Open-source licenses
The open-source libraries Eddytor is built on, the license each one carries, and what that means when you redistribute the images.
Eddytor's own code is proprietary (terms); the
server, engine, and CLI are Rust binaries linking a large amount of open-source
work. This page names libraries, not versions - the per-release SBOM and
attribution file carry the exact inventory (below).
Across the roughly 660 third-party crates the server, engine, and CLI link, resolved
for x86_64-unknown-linux-gnu with all features enabled:
| License | Crates |
|---|
| MIT OR Apache-2.0 (dual) | ~385 |
| MIT | ~120 |
| Apache-2.0 | ~100 |
| Unicode-3.0 | 18 |
Other permissive (Zlib, CDLA-Permissive-2.0, CC0-1.0, bzip2-1.0.6, 0BSD) | 11 |
| MIT OR another permissive license | 10 |
| BSD-2-Clause / BSD-3-Clause | 8 |
| ISC | 6 |
| Weak copyleft (MPL-2.0, or MPL-2.0 elected from a dual grant) | 3 |
- No crate is under GPL, AGPL, SSPL, or any other strong or network copyleft
license. Nothing in the graph can oblige you to publish your own source.
- Every crate declares a license. There are no unlicensed dependencies.
- Counts are approximate and drift with dependency bumps; both claims above are
checked per release. Last reviewed 2026-08-27.
| Library | License | What it does |
|---|
deltalake | Apache-2.0 | Delta Lake protocol: transaction log, commits, time travel, schema evolution |
datafusion | Apache-2.0 | SQL planning and execution - the engine's query core |
arrow | Apache-2.0 | Columnar memory format for every row that crosses a transport |
object_store | MIT OR Apache-2.0 | Uniform access to S3, Azure Blob / ADLS Gen2, GCS, and local paths |
| Library | License | What it does |
|---|
poem + poem-openapi | MIT OR Apache-2.0 | HTTP server and the OpenAPI spec served at /spec |
poem-grpc | MIT OR Apache-2.0 | gRPC services on the same runtime as REST |
poem-mcpserver | MIT OR Apache-2.0 | The MCP endpoint AI clients connect to |
arrow-flight | Apache-2.0 | Flight SQL - bulk Arrow results over gRPC |
tonic / prost | MIT / Apache-2.0 | gRPC client plumbing and protobuf codegen |
reqwest | MIT OR Apache-2.0 | Outbound HTTP: OIDC discovery, AI providers, storage APIs |
| Library | License | What it does |
|---|
cedar-policy | Apache-2.0 | Authorization policy engine |
openidconnect / oauth2 | MIT / MIT OR Apache-2.0 | SSO/OIDC login and the OAuth 2.1 flows |
jsonwebtoken | MIT | JWT encoding and verification |
rustls | Apache-2.0 OR ISC OR MIT | TLS for every client and server socket - no OpenSSL in the tree |
| RustCrypto AEADs, hashes, MACs, elliptic curves | MIT OR Apache-2.0 | Authenticated encryption, signature, and digest primitives |
| Library | License | What it does |
|---|
tokio | MIT | Async runtime for both binaries |
sqlx | MIT OR Apache-2.0 | Compile-time-checked PostgreSQL access |
serde / serde_json | MIT OR Apache-2.0 | Serialisation across every wire format |
tracing | MIT | Structured logs and spans |
opentelemetry + -otlp | Apache-2.0 | OTLP export of traces and metrics |
lettre | MIT | SMTP client |
hickory-resolver | MIT OR Apache-2.0 | Async DNS resolver |
| Library | License | What it does |
|---|
clap | MIT OR Apache-2.0 | Command, flag, and completion parsing |
comfy-table | MIT | Table rendering for query output |
dirs | MIT OR Apache-2.0 | Locating the config and token cache per platform |
open | MIT | Opening the browser during eddytor login |
Three transitive dependencies are not purely permissive. Eddytor uses all three
unmodified and elects MPL-2.0, whose copyleft is per-file: it obliges us to
make those files' source available, not the larger work.
| Crate | Declared license | Reaches Eddytor through | Treatment |
|---|
priority-queue | LGPL-3.0-or-later OR MPL-2.0 | poem → poem-grpc | MPL-2.0 elected |
sse-codec | MPL-2.0 | poem | Unmodified; source is upstream |
option-ext | MPL-2.0 | deltalake → dirs → dirs-sys | Unmodified; source is upstream |
- Unicode-3.0 (18 crates) - the ICU data behind normalisation and collation.
Permissive, attribution required.
- CDLA-Permissive-2.0 (
webpki-roots) - a data license, not a code license,
covering the Mozilla root-certificate set compiled into the TLS clients.
bzip2-1.0.6 (libbz2-rs-sys) - BSD-style, reached through DataFusion's
compression codecs.
- CC0-1.0 (
tiny-keccak, and as one branch of blake3, constant_time_eq,
dunce) - public-domain dedication. Where a crate offers Apache-2.0 as an
alternative, Eddytor elects Apache-2.0 for its explicit patent grant.
- Running Eddytor internally, self-hosted or on Eddytor Cloud: nothing to do.
- Redistributing the images, the Helm chart, or the CLI beyond your own
organisation: ship the attribution notice with them. MIT and Apache-2.0 require
license text and copyright notices to travel with binary distributions;
Apache-2.0 §4(d) requires a dependency's
NOTICE content to be carried forward.
- Nothing in the dependency graph requires you to publish your own source, at any
tier.
For any release we can provide a CycloneDX SBOM of the dependency graph and a
per-crate attribution file with every dependency's license text. Mail
support@eddytor.com with your release tag or image digest.