Project-wide license scans, evidence paths, plain-language verdicts, fix guidance, CREDITS exports, SPDX and CycloneDX SBOMs, VEX, history, and an optional release gate.
What you get, how long it takes, and what you need.
About 2 minutes from importing the package to your first audit. Open the License Auditor window and scan; no setup asset is required.
Unity 2022.3 or newer for the editor scan. Local scanning needs no network; registry lookup is opt-in. The separate CI command-line scanner requires .NET 8.
Your whole dependency graph, not just the manifest.
Open Tools → ShipIt → License Auditor and click Scan Project. No configuration: the scanner reads your manifest, the PackageCache and Assets/ directly, sliced across editor frames so the window keeps painting on large projects.
Packages and code
- UPM — direct dependencies from
Packages/manifest.json, plus transitive and embedded packages. - Source headers —
SPDX-License-Identifiercomments inAssets/**.cs, one entry per license with a file count. - Manifests and lockfiles — every shape of npm
licensefield, yarn, Cargo and poetry lockfiles, and NuGet references resolved from your local cache. - SPDX expressions —
OR,AND,WITHexceptions and parentheses.
Assets and binaries
- License files — LICENSE, COPYING and NOTICE files in packages and under
Assets/, matched against canonical texts; a NOTICE bundle yields one entry per license. - Fonts — OFL and Apache hints plus the copyright line.
- Prebuilt binaries — vendor information from DLLs and native libraries.
- Asset Store content — a curated map for common packages such as DOTween, Mirror and FishNet; everything unmapped goes to the manual review queue.
Ship it, credit it, review it, replace it.
| Verdict | What it covers | What to do |
|---|---|---|
| OK | Permissive: MIT, Apache-2.0, BSD, ISC, Zlib, CC0 | Ship it |
| Attribution | Free to use commercially, but you must credit: CC-BY, SIL OFL fonts | Ship it after exporting CREDITS |
| Review | Weak copyleft (MPL-2.0, LGPL) or proprietary terms | Usually fine as a library; read the summary |
| Copyleft risk | Strong copyleft: GPL, AGPL, CC-BY-SA | Replace it in a closed-source game, or relicense |
| Non-commercial | CC-BY-NC variants | Hard stop for any commercial release |
| Proprietary | Custom vendor terms: Asset Store EULA, SEE LICENSE IN files | Read the evidence |
| Unknown | No machine-readable license found | Resolve it by hand or with Fetch |
Every verdict carries its evidence path, so you can open the file it came from. Cached verdicts go stale after a set number of days and block the release gate until re-confirmed.
The files your release and your publisher ask for.
CREDITS.md for humans and CREDITS.json for the game, with a runtime credits screen sample that builds its own UI.
Third-Party Notices.md and an HTML report of the whole inventory.
SPDX 2.3 and CycloneDX 1.4, plus a VEX sidecar that states which entries need action.
One zip with every artifact, a manifest of headline counts and SHA-256 hashes, for due-diligence requests.
Past scans with drift between runs, so a new dependency shows up as a change, not a surprise.
Default, Permissive only, Permissive + attribution and Strict. Templates are policy choices, not legal advice.
A release gate that fails for a reason.
Tools → ShipIt → License Auditor → Verify Release Readiness fails on non-commercial licenses, strong copyleft, unresolved unknowns, a missing CREDITS file, policy violations, project-license conflicts and stale cached resolutions.
In the build
Two opt-in switches on the settings asset: Write License Manifest On Build puts CREDITS, both SBOMs, the VEX sidecar and the raw report next to the build output, and Fail Build On Blocking Licenses runs the gate before the build. Both are off until you turn them on.
In batch mode
The same gate runs headless, so a CI machine with a Unity licence can call it on every build with the command below. The self-test entry point, LicenseAuditSelfTest.Run, runs a live scan, the exports and the gate in one pass.
Unity.exe -batchmode -nographics -quit -projectPath . \
-executeMethod ShipIt.LicenseAudit.EditorTools.LicenseReleaseReadiness.VerifyStrict
Two minutes from import to your first audit.
Open the window
Tools → ShipIt → License Auditor. Nothing to configure first.
Scan
Click Scan Project, then filter by verdict or search. Repeat scans reuse a fingerprint cache and only re-read changed files.
Fix what blocks
Open the Fix tab for Copyleft risk, Non-commercial and Unknown entries: obligations, remediation hints, and which build scenes actually ship each one.
Export credits
Export CREDITS.md and CREDITS.json from the Export tab and check both into version control.
Verify
Run Verify Release Readiness. Fix what it lists, then run it again until it is clean.
Show credits in game
Tools → ShipIt → License Auditor → Create Credits Demo Scene builds a working credits screen from your latest scan.
What has been run, and what has not.
| Round | Check | Result |
|---|---|---|
| v0.4.0 · Sep 30, 2026 | EditMode suite on Unity 2022.3.62f1 and 6000.3.11f1 | 156 / 156 passed on both |
| v0.4.0 · Sep 30, 2026 | PlayMode credits smoke test on both editors | 1 / 1 passed on both |
| v0.4.0 · Sep 30, 2026 | Headless self-test and release gate on Unity 6000.3.11f1 | Passed |
| v0.4.0 · Sep 30, 2026 | UPM package installed into a clean Unity 6000.3.11f1 project | Installed; self-test passed inside it |
| v0.4.0 · Sep 30, 2026 | CLI unit and contract tests, strict scan, MCP stdio smoke test | 29 / 29 passed; 0 blocking; all 7 tools answer |
| v0.4.0 | IL2CPP stripping proof and a scan benchmark | Not run yet |
What it does not do.
- It is not legal advice. Results are informational. Talk to a lawyer before you rely on a verdict for a release decision.
- Asset Store EULAs are not machine-readable. A curated map covers common packages; everything else lands in the manual review queue.
- Expressions are simplified.
ORpicks the least restrictive branch andANDthe most restrictive. Complex custom licenses always land in Review. - The Unity 6 global package-cache database is detected, never parsed. Audit the extracted packages instead.
- Fetch needs the network. Air-gapped scans still work, but unknowns stay unknown until you resolve them by hand.
- The standalone .NET command-line scanner is not in the package. It lives in the development repository; the package's CI path is the batch-mode gate above.
Before you rely on a scan.
Does a scan send project data over the network?
No. Scanning is local and deterministic. Looking up an unknown license is a separate Fetch action that you choose to run.
Does a verdict guarantee that a dependency is safe to ship?
No. Results are informational, not legal advice. Unknown and complex licenses stay visible for manual review.
Does the auditor run in my shipped game?
The scanner is editor-only. You can optionally include the exported CREDITS.json and attribution helper, or enable the build gate in project settings.
Do I need .NET to use the Unity window?
No. .NET 8 is only needed for the separate command-line scanner used in Unity-free CI.
Know what you are shipping before a store or a lawyer asks.
The Asset Store listing is not live yet. Ask about release timing or read the quick start.
Trademarks
SPDX, CycloneDX, GitHub, GitLab, Bitbucket, npm, PyPI, crates.io and NuGet are the property of their respective owners. This is an independent tool and is not affiliated with, endorsed by, or sponsored by any of them. "Unity" is a trademark of Unity Technologies.