All screens
42 days

Dependency Inventory

Every third-party component Uploz runs on is open-source and self-hostable — the whole stack can run inside an operator's own infrastructure with no managed-SaaS lock-in. Each entry records its purpose, SPDX license and how it is deployed. 2 components carry a copyleft license flagged for legal review.

All dependencies

Sorted by name. Each entry names its license and how it is self-hosted.

Grafana

AGPL-3.0
ObservabilityCopyleft — review

Operator-facing dashboards for the metrics and traces that back the cockpit observability views.

Self-hosting

Self-hosted with provisioned dashboards; AGPL means UI changes must stay in-house or be shared — flagged for review.

MinIO

AGPL-3.0
Data & storageCopyleft — review

S3-compatible object storage for exported reports, replay bundles and signed-document artifacts.

Self-hosting

Used unmodified over its S3 API; AGPL obligations limited to network use — flagged for legal sign-off.

Next.js

MIT
FrontendPermissive

App-router framework for apps/web and apps/dev-admin — server components, routing and the build pipeline.

Self-hosting

Runs in standalone output mode behind the reverse proxy.

Node.js

MIT
Runtime & APIPermissive

JavaScript/TypeScript runtime for the Next.js app server, the worker process and the validation-engine CLI.

Self-hosting

Pinned LTS in the base container image; no external service.

OpenTelemetry

Apache-2.0
ObservabilityPermissive

Vendor-neutral tracing and metrics instrumentation across the app server, worker and engine.

Self-hosting

Exports via OTLP to a self-hosted collector.

Playwright

Apache-2.0
Build & toolingPermissive

Drives the live end-to-end suite against a running cockpit instance.

Self-hosting

CI-only; browsers vendored into the test image.

PostgreSQL

PostgreSQL
Data & storagePermissive

Primary store for events, nodes, Nuggets, gate results and the audit log. The readiness gate runs against real Postgres.

Self-hosting

Single primary with streaming replica; managed by the operator.

Prometheus

Apache-2.0
ObservabilityPermissive

Scrapes engine and worker metrics (gate latency, escalation counts, readiness drift).

Self-hosting

Scrapes the /metrics endpoint; retention set by the operator.

React

MIT
FrontendPermissive

Component model underpinning @uploz/ui and every cockpit surface.

Self-hosting

Bundled into the app build; no runtime dependency.

Redis

BSD-3-Clause
Data & storagePermissive

Job queue backing the worker and short-lived cache for computed readiness snapshots.

Self-hosting

Run in append-only persistence mode; replicated for HA.

Tailwind CSS

MIT
FrontendPermissive

Utility-first styling for the cockpit, driving the shared status-color and spacing tokens.

Self-hosting

Compiled at build time; ships as static CSS.

TypeScript

Apache-2.0
Build & toolingPermissive

Strict static typing across every package — the validation engine, UI kit and apps.

Self-hosting

Build-time only; emits plain JavaScript.

Vitest

MIT
Build & toolingPermissive

Unit and contract test runner for the engine and shared packages.

Self-hosting

Build-time only; no runtime footprint.

Inventory content is illustrative project-tracking data authored in src/data/dep-inventory, not a generated SBOM. License families are a triage hint, not legal advice.