Archived Third-party licenses
QueueRove web license notices
This page records the checked-in web dependency and font evidence. A signed release artifact, immutable image digest, and counsel-reviewed drift result are still required before it can be called a final release notice.
- Version 2026-07-18-draft.3
- Effective date: Pending Texas counsel approval
- SHA-256
7d635a9abc58120f0ee21324676f63b64698e3f8812eb15e1e33ec67e0cc48d5
Archived draft status
Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.
This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.
The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.
View the current stable route → · View all archived documents
1. Artifact and evidence boundary
Repository-local candidate, not signed-release evidence
The versions below come from the current repository manifests, lockfile, and an exact locally built web image SBOM with all-file SHA-256 metadata enabled. This checked-in candidate does not itself identify an immutable registry digest, production environment, or signed mobile binary. Release automation must regenerate the SBOM/notices and fail on drift before publication as final evidence.
Private QueueRove package names, internal image paths, credentials, mutable SBOM identifiers, and vulnerability details are intentionally excluded. Release checks exact-match every non-private package purl, retain the Node.js distribution license bundle and traced Next.js-vendored notices, and bind the distributed Inter files to exact image hashes. The internal SBOM retains the complete file and package inventory.
2. Web runtime notice candidate
| Component | Version | License or retained notice evidence |
|---|---|---|
| alpine-baselayout-data | 3.7.2-r0 | GPL-2.0-only |
| alpine-baselayout | 3.7.2-r0 | GPL-2.0-only |
| alpine-keys | 2.6-r0 | MIT |
| alpine-release | 3.23.5-r0 | MIT |
| apk-tools | 3.0.6-r0 | GPL-2.0-only |
| busybox-binsh | 1.37.0-r30 | GPL-2.0-only |
| busybox | 1.37.0-r30 | GPL-2.0-only |
| ca-certificates-bundle | 20260611-r0 | MPL-2.0 AND MIT |
| libapk | 3.0.6-r0 | GPL-2.0-only |
| libcrypto3 | 3.5.7-r0 | Apache-2.0 |
| libgcc | 15.2.0-r2 | GPL-2.0-or-later AND LGPL-2.1-or-later |
| libssl3 | 3.5.7-r0 | Apache-2.0 |
| libstdc++ | 15.2.0-r2 | GPL-2.0-or-later AND LGPL-2.1-or-later |
| musl-utils | 1.2.5-r23 | MIT AND BSD-2-Clause AND GPL-2.0-or-later |
| musl | 1.2.5-r23 | MIT |
| scanelf | 1.3.8-r2 | GPL-2.0-only |
| ssl_client | 1.37.0-r30 | GPL-2.0-only |
| zlib | 1.3.2-r0 | Zlib |
| node | 24.17.0 | Node.js distribution LICENSE bundle (MIT core and bundled third-party terms) |
The Node.js distribution retains its composite LICENSE bundle covering the MIT-licensed core and bundled third-party terms. Release evidence binds that file to SHA-256 4573185d56580da2b890ba34a85a409257640f1c5632eade4300137266194d18. Public rows omit internal image paths and mutable SBOM identifiers.
