OSS-001record 1
{
"id": "OSS-001",
"repo": "Alfresco/alfresco-community-repo",
"url": "https://github.com/Alfresco/alfresco-community-repo",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "LGPL-3.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/Alfresco/alfresco-community-repo API license.spdx_id = LGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents",
"case_workflow"
],
"composite_contents": [
"data",
"workflow",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 229,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 104,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 405739
},
"adaptation_risks": "LGPL-3.0 weak copyleft; enterprise ECM, Java, 229 stars on this component repo",
"claim": "Alfresco/alfresco-community-repo supplies files_documents, case_workflow at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow+auth, no ui; the ECM repository/back-end component - Alfresco Share (the UI product) is a separate repo -> primitive"
}
OSS-002record 2
{
"id": "OSS-002",
"repo": "AppFlowy-IO/AppFlowy",
"url": "https://github.com/AppFlowy-IO/AppFlowy",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/AppFlowy-IO/AppFlowy API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs",
"airtable_data"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 75996,
"pushed_at": "2026-08-11",
"days_since_push": 16,
"maintenance": "active",
"archived": false,
"primary_language": "Dart",
"open_issues": 1003,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 93939
},
"adaptation_risks": "AGPL-3.0; Dart/Flutter stack, no web-first seam",
"claim": "AppFlowy-IO/AppFlowy supplies notes_docs, airtable_data at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows frontend/ (Flutter+Rust app) + install.sh, containerized; a runnable workspace/notes application -> product"
}
OSS-003record 3
{
"id": "OSS-003",
"repo": "BookStackApp/BookStack",
"url": "https://github.com/BookStackApp/BookStack",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/BookStackApp/BookStack API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 19001,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 1,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 51983
},
"adaptation_risks": "MIT verified clean, pushed today; PHP/Laravel. One of the few clean-rights document/wiki systems",
"claim": "BookStackApp/BookStack supplies notes_docs, portal at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 5,
"kind_revision_note": "Portal tag removed. BookStack is an internal wiki. Observed repos/BookStackApp/BookStack/contents/app/Access = Ldap.php, LdapService.php, Saml2Service.php, Oidc/, SocialAuthService.php, GroupSyncService.php, Mfa/ — that is enterprise SSO for STAFF joining an org directory, the opposite of an untrusted external identity. app/Permissions/ (EntityPermissionEvaluator, JointPermissionBuilder) scopes shelf/book visibility between internal roles; there is no external-requester concept and no request-submission surface in app/. Retains notes_docs, which is what it actually is.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, composite_repo, containerized; deployable wiki product -> product"
}
OSS-004record 4
{
"id": "OSS-004",
"repo": "Budibase/budibase",
"url": "https://github.com/Budibase/budibase",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPLv3 overall, per-package licenses",
"license_class": "strong-copyleft",
"license_evidence": "LICENSE body read: \"You can consider Budibase to be GPLv3 licensed overall\"; each package carries its own license file",
"capability_kinds": [
"admin_data",
"approvals_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"connectors",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 28244,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 277,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 781454
},
"adaptation_risks": "LICENSE body says \"consider Budibase GPLv3 overall\" with per-package files — no single clean answer",
"claim": "Budibase/budibase supplies admin_data, portal, approvals_workflow at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Observed repos/Budibase/budibase/contents/packages = builder, client, server, worker, backend-core, bbui, sdk, pro — a low-code app builder, same archetype as appsmith and ToolJet. Note packages/pro/ carries its own license.md, corroborating an open-core carve-out beside the 'GPLv3 overall' reading already in this row's licence evidence. Retains admin_data and approvals_workflow.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,connectors,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-005record 5
{
"id": "OSS-005",
"repo": "BuilderIO/builder",
"url": "https://github.com/BuilderIO/builder",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/BuilderIO/builder API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data",
"notes_docs"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 8808,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 133,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 340666
},
"adaptation_risks": "MIT repo but the visual builder is a paid hosted product — SDK-to-paid-API shape",
"claim": "BuilderIO/builder supplies admin_data, notes_docs at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Top-level `packages/` + `plugins/` monorepo publishing the Builder SDKs to npm (Apache-2.0 root). The reusable seam is a published SDK package, not the hosted visual-editor service, so extracted_package beats pattern.",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents=[ui], extracted_package monorepo of SDKs for a hosted visual CMS; you embed it -> framework"
}
OSS-006record 6
{
"id": "OSS-006",
"repo": "Dolibarr/dolibarr",
"url": "https://github.com/Dolibarr/dolibarr",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/Dolibarr/dolibarr API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm",
"inventory",
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 7541,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 1189,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1725136
