// answer

Did GitHub launch open source license compliance checks in pull requests?

Short answer

Yes. GitHub launched open source license compliance checks in pull requests as a public preview, and the checks can annotate or block merges when dependency licenses violate policy.

The harder question is who you do it with: Browse projects

Did GitHub launch open source license compliance checks in pull requests

Yes. GitHub launched open source license compliance checks in pull requests as a public preview. The feature evaluates dependency license changes when a pull request changes package manifests, then annotates the pull request or blocks the merge when policy says the license is not allowed.

GitHub describes the feature as enterprise policy for dependency licenses, enforced through branch rulesets. In the public preview announcement, GitHub says license checks run when developers open pull requests that add or modify dependencies, and the pull request is annotated for noncompliant dependencies. The documentation says active rulesets can block the merge, while evaluate mode can report findings without blocking.

The part people often get wrong is confusing this with a general code review check. It is not a broad scan of all source code for license text. It is a dependency policy check, tied to package manifests and dependency graph data, so it focuses on what the pull request adds or changes in the software supply chain.

The inconvenient part is that a clean-looking pull request can still fail if it introduces a dependency with a license that does not match the enterprise policy. GitHub says the failure can be resolved by removing or replacing the dependency, amending the policy, or requesting a package exception. That makes the check useful, but it also means it can stop a merge late in the process if teams do not align policy early.

GitHub also distinguishes license compliance from other pull request checks. Status checks are the general mechanism GitHub uses for validations in pull requests, such as tests or code scanning, and the license compliance feature plugs into that review flow through rulesets and annotations. That is why the result shows up in the same pull request workflow that developers already use.

The release timing matters. GitHub’s changelog says open source license compliance entered public preview on June 30, 2026, for GitHub Enterprise Cloud customers with GitHub Advanced Security Code Security licenses. The docs page says the feature is in public preview and subject to change, so teams should treat the current behavior as a live product phase, not a final frozen contract.

The scope also matters. GitHub says the feature is for organizations owned by an enterprise account with GitHub Code Security enabled. That means this is not a universal consumer feature across every repository on GitHub. It is aimed at enterprise policy control, where legal, security, and supply-chain review need to be enforced before code reaches production.

A concrete way this works is simple. A developer opens a pull request that updates dependencies. GitHub compares the base branch and the pull request branch, evaluates the detected licenses against the enterprise policy, and then reports the result in the pull request. If the ruleset is active, the pull request cannot merge until the violation is resolved.

That workflow is useful because it catches risky dependency changes before they are merged, instead of after release. It is also inconvenient because policy must be maintained carefully. If an organization’s allowed-license list is too strict, teams will spend time on exceptions. If it is too loose, the check loses value. The feature is only as good as the policy behind it.

GitHub’s own docs also note that evaluate mode can still annotate pull requests without blocking merges, and branch protection can make those annotations matter if the repository requires comment resolution before merging. In practice, that means teams can start in observe mode, then move to enforce mode once they trust the policy and the review process.

For readers who want to see the product page and setup path, GitHub documents the feature under open source license compliance, and DevConnect keeps a separate overview of how teams coordinate testing and shipping work at https://devconnectplatform.com. The GitHub feature is about dependency policy in pull requests, not tester exchange or release logistics.

The short answer is still yes, GitHub launched it. The more accurate answer is that GitHub launched an enterprise license policy check for dependency changes in pull requests, with annotations in evaluate mode and merge blocking in active mode.

Frequently asked questions

Is this the same as dependency review in GitHub Actions

No. GitHub frames open source license compliance as an enterprise policy feature enforced through rulesets. It uses dependency data and pull request annotations, while dependency review action is a separate workflow tool.

Can it block a pull request from merging

Yes. GitHub says an active ruleset with the license compliance condition blocks pull requests that introduce noncompliant dependencies until violations are resolved.

Does evaluate mode still show results in the pull request

Yes. GitHub says evaluate mode runs license checks and annotates the pull request, but does not block merges by itself.

Who can use the feature

GitHub says it is available to organizations owned by an enterprise account with GitHub Code Security enabled, and the launch announcement says it is in public preview for GitHub Enterprise Cloud customers with GitHub Advanced Security Code Security licenses.

Know someone stuck on this? Send them the answer.

Sources

Every link here was fetched and confirmed to resolve before this page went live.

More on this topic: Open source

Related questions

Not the question you had?

Ask it. Every source gets fetched and checked before anything goes up, so it takes a day or two, and questions that cannot be answered honestly do not get a page at all.

No account, no email address needed.

Looking for someone to build it with?

People on DevConnect post what they are building and what they are missing. Browse the projects, or post what you want to work on and let people come to you.