ENGINEERING

Block PRs that add incompatible Hugging Face model licenses

When a pull request adds or bumps a Hugging Face model dependency, it fetches the model card license, checks it against your org's allowed-license policy.

CategoryEngineering
Enginesim
Difficultyintermediate
Triggerevent
Steps5
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerPull request opened or updatedGitHubGitHub
  • ActionExtract added HF model IDs from diffGitHubGitHub
  • ActionFetch model card license for each modelHugging FaceHugging Face
  • LogicCompare licenses against org allowlist
  • OutputPost pass/fail GitHub status checkGitHubGitHub

What it does

Guards your repository against silently pulling in Hugging Face models whose licenses your legal policy forbids (for example a research-only or non-commercial license slipping into a commercial product). It runs on every pull request, identifies newly referenced model repos, resolves each one's license from its model card, and turns that into a required GitHub status check.

When to use it

Use it on any repo where engineers add `model_id` references, `from_pretrained` calls, or HF entries to a manifest, and where shipping a wrong-licensed model is a real legal risk. It is the enforcement layer that makes "check the license first" automatic instead of tribal knowledge.

How it works

  1. 1A GitHub pull request event fires the workflow.
  2. 2The diff is scanned to extract any added or changed Hugging Face model repo IDs.
  3. 3For each model ID, the Hugging Face API returns the model card metadata including the declared license tag.
  4. 4A logic step compares every license against your allowlist (for example apache-2.0, mit, bsd) and flags anything outside it.
  5. 5The workflow posts a GitHub commit status: green when all licenses pass, red with the offending model and license named when any fail, blocking merge until resolved.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect GitHubRepos, issues, pull requests, actions.
  2. 2
    Connect Hugging FaceModels, datasets, spaces — the open-source hub.
  3. 3
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  4. 4
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  5. 5
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.