Generated: 2026-09-04T01:42:06.068Z
Intended license for the open WAVE surface: Apache-2.0 — per wave-av/cli@5da8018 ("chore: adopt Apache-2.0 license + add NOTICE"): Standardize the open WAVE protocol/SDK surface on Apache-2.0 (patent grant for adoption). Replaces any prior license; adds NOTICE reserving the WAVE marks.
declared is the identifier in the published artifact's own metadata. ships is the license whose TEXT is in the file inside that artifact. source declares is what the manifest on the source repository's default branch says today. All three must agree; any disagreement is drift, and the last pair is the one an artifact cannot self-report.
| package | registry | version | declared | ships | source declares | NOTICE | verdict |
|---|---|---|---|---|---|---|---|
@wave-av/cli |
npm | 1.0.8 | MIT |
MIT |
MIT |
no | DRIFT — source manifest says "MIT" but LICENSE is the Apache-2.0 text |
@wave-av/sdk |
npm | 2.1.3 | Apache-2.0 |
Apache-2.0 |
Apache-2.0 |
no | consistent |
@wave-av/adk |
npm | 1.0.15 | Apache-2.0 |
Apache-2.0 |
Apache-2.0 |
no | consistent |
@wave-av/mcp-server |
npm | 0.2.0 | Apache-2.0 |
Apache-2.0 |
Apache-2.0 |
no | consistent |
@wave-av/workflow-sdk |
npm | 1.0.6 | MIT |
MIT |
Apache-2.0 |
no | DRIFT — published as "MIT" but source declares "Apache-2.0"; source manifest says "Apache-2.0" but sdk-typescript/packages/workflow-sdk/LICENSE is the MIT text |
@wave-av/create-app |
npm | 1.0.9 | MIT |
MIT |
unresolved | no | unverified — artifact self-consistent; source unresolved (UNVERIFIED — no package.json found on any wave-av default branch) |
wave-sdk |
pypi | 2.0.0 | MIT |
MIT |
MIT |
no | DRIFT — source manifest says "MIT" but LICENSE is the Apache-2.0 text |
wave-av-sdk |
pypi | 2.0.0 | MIT |
MIT |
Apache-2.0 |
no | DRIFT — published as "MIT" but source declares "Apache-2.0"; source manifest says "Apache-2.0" but sdk-python/LICENSE is the MIT text |
| package | source of truth | LICENSE file in that repo |
|---|---|---|
@wave-av/cli |
wave-av/cli:package.json | LICENSE is Apache-2.0 |
@wave-av/sdk |
wave-av/sdk:package.json | LICENSE is Apache-2.0 |
@wave-av/adk |
wave-av/adk:package.json | LICENSE is Apache-2.0 |
@wave-av/mcp-server |
wave-av/mcp-server:package.json | LICENSE is Apache-2.0 |
@wave-av/workflow-sdk |
wave-av/sdks:sdk-typescript/packages/workflow-sdk/package.json | sdk-typescript/packages/workflow-sdk/LICENSE is MIT |
@wave-av/create-app |
UNVERIFIED — no package.json found on any wave-av default branch | unresolved: UNVERIFIED — no package.json found on any wave-av default branch |
wave-sdk |
wave-av/sdk-python:pyproject.toml | LICENSE is Apache-2.0 |
wave-av-sdk |
wave-av/sdks:sdk-python/pyproject.toml | sdk-python/LICENSE is MIT |
- package:
@wave-av/cli@1.0.9 package.jsondeclares:Apache-2.0LICENSEfile text is:Apache-2.0README.mdLicense section:Apache-2.0package-lock.jsonroot:Apache-2.0NOTICEpresent in repo: yes- offline gate: clean
Strong copyleft (GPL/AGPL/SSPL/EUPL/CC-BY-SA) in a runtime dependency fails the gate. Weak, file-level copyleft (MPL/LGPL/EPL/CDDL) is listed here but does not block.
| scope | total | permissive | weak copyleft | strong copyleft | unknown |
|---|---|---|---|---|---|
| runtime | 127 | 127 | 0 | 0 | 0 |
| dev | 235 | 223 | 12 | 0 | 0 |
Notable (non-permissive) dependencies:
| dependency | license | class |
|---|---|---|
lightningcss@1.33.0 |
MPL-2.0 |
weak |
lightningcss-android-arm64@1.33.0 |
MPL-2.0 |
weak |
lightningcss-darwin-arm64@1.33.0 |
MPL-2.0 |
weak |
lightningcss-darwin-x64@1.33.0 |
MPL-2.0 |
weak |
lightningcss-freebsd-x64@1.33.0 |
MPL-2.0 |
weak |
lightningcss-linux-arm-gnueabihf@1.33.0 |
MPL-2.0 |
weak |
lightningcss-linux-arm64-gnu@1.33.0 |
MPL-2.0 |
weak |
lightningcss-linux-arm64-musl@1.33.0 |
MPL-2.0 |
weak |
lightningcss-linux-x64-gnu@1.33.0 |
MPL-2.0 |
weak |
lightningcss-linux-x64-musl@1.33.0 |
MPL-2.0 |
weak |
lightningcss-win32-arm64-msvc@1.33.0 |
MPL-2.0 |
weak |
lightningcss-win32-x64-msvc@1.33.0 |
MPL-2.0 |
weak |