Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.
- Source URLs
- https://oss-review-toolkit.org/ort/docs/getting-started/usage, https://github.com/oss-review-toolkit/ort, https://oss-review-toolkit.org/ort/
- Brand
- OSS Review Toolkit
- Brand domain
- oss-review-toolkit.org
- Brand asset source
- manual
- Safety notes
- Runs after Write, Edit, and MultiEdit and inspects only the edited file path to decide whether a dependency manifest or lockfile changed., Install this project-relative command only in the trusted project's `.claude/settings.json`; user/global hooks must point to a trusted absolute path outside project directories., Default mode is advisory, prints the ORT command to run, and always exits 0 without reading dependency contents, creating reports, or contacting registries., When `ORT_LICENSE_HOOK_RUN=1` is set, it runs `ort analyze` in the project root and writes reports under `.claude/ort-license-checks/` by default., An opted-in ORT run may invoke package managers, inspect dependency graphs, read project configuration, fetch package metadata, and take several minutes on large repositories., Strict mode exits 2 only when `ORT_LICENSE_HOOK_STRICT=1` is also set and the opted-in ORT analysis fails.
- Privacy notes
- Default advisory mode prints only the changed dependency file path and the suggested local ORT command., Opted-in ORT runs can record dependency names, versions, package metadata, source URLs, license findings, project paths, package-manager output, and configuration details in local report files., Package managers or ORT integrations may contact configured package registries, VCS hosts, or metadata services during analysis., Review generated reports before sharing them because internal package names, private registry hostnames, source URLs, and license-policy exceptions can be sensitive.
- Author
- OSS Review Toolkit
- Submitted by
- oktofeesh1
- Claim status
- unclaimed
- Last verified
- 2026-06-04