The release gate for creative assets. CreditsDue proves which images, audio, fonts, videos, 3D models, and design sources are in a project, where they came from, what rights were declared, which obligations still apply, and whether the actual bytes changed after review.
It is a zero-dependency CLI, JavaScript library, and GitHub Action. It runs locally, never uploads assets, never guesses a license, and never calls a remote AI or registry.
中文说明 · Manifest reference · Repair playbook · Research
Software dependencies have SBOMs and mature scanners. Creative assets are still commonly tracked in a spreadsheet, a text file, or memory. That breaks down when:
- one pack covers many files, or the same bytes appear under different names;
- a marketplace page or license changes after download;
- an attribution-required texture reaches a release without its credit line;
- a no-redistribution asset is accidentally committed to a public repository;
- a modified asset loses the note required by its license;
- a teammate replaces a reviewed file but keeps the old documentation.
CreditsDue treats supplied evidence as evidence. It does not infer permission from pixels, metadata, a filename, or a model. This boundary keeps the result auditable and avoids false legal confidence.
Given a project root and creditsdue.json, CreditsDue:
- walks declared asset roots without following symbolic links;
- recognizes common creative formats and verifies signatures where practical;
- hashes every supported asset with SHA-256;
- maps each file to exactly one rights entry;
- validates creator, source, SPDX or
LicenseRef-*, obligations, attribution, modification notes, restrictions, license files, and local evidence; - detects stale globs, untracked files, ambiguous matches, oversized assets, disguised formats, duplicate bytes with conflicting rights, and public redistribution conflicts;
- compares the reviewed result with
creditsdue.lock.json; - emits release-ready credits, an audit report, a CycloneDX 1.6 asset BOM, and a deterministic evidence ZIP.
The committed example is not a screenshot shell:
$ node bin/creditsdue.mjs audit examples/moonbase-echo
CreditsDue 0.1.0 - Moonbase Echo
Assets 4/4 tracked | Entries 4 | Evidence 6
Errors 0 | Warnings 0 | Info 0
Result: PASS
Add an undocumented SVG and the same command exits 1, naming both the
untracked-asset and lock-new-asset failures with repair instructions.
Requirements: Node.js 20 or newer. There are no runtime dependencies.
From the GitHub Release:
npm install --global https://github.com/KanadeK/creditsdue/releases/download/v0.1.0/creditsdue-v0.1.0.tgz
creditsdue --versionFrom source:
git clone https://github.com/KanadeK/creditsdue.git
cd creditsdue
node bin/creditsdue.mjs audit examples/moonbase-echoNo install is needed for repository development.
creditsdue init . --asset-roots assets,publicinit scans real files and creates one deliberately failing review entry per
asset. Resolve every TODO, replace LicenseRef-TODO, record obligations, and
attach local evidence. CreditsDue will not turn an unknown asset green.
A compact entry looks like this:
{
"id": "orbit-dust-noise",
"files": ["assets/textures/noise.png"],
"origin": "third-party",
"creator": "Orbit Dust Studio",
"source": "https://example.com/orbit-dust/noise",
"license": "CC-BY-4.0",
"license_file": "licenses/CC-BY-4.0.txt",
"attribution": "Noise texture by Orbit Dust Studio, CC BY 4.0.",
"obligations": ["credit", "include-license"],
"modified": false,
"evidence_files": ["evidence/orbit-dust-receipt.html"]
}See the complete manifest contract and the machine-readable JSON Schema.
| Command | What it does | Writes files |
|---|---|---|
creditsdue init [root] |
Discovers assets and creates review placeholders | creditsdue.json |
creditsdue audit [root] |
Runs the full evidence and lock audit | only with --output |
creditsdue lock [root] |
Reviews current hashes into a deterministic lock | creditsdue.lock.json |
creditsdue credits [root] |
Generates all human and machine reports after a pass | dist/credits/* |
creditsdue evidence [root] |
Builds a deterministic, checksum-addressed evidence ZIP | dist/creditsdue-evidence.zip |
creditsdue explain <asset> [root] |
Shows the exact entry and findings for one file | no |
Useful options:
--manifest <path> custom manifest inside the project
--lock-file <path> custom lock inside the project
--format text|json console or machine-readable audit
--fail-on-warning promote warnings to a failing verdict
--no-lock inspect current evidence without lock verification
Exit codes are stable: 0 passed, 1 audit/policy failure, 2 bad usage or
manifest, and 3 file-system failure.
After creditsdue credits, the output directory contains:
audit.json— complete findings, assets, hashes, entries, and policy;CREDITS.md— human-readable credits ready for a game, site, or handoff;credits.json— compact runtime-friendly credit data;asset-bom.cdx.json— CycloneDX 1.6filecomponents with SHA-256, declared license expressions, origin, obligations, and references;report.html— a responsive, self-contained report with no JavaScript.
The evidence ZIP adds the source manifest, lock, local license/evidence files,
ASSET_SHA256SUMS, SHA256SUMS, and a bundle manifest. It intentionally omits
raw creative assets, so building evidence does not silently redistribute a
restricted file.
name: Creative asset rights
on: [push, pull_request]
jobs:
creditsdue:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: KanadeK/creditsdue@v0.1.0
with:
root: .
manifest: creditsdue.json
fail-on-warning: "true"The Action runs the repository's checked-in CLI with Node 20 and preserves its exit codes. It does not send assets to this repository or any service.
Built-in families include PNG/JPEG/GIF/WebP/AVIF/SVG/HDR textures; WAV/MP3/
Ogg/FLAC/AAC/MIDI audio; TTF/OTF/WOFF fonts; MP4/MOV/WebM/MKV video; glTF/GLB/
OBJ/FBX/DAE/Blend/STL models; and PSD/AI/Krita/Aseprite/XCF design sources.
Project-specific extensions can be declared with custom_extensions.
CreditsDue scans only configured asset_roots; it is not a dependency or source
code license scanner. Use REUSE or a software
composition analysis tool for source dependencies.
Every command below is offline after cloning:
node scripts/quality.mjs
node --test --experimental-test-coverage \
--test-coverage-lines=85 \
--test-coverage-functions=85 \
--test-coverage-branches=75
node scripts/build-examples.mjs
node bin/creditsdue.mjs audit examples/moonbase-echo
node scripts/release-gate.mjsThe release gate:
- checks syntax, JSON, local links, secrets, and version synchronization;
- runs behavior and failure-path tests with coverage thresholds;
- builds examples twice more than one second apart and compares bytes;
- packages twice more than one second apart and compares every artifact hash;
- verifies
SHA256SUMS; - installs the release tarball offline in a clean temporary prefix;
- proves the installed CLI passes the good fixture and rejects a broken copy;
- checks commit authors and rejects
Co-authored-by.
If something fails, use the repair playbook. It maps each failure family to a bounded diagnosis, repair, and recheck command.
- This is evidence and release tooling, not legal advice.
- A valid manifest proves internal consistency, not that a supplier owned the rights they claimed.
- CreditsDue never downloads license pages. Preserve a local grant, receipt, license file, or source snapshot when you acquire an asset.
- SPDX syntax validation confirms expression structure. It does not reinterpret custom marketplace terms.
- Symlinks are skipped to prevent evidence from escaping the project root.
Read the security model before using untrusted repositories.
Bug reports and focused adapters are welcome. Start with CONTRIBUTING.md, preserve the no-network runtime boundary, and add a failing fixture before a parser or policy repair.
CreditsDue is released under the MIT License.