Dependency Inventory
Every third-party component Uploz runs on is open-source and self-hostable — the whole stack can run inside an operator's own infrastructure with no managed-SaaS lock-in. Each entry records its purpose, SPDX license and how it is deployed. 2 components carry a copyleft license flagged for legal review.
All dependencies
Sorted by name. Each entry names its license and how it is self-hosted.
Grafana
AGPL-3.0Operator-facing dashboards for the metrics and traces that back the cockpit observability views.
Self-hosting
Self-hosted with provisioned dashboards; AGPL means UI changes must stay in-house or be shared — flagged for review.
MinIO
AGPL-3.0S3-compatible object storage for exported reports, replay bundles and signed-document artifacts.
Self-hosting
Used unmodified over its S3 API; AGPL obligations limited to network use — flagged for legal sign-off.
Next.js
MITApp-router framework for apps/web and apps/dev-admin — server components, routing and the build pipeline.
Self-hosting
Runs in standalone output mode behind the reverse proxy.
Node.js
MITJavaScript/TypeScript runtime for the Next.js app server, the worker process and the validation-engine CLI.
Self-hosting
Pinned LTS in the base container image; no external service.
OpenTelemetry
Apache-2.0Vendor-neutral tracing and metrics instrumentation across the app server, worker and engine.
Self-hosting
Exports via OTLP to a self-hosted collector.
Playwright
Apache-2.0Drives the live end-to-end suite against a running cockpit instance.
Self-hosting
CI-only; browsers vendored into the test image.
PostgreSQL
PostgreSQLPrimary store for events, nodes, Nuggets, gate results and the audit log. The readiness gate runs against real Postgres.
Self-hosting
Single primary with streaming replica; managed by the operator.
Prometheus
Apache-2.0Scrapes engine and worker metrics (gate latency, escalation counts, readiness drift).
Self-hosting
Scrapes the /metrics endpoint; retention set by the operator.
React
MITComponent model underpinning @uploz/ui and every cockpit surface.
Self-hosting
Bundled into the app build; no runtime dependency.
Redis
BSD-3-ClauseJob queue backing the worker and short-lived cache for computed readiness snapshots.
Self-hosting
Run in append-only persistence mode; replicated for HA.
Tailwind CSS
MITUtility-first styling for the cockpit, driving the shared status-color and spacing tokens.
Self-hosting
Compiled at build time; ships as static CSS.
TypeScript
Apache-2.0Strict static typing across every package — the validation engine, UI kit and apps.
Self-hosting
Build-time only; emits plain JavaScript.
Vitest
MITUnit and contract test runner for the engine and shared packages.
Self-hosting
Build-time only; no runtime footprint.
Inventory content is illustrative project-tracking data authored in src/data/dep-inventory, not a generated SBOM. License families are a triage hint, not legal advice.