This document summarizes a study of license violations in the npm and RubyGems package dependency networks. The researchers analyzed over 750,000 npm packages and 95,000 RubyGems packages to determine: 1) the most prevalent licenses in each ecosystem, 2) the extent that direct dependencies rely on incompatible licenses, and 3) how license incompatibility spreads across indirect dependencies. They found that MIT and Apache licenses are most common, direct dependencies rarely have incompatible licenses, and GPL dependencies cause most indirect violations that decrease with deeper dependency levels.