Getting started with init
Adopting PackageGuard usually starts with an empty configuration file and a question you can't answer yet:
which licenses should you allow? The init command scans your repository first, so the question comes with
an answer already in front of you: here's what's actually here, and here's a policy that fits it.
packageguard init <path-to-solution-file-or-project>
This scans the repository just like a normal run, then prints a breakdown of every license in use, with copyleft licenses flagged:
Scanning MyProduct...
Found 247 packages across 12 projects.
Licenses in use:
MIT 184 packages
Apache-2.0 41 packages
BSD-3-Clause 9 packages
MS-PL 7 packages
LGPL-2.1-only 4 packages <- weak copyleft
GPL-3.0-only 2 packages <- strong copyleft
(unknown) 1 package <- SomeObscurePackage 1.2.0
It then asks what kind of software this is, since that decides how much copyleft exposure is reasonable to allow:
- Proprietary / commercial - suggests a permissive-only policy (MIT, Apache-2.0, BSD, and similar).
- SaaS / hosted - suggests permissive plus weak copyleft (LGPL, MPL), but excludes GPL and AGPL, since AGPL's obligations are specifically triggered by offering software as a network service.
- Open source - suggests allowing every copyleft category, since an open-source project is typically already compatible with them.
The answer only decides which of the licenses found in the scan end up in the generated allow list -
init never invents a policy that allows a license your dependencies don't actually use, and it never
allows everything present just to guarantee a clean first run. If a copyleft license doesn't fit the chosen
profile, it's left out, and the packages using it show up as violations you can act on:
Written .packageguard/config.json
2 packages violate the suggested policy. Run `packageguard .` to see them.
Warnings for tolerated copyleft
Copyleft licenses that the chosen profile tolerates (for example LGPL for SaaS software) are allowed, but
init also lists them in a warn section. They
never fail the build, but they show up as warnings so the obligations stay visible. When some packages
violate the suggested policy, init also reminds you that --treat-deny-as-warning lets you adopt the
policy gradually, reporting violations without failing the build yet.
Risk gates
Optionally, init can also add risk-based deny rules
to the generated file. You are asked about it interactively, or you can pass --risk-gates:
"deny": {
"maxOverallRisk": 60,
"maxSecurityRisk": 7,
"maxOsvSeverityScore": 7.0,
"denyDeprecated": true,
"minPackageAgeDays": { "npm": 14, "nuget": 3 }
}
This is off by default, because gating on risk makes every run slower: PackageGuard has to collect risk
data for each package, which works best with a GitHub API key. init itself doesn't collect risk data, so
these rules are only evaluated by your next packageguard . run. The file also contains a commented-out
riskExceptions example, for packages whose risk you have decided to accept.
Non-interactive use
For scripted setup, CI, or project templates, skip the question with --preset:
packageguard init --preset permissive-only
The available presets are permissive-only, no-network-copyleft, and oss-friendly, matching the three
questions above.
Options
--config-path <path>- where to write the generated file. Defaults to.packageguard/config.jsonnext to the solution (or the resolved project directory when no solution is found).--risk-gates- also add the risk-baseddenyrules described above. Without it,--presetskips the question and leaves them out.--overwrite- overwrite a configuration file that already exists at that path. Without it,initrefuses to run rather than silently replacing your policy.--npm,--npm-path,--npm-exe-path,--nuget,-i/-f/-s- the same project-discovery and restore optionsanalyzesupports, sinceinitscans the repository the same way.
The generated file is a normal configuration file - a settings.allow.licenses list
with a comment explaining the chosen preset and what copyleft means for it. Edit it like any other
PackageGuard configuration from there.