, and what has not.

RoundCheckResult
v0.4.0 · Sep 30, 2026EditMode suite on Unity 2022.3.62f1 and 6000.3.11f1156 / 156 passed on both
v0.4.0 · Sep 30, 2026PlayMode credits smoke test on both editors1 / 1 passed on both
v0.4.0 · Sep 30, 2026Headless self-test and release gate on Unity 6000.3.11f1Passed
v0.4.0 · Sep 30, 2026UPM package installed into a clean Unity 6000.3.11f1 projectInstalled; self-test passed inside it
v0.4.0 · Sep 30, 2026CLI unit and contract tests, strict scan, MCP stdio smoke test29 / 29 passed; 0 blocking; all 7 tools answer
v0.4.0IL2CPP stripping proof and a scan benchmarkNot run yet
The feature list on this page describes v0.4.0, the version verified above. Verified on Windows only.

What it does not do.

  • It is not legal advice. Results are informational. Talk to a lawyer before you rely on a verdict for a release decision.
  • Asset Store EULAs are not machine-readable. A curated map covers common packages; everything else lands in the manual review queue.
  • Expressions are simplified. OR picks the least restrictive branch and AND the most restrictive. Complex custom licenses always land in Review.
  • The Unity 6 global package-cache database is detected, never parsed. Audit the extracted packages instead.
  • Fetch needs the network. Air-gapped scans still work, but unknowns stay unknown until you resolve them by hand.
  • The standalone .NET command-line scanner is not in the package. It lives in the development repository; the package's CI path is the batch-mode gate above.

Before you rely on a scan.

Does a scan send project data over the network?

No. Scanning is local and deterministic. Looking up an unknown license is a separate Fetch action that you choose to run.

Does a verdict guarantee that a dependency is safe to ship?

No. Results are informational, not legal advice. Unknown and complex licenses stay visible for manual review.

Does the auditor run in my shipped game?

The scanner is editor-only. You can optionally include the exported CREDITS.json and attribution helper, or enable the build gate in project settings.

Do I need .NET to use the Unity window?

No. .NET 8 is only needed for the separate command-line scanner used in Unity-free CI.

Pre-release

Know what you are shipping before a store or a lawyer asks.

The Asset Store listing is not live yet. Ask about release timing or read the quick start.

Trademarks

SPDX, CycloneDX, GitHub, GitLab, Bitbucket, npm, PyPI, crates.io and NuGet are the property of their respective owners. This is an independent tool and is not affiliated with, endorsed by, or sponsored by any of them. "Unity" is a trademark of Unity Technologies.