Skip to main content
SourceTrustSign in

Help center

Guides for SourceTrust: Importing dependencies, reviewing licenses, external obligations, publishing attestation pages, billing, plain-language license explainers, and procurement-oriented explainers for common open-source licenses.

Why was this package not approved automatically?

← All articles

Every package that waits for a person says why in plain words. These are the reasons you can meet, what each one means, and what finishes it.

We approve a package for you only when we are sure. We found the license, we confirmed that its text carries the standard terms and nothing that changes them, and the license is one you chose for automatic approval. When one of those is missing, the package waits for a person and says why. Open it and the message at the top gives you the reason, what to look at and the steps that finish it. These are the reasons you can meet.

Nothing is missing

  • Ready for your approval. Everything is in place and the last press is yours. It also reads this way when you changed the license or the text yourself, or when we could not confirm the package automatically and you finished it by hand.
  • The license is not on your list for automatic approval. The package is fine, the license is simply one you asked to see. The message says what that kind of license asks of you, and you can add it to your list in the project settings.
  • One step is left for your team. The license asks for something you do outside SourceTrust, so the step is yours to do and to tick off.

The license text is not the standard text

  • Only the form of the file is different. A heading over the copyright block, another name or year, a word dropped from a sentence that says the same thing: none of it changes what you may do, so we confirm the text and say nothing about it. Those packages are approved with the rest.
  • A few real things are different, and none of them adds a condition. We quote every place that differs and say what each one does, and we recommend approving the text if you agree. We never approve one of these for you: a real difference is worth one look from a person.
  • A difference adds a condition the standard text does not have. We say so in those words, quote the sentences and say what each one asks of you. If it is a condition you cannot meet, do not approve the package. Replace it or ask the publisher.
  • Some of it is different and we can point at the words. We quote what was added, what is missing and what was changed, so you can go straight to that place in the text. Read it, and approve the text if it does not change what you may do.
  • We found a text and could not confirm it. Read it before you rely on it, then approve it or paste the right one.
  • The license is filled in by the publisher. Some licenses name the publisher, a date and what you may not do, and those parts differ from package to package. We never approve one of them for you.
  • A NOTICE or PATENTS file sits next to the license. It can hold credits you must keep, or patent rights it gives or limits. Open the package and read it.

We could not settle which license it is

  • The publisher says one license and the license file says another. The file is what travels with the code, so we show the file's license. You can switch to the other one.
  • The only license file we found sits at the top of the source code and not inside the package. It may cover other code as well, so we pick nothing for you and offer no text.
  • The publisher lets you choose between two licenses. We picked the one whose text we found, and you keep it or choose the other one.
  • Several licenses apply at the same time. All of them apply, not just one, and the strictest one decides what you may do. Each of them needs its own text.
  • The publisher lists several licenses without saying whether you may choose, or states something too complex for us to settle. Check the project's own page for how it is licensed, then choose.
  • The license file is the publisher's own terms, or a license we do not have in our library yet. Read it, choose the license that fits or Other license, and approve only if your use is allowed.
  • The file we found is not a license text at all. Find the license on the package's page and paste it.

There is no text

  • The publisher states a license and this version comes without a text. If you trust the statement, accept it with one button and we record that no text was published. Or paste the text you agreed to.
  • We found no license at all. Without a license you have no stated right to use the package. Check its page, ask the publisher, or think about replacing it.
  • The license needs its text and we have none. You must be able to show the text to the people you pass the package on to, so find it and paste it.

It is one of your own

  • We could not find this version where it is published, and it looks like one of yours. If it is, mark it as internal and we remember that for your whole organization.
  • The package was not installed from the public package source. It comes straight from a git address, a folder or a link, and we never swap it for a package with the same name somewhere else.
  • The publisher marks the package as not licensed for others. That is normal for a company's own packages. If it belongs to someone else, you need their permission.

We could not check it

Sometimes the check itself does not get through: we tried several times and got no answer, the copy we downloaded was not the one your project recorded, the package is too large to read in full, there is no fixed version to check, we could not find this exact version where it is published, or we could not read all of its license files. We never turn that into a verdict, so the page says what stopped and offers you the way on: choose the license and paste the text from your installed copy. When only the answer was slow, we check the package again on our own and tell you that we are doing it.

A package you open while the import is still running says that we are still checking it. Nothing is wrong. Review other packages meanwhile, and come back when the check has finished.
See Help center → Reviewing a package (Reviewing a package), Bulk approve after import (Bulk approve after import), and Auto-fetch license text (Auto-fetch license text).