| Package | Version | License |
|---|---|---|
| @auth0/nextjs-auth0 | 4.25.0 | MIT |
| @edge-runtime/cookies | 5.0.2 | MIT |
| @img/colour | 1.1.0 | MIT |
| @img/sharp-libvips-linuxmusl-x64 | 1.2.4 | LGPL-3.0-or-later |
| @img/sharp-linuxmusl-x64 | 0.34.5 | Apache-2.0 |
| @next/env | 16.2.10 | MIT |
| @panva/hkdf | 1.2.1 | MIT |
| @stablelib/base64 | 1.0.1 | MIT |
| @swc/helpers | 0.5.15 | Apache-2.0 |
| client-only | 0.0.1 | MIT |
| detect-libc | 2.1.2 | Apache-2.0 |
| drizzle-orm | 0.45.2 | Apache-2.0 |
| fast-sha256 | 1.3.0 | Unlicense |
| jose | 6.2.3 | MIT |
| next | 16.2.10 | MIT |
| oauth4webapi | 3.8.6 | MIT |
| openid-client | 6.8.4 | MIT |
| postal-mime | 2.7.4 | MIT-0 |
| postgres | 3.4.9 | Unlicense |
| react-dom | 19.2.4 | MIT |
| react | 19.2.4 | MIT |
| resend | 6.17.2 | MIT |
| semver | 7.8.5 | ISC |
| sharp | 0.34.5 | Apache-2.0 |
| standardwebhooks | 1.0.0 | MIT |
| stripe | 22.3.2 | MIT |
| styled-jsx | 5.1.6 | MIT |
| zod | 4.4.3 | MIT |
| Parent package | Bundled package | Observed version | License |
|---|---|---|---|
| next@16.2.10 | @edge-runtime/cookies | 6.0.0 | MIT |
| next@16.2.10 | @edge-runtime/ponyfill | 4.0.0 | MIT |
| next@16.2.10 | @edge-runtime/primitives | 6.0.0 | MIT |
| next@16.2.10 | @hapi/accept | UNKNOWN | BSD-3-Clause |
| next@16.2.10 | @mswjs/interceptors | UNKNOWN | MIT |
| next@16.2.10 | @napi-rs/triples | UNKNOWN | MIT |
| next@16.2.10 | @opentelemetry/api | UNKNOWN | Apache-2.0 |
| next@16.2.10 | async-retry | UNKNOWN | MIT |
| next@16.2.10 | async-sema | UNKNOWN | MIT |
| next@16.2.10 | busboy | UNKNOWN | MIT |
| next@16.2.10 | bytes | UNKNOWN | MIT |
| next@16.2.10 | ci-info | UNKNOWN | MIT |
| next@16.2.10 | commander | UNKNOWN | MIT |
| next@16.2.10 | comment-json | UNKNOWN | MIT |
| next@16.2.10 | compression | UNKNOWN | MIT |
| next@16.2.10 | conf | UNKNOWN | MIT |
| next@16.2.10 | content-disposition | UNKNOWN | MIT |
| next@16.2.10 | cookie | UNKNOWN | MIT |
| next@16.2.10 | cross-spawn | UNKNOWN | MIT |
| next@16.2.10 | debug | UNKNOWN | MIT |
| next@16.2.10 | edge-runtime | UNKNOWN | MIT |
| next@16.2.10 | find-up | UNKNOWN | MIT |
| next@16.2.10 | fresh | UNKNOWN | MIT |
| next@16.2.10 | http-proxy | UNKNOWN | MIT |
| next@16.2.10 | image-size | UNKNOWN | MIT |
| next@16.2.10 | ipaddr.js | UNKNOWN | MIT |
| next@16.2.10 | is-animated | UNKNOWN | MIT |
| next@16.2.10 | is-docker | UNKNOWN | MIT |
| next@16.2.10 | is-wsl | UNKNOWN | MIT |
| next@16.2.10 | jsonwebtoken | UNKNOWN | MIT |
| next@16.2.10 | nanoid | UNKNOWN | MIT |
| next@16.2.10 | p-limit | UNKNOWN | MIT |
| next@16.2.10 | p-queue | UNKNOWN | MIT |
| next@16.2.10 | path-browserify | UNKNOWN | MIT |
| next@16.2.10 | path-to-regexp | UNKNOWN | MIT |
| next@16.2.10 | picomatch | UNKNOWN | MIT |
| next@16.2.10 | react-is | 19.3.0-canary-3f0b9e61-20260317 | MIT |
| next@16.2.10 | regenerator-runtime | 0.13.4 | MIT |
| next@16.2.10 | semver | UNKNOWN | ISC |
| next@16.2.10 | send | UNKNOWN | MIT |
| next@16.2.10 | source-map | UNKNOWN | BSD-3-Clause |
| next@16.2.10 | stacktrace-parser | UNKNOWN | MIT |
| next@16.2.10 | string-hash | UNKNOWN | CC0-1.0 |
| next@16.2.10 | strip-ansi | UNKNOWN | MIT |
| next@16.2.10 | superstruct | UNKNOWN | MIT |
| next@16.2.10 | tar | UNKNOWN | BlueOak-1.0.0 |
| next@16.2.10 | text-table | UNKNOWN | MIT |
| next@16.2.10 | ua-parser-js | UNKNOWN | MIT |
| next@16.2.10 | watchpack | UNKNOWN | MIT |
| next@16.2.10 | ws | UNKNOWN | MIT |
| next@16.2.10 | zod-validation-error | UNKNOWN | MIT |
| next@16.2.10 | zod | UNKNOWN | MIT |
3. Inter font distribution
| Asset | SHA-256 | License |
|---|---|---|
| Inter-Medium.ttf | 97ad806f526e41546d46365bb3a393145f75b7b1568913db74549ad8b8dba872 | SIL OFL 1.1 |
| Inter-Bold.ttf | 288316099b1e0a47a4716d159098005eef7c0066921f34e3200393dbdb01947f | SIL OFL 1.1 |
| LICENSE.txt | 262481e844521b326f5ecd053e59b98c8b2da78c8ee1bdbb6e8174305e54935a | Complete SIL OFL 1.1 text |
The checked-in web assets distribute Inter-Medium.ttf and Inter-Bold.ttf. Copyright (c) 2016 The Inter Project Authors (https://github.com/rsms/inter). The complete SIL Open Font License 1.1 appears below and is distributed beside the public font files as LICENSE.txt.
