ENGINEERING
Block PRs that introduce copyleft or forbidden licenses
On every pull request, diffs the lockfile for newly added dependencies, resolves each package's license.
How it runs
The automated pipeline, trigger to output.
- TriggerPull request opened or updatedGitHub
- ActionFetch lockfile diff and parse newly added packagesGitHub
- ActionResolve SPDX license for each new packageHTTP webhook
- LogicMatch licenses against forbidden/copyleft policy list
- OutputSet GitHub commit status and comment violations on PRGitHub
What it does
Acts as a required PR gate. When a pull request changes the lockfile, it isolates only the newly added dependency entries, looks up each package's declared license, and compares them against your policy list (e.g. GPL-3.0, AGPL-3.0, SSPL, or anything unrecognized). If a violation is found it posts a failing commit status that blocks merge until resolved.
When to use it
Use it when you want license compliance enforced automatically at merge time rather than caught in a quarterly audit. Ideal for teams shipping proprietary software who must avoid copyleft contamination but don't want to hand-review every dependency bump.
How it works
- 1A pull request opened or synchronized fires the trigger.
- 2The flow fetches the lockfile diff and parses only the added package entries.
- 3For each new package it resolves the SPDX license from the registry metadata.
- 4A policy check compares each license against the forbidden and copyleft lists.
- 5If clean, it sets a passing GitHub commit status; if violations exist, it posts a failing status plus a PR comment naming each offending package and license.
Set it up
What you configure once, before turning it on.
- 1Connect GitHubRepos, issues, pull requests, actions.
- 2Connect HTTP webhookTrigger any URL on agent actions.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
