# Third-party components and license notices AssetManager is released under the Apache License 2.0. The following components are independent third-party projects and are governed by their respective licenses. ## Directly used components | Component | Use | Upstream license | |---|---|---| | FastAPI | Web framework | MIT | | Uvicorn | ASGI server | BSD-3-Clause | | SQLAlchemy | Database abstraction | MIT | | Psycopg / psycopg-binary | PostgreSQL driver | LGPL-3.0-only | | Jinja | HTML templates | BSD-3-Clause | | python-multipart | Form and upload processing | Apache-2.0 | | pydantic-settings | Environment-based configuration | MIT | | itsdangerous | Signed session data | BSD-3-Clause | | ldap3 | Optional LDAP integration | LGPL-3.0-or-later | | Passlib | Password hashing | BSD-style license; includes additional notices for bundled components | | bcrypt | Hashing library used by `passlib[bcrypt]` | Apache-2.0 | | openpyxl | Excel import and export | MIT | | MeshCentral / MeshCtrl | Optional integration and remote jobs | Apache-2.0 | | PostgreSQL container image | Database service | Contains PostgreSQL and operating-system packages under their own licenses | | Python container image | Runtime base | Contains Python and operating-system packages under their own licenses | ## Transitive dependencies Extras such as `uvicorn[standard]`, `psycopg[binary]`, and `passlib[bcrypt]` install additional packages. Node.js packages may also bring transitive dependencies. The license texts of the versions actually built and distributed are authoritative. The Docker build therefore runs `tools/export_dependency_licenses.py`. Discovered license, NOTICE, COPYING, and copyright files are collected under `/app/THIRD_PARTY_LICENSES/` in the image. Preserve this directory when distributing a built image or offline package. ## No transfer of third-party rights Product names and trademarks belong to their respective owners. Their mention only describes technical use or integration and does not imply affiliation, endorsement, or certification. ## Review when dependencies change Review license terms and required notices whenever a dependency is added or updated. Automatically collected metadata does not replace review of the original license texts.