Complete Inter SIL Open Font License 1.1
Copyright (c) 2016 The Inter Project Authors (https://github.com/rsms/inter) This Font Software is licensed under the SIL Open Font License, Version 1.1. This license is copied below, and is also available with a FAQ at: http://scripts.sil.org/OFL ----------------------------------------------------------- SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007 ----------------------------------------------------------- PREAMBLE The goals of the Open Font License (OFL) are to stimulate worldwide development of collaborative font projects, to support the font creation efforts of academic and linguistic communities, and to provide a free and open framework in which fonts may be shared and improved in partnership with others. The OFL allows the licensed fonts to be used, studied, modified and redistributed freely as long as they are not sold by themselves. The fonts, including any derivative works, can be bundled, embedded, redistributed and/or sold with any software provided that any reserved names are not used by derivative works. The fonts and derivatives, however, cannot be released under any other type of license. The requirement for fonts to remain under this license does not apply to any document created using the fonts or their derivatives. DEFINITIONS "Font Software" refers to the set of files released by the Copyright Holder(s) under this license and clearly marked as such. This may include source files, build scripts and documentation. "Reserved Font Name" refers to any names specified as such after the copyright statement(s). "Original Version" refers to the collection of Font Software components as distributed by the Copyright Holder(s). "Modified Version" refers to any derivative made by adding to, deleting, or substituting -- in part or in whole -- any of the components of the Original Version, by changing formats or by porting the Font Software to a new environment. "Author" refers to any designer, engineer, programmer, technical writer or other person who contributed to the Font Software. PERMISSION AND CONDITIONS Permission is hereby granted, free of charge, to any person obtaining a copy of the Font Software, to use, study, copy, merge, embed, modify, redistribute, and sell modified and unmodified copies of the Font Software, subject to the following conditions: 1) Neither the Font Software nor any of its individual components, in Original or Modified Versions, may be sold by itself. 2) Original or Modified Versions of the Font Software may be bundled, redistributed and/or sold with any software, provided that each copy contains the above copyright notice and this license. These can be included either as stand-alone text files, human-readable headers or in the appropriate machine-readable metadata fields within text or binary files as long as those fields can be easily viewed by the user. 3) No Modified Version of the Font Software may use the Reserved Font Name(s) unless explicit written permission is granted by the corresponding Copyright Holder. This restriction only applies to the primary font name as presented to the users. 4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font Software shall not be used to promote, endorse or advertise any Modified Version, except to acknowledge the contribution(s) of the Copyright Holder(s) and the Author(s) or with their explicit written permission. 5) The Font Software, modified or unmodified, in part or in whole, must be distributed entirely under this license, and must not be distributed under any other license. The requirement for fonts to remain under this license does not apply to any document created using the Font Software. TERMINATION This license becomes null and void if any of the above conditions are not met. DISCLAIMER THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM OTHER DEALINGS IN THE FONT SOFTWARE.
4. iOS and Android are separate artifact gates
This web inventory does not cover either native application. Apple and Android notices, SDKs, permissions, assets, data practices, screenshots, and store disclosures must be generated independently from each exact signed release binary. Website completion is not mobile-artifact evidence.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove support”.