Open-source licenses

The open-source libraries Eddytor is built on, the license each one carries, and what that means when you redistribute the images.

Eddytor's own code is proprietary (terms); the server, engine, and CLI are Rust binaries linking a large amount of open-source work. This page names libraries, not versions - the per-release SBOM and attribution file carry the exact inventory (below).

License mix

Across the roughly 660 third-party crates the server, engine, and CLI link, resolved for x86_64-unknown-linux-gnu with all features enabled:

LicenseCrates
MIT OR Apache-2.0 (dual)~385
MIT~120
Apache-2.0~100
Unicode-3.018
Other permissive (Zlib, CDLA-Permissive-2.0, CC0-1.0, bzip2-1.0.6, 0BSD)11
MIT OR another permissive license10
BSD-2-Clause / BSD-3-Clause8
ISC6
Weak copyleft (MPL-2.0, or MPL-2.0 elected from a dual grant)3
  • No crate is under GPL, AGPL, SSPL, or any other strong or network copyleft license. Nothing in the graph can oblige you to publish your own source.
  • Every crate declares a license. There are no unlicensed dependencies.
  • Counts are approximate and drift with dependency bumps; both claims above are checked per release. Last reviewed 2026-08-27.

Key libraries

Data plane

LibraryLicenseWhat it does
deltalakeApache-2.0Delta Lake protocol: transaction log, commits, time travel, schema evolution
datafusionApache-2.0SQL planning and execution - the engine's query core
arrowApache-2.0Columnar memory format for every row that crosses a transport
object_storeMIT OR Apache-2.0Uniform access to S3, Azure Blob / ADLS Gen2, GCS, and local paths

Transports

LibraryLicenseWhat it does
poem + poem-openapiMIT OR Apache-2.0HTTP server and the OpenAPI spec served at /spec
poem-grpcMIT OR Apache-2.0gRPC services on the same runtime as REST
poem-mcpserverMIT OR Apache-2.0The MCP endpoint AI clients connect to
arrow-flightApache-2.0Flight SQL - bulk Arrow results over gRPC
tonic / prostMIT / Apache-2.0gRPC client plumbing and protobuf codegen
reqwestMIT OR Apache-2.0Outbound HTTP: OIDC discovery, AI providers, storage APIs

Identity, authorisation, and crypto

LibraryLicenseWhat it does
cedar-policyApache-2.0Authorization policy engine
openidconnect / oauth2MIT / MIT OR Apache-2.0SSO/OIDC login and the OAuth 2.1 flows
jsonwebtokenMITJWT encoding and verification
rustlsApache-2.0 OR ISC OR MITTLS for every client and server socket - no OpenSSL in the tree
RustCrypto AEADs, hashes, MACs, elliptic curvesMIT OR Apache-2.0Authenticated encryption, signature, and digest primitives

Runtime, database, observability

LibraryLicenseWhat it does
tokioMITAsync runtime for both binaries
sqlxMIT OR Apache-2.0Compile-time-checked PostgreSQL access
serde / serde_jsonMIT OR Apache-2.0Serialisation across every wire format
tracingMITStructured logs and spans
opentelemetry + -otlpApache-2.0OTLP export of traces and metrics
lettreMITSMTP client
hickory-resolverMIT OR Apache-2.0Async DNS resolver

CLI

LibraryLicenseWhat it does
clapMIT OR Apache-2.0Command, flag, and completion parsing
comfy-tableMITTable rendering for query output
dirsMIT OR Apache-2.0Locating the config and token cache per platform
openMITOpening the browser during eddytor login

Weak copyleft

Three transitive dependencies are not purely permissive. Eddytor uses all three unmodified and elects MPL-2.0, whose copyleft is per-file: it obliges us to make those files' source available, not the larger work.

CrateDeclared licenseReaches Eddytor throughTreatment
priority-queueLGPL-3.0-or-later OR MPL-2.0poem → poem-grpcMPL-2.0 elected
sse-codecMPL-2.0poemUnmodified; source is upstream
option-extMPL-2.0deltalake → dirs → dirs-sysUnmodified; source is upstream

Other licenses worth naming

  • Unicode-3.0 (18 crates) - the ICU data behind normalisation and collation. Permissive, attribution required.
  • CDLA-Permissive-2.0 (webpki-roots) - a data license, not a code license, covering the Mozilla root-certificate set compiled into the TLS clients.
  • bzip2-1.0.6 (libbz2-rs-sys) - BSD-style, reached through DataFusion's compression codecs.
  • CC0-1.0 (tiny-keccak, and as one branch of blake3, constant_time_eq, dunce) - public-domain dedication. Where a crate offers Apache-2.0 as an alternative, Eddytor elects Apache-2.0 for its explicit patent grant.

Your obligations

  • Running Eddytor internally, self-hosted or on Eddytor Cloud: nothing to do.
  • Redistributing the images, the Helm chart, or the CLI beyond your own organisation: ship the attribution notice with them. MIT and Apache-2.0 require license text and copyright notices to travel with binary distributions; Apache-2.0 §4(d) requires a dependency's NOTICE content to be carried forward.
  • Nothing in the dependency graph requires you to publish your own source, at any tier.

SBOM and attribution files

For any release we can provide a CycloneDX SBOM of the dependency graph and a per-crate attribution file with every dependency's license text. Mail support@eddytor.com with your release tag or image digest.

On this page