Check the dependencies of a project (direct and transitive - CMake packages, pkg-config, FetchContent, submodules, vendored code, prebuilt binaries, includes, pip/npm/cargo) for their licenses - what must be credited, copyleft constraints, non-commercial / source-available / paid / proprietary terms, dependencies without license or of unknown origin - generate the third-party notices, and check their known vulnerabilities / compromised versions; result delivered as a PDF report.