},
"adaptation_risks": "GPL-3.0 verified; PHP",
"claim": "Dolibarr/dolibarr supplies crm, inventory, billing at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-007record 7
{
"id": "OSS-007",
"repo": "Leantime/leantime",
"url": "https://github.com/Leantime/leantime",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/Leantime/leantime API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 11458,
"pushed_at": "2026-08-15",
"days_since_push": 12,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 321,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 250019
},
"adaptation_risks": "AGPL-3.0 verified",
"claim": "Leantime/leantime supplies project_management at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-008record 8
{
"id": "OSS-008",
"repo": "LimeSurvey/LimeSurvey",
"url": "https://github.com/LimeSurvey/LimeSurvey",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-2.0-or-later",
"license_class": "strong-copyleft",
"license_evidence": "LICENSE body read: \"GNU General Public License ... either version 2 of the License, or (at your option) any later version\"",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3703,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 107,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1468395
},
"adaptation_risks": "GPL-2.0-or-later per LICENSE body",
"claim": "LimeSurvey/LimeSurvey supplies forms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-009record 9
{
"id": "OSS-009",
"repo": "NangoHQ/nango",
"url": "https://github.com/NangoHQ/nango",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Elastic License 2.0",
"license_class": "source-available",
"license_evidence": "LICENSE body read: verbatim \"Elastic License 2.0 (ELv2)\" with the standard hosting/managed-service limitation",
"capability_kinds": [
"connectors",
"auth_identity"
],
"composite_contents": [
"data",
"connectors",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 11615,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 107,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 330975
},
"adaptation_risks": "ELv2 confirmed from LICENSE body — hosting limitation makes this unusable as a hosted component in client delivery",
"claim": "NangoHQ/nango supplies connectors, auth_identity at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+connectors+auth, no ui in list; a unified-integrations engine you embed, source-available -> primitive"
}
OSS-010record 10
{
"id": "OSS-010",
"repo": "Part-DB/Part-DB-server",
"url": "https://github.com/Part-DB/Part-DB-server",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/Part-DB/Part-DB-server API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 1739,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 201,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 69209
},
"adaptation_risks": "AGPL-3.0 verified; electronics-parts specific",
"claim": "Part-DB/Part-DB-server supplies inventory at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-011record 11
{
"id": "OSS-011",
"repo": "Peppermint-Lab/peppermint",
"url": "https://github.com/Peppermint-Lab/peppermint",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Commercial license",
"license_class": "source-available",
"license_evidence": "license body read: content under the repo is under a Commercial License; repo also ARCHIVED per repos API archived:true",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3160,
"pushed_at": "2025-09-21",
"days_since_push": 340,
"maintenance": "slowing",
"archived": true,
"primary_language": "TypeScript",
"open_issues": 101,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 111836
},
"adaptation_risks": "ARCHIVED (archived:true) and a Commercial License per its license file",
"claim": "Peppermint-Lab/peppermint supplies support_desk at slowing maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-012record 12
{
"id": "OSS-012",
"repo": "PostHog/posthog",
"url": "https://github.com/PostHog/posthog",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: ee/ under ee/LICENSE; content outside it permissive",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 39288,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 5108,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 6662701
},
"adaptation_risks": "MIT outside ee/; very large Python/Django monolith",
"claim": "PostHog/posthog supplies analytics_bi at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. Top-level listing shows an `ee/` directory alongside `products/`, `frontend/`, `rust/`, `dagster_cloud.yaml` and ten docker-compose variants: this is an enormous multi-language open-core monolith whose MIT root does not cover `ee/`. Learning the event/insight model is worth more than lifting code.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-013record 13
{
"id": "OSS-013",
"repo": "PostgREST/postgrest",
"url": "https://github.com/PostgREST/postgrest",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/PostgREST/postgrest API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 27630,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Haskell",
"open_issues": 396,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 17988
},
"adaptation_risks": "MIT verified clean; turns Postgres schema into a REST API. Haskell, but operated as a binary",
"claim": "PostgREST/postgrest supplies admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only; turns a Postgres schema into a REST API, no UI or identity -> primitive"
}
OSS-014record 14
{
"id": "OSS-014",
"repo": "ProcessMaker/processmaker",
"url": "https://github.com/ProcessMaker/processmaker",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/ProcessMaker/processmaker API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow",
"case_workflow",
"forms"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 541,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 226,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 170304
},
"adaptation_risks": "AGPL-3.0; 541 stars; PHP/Laravel",
"claim": "ProcessMaker/processmaker supplies approvals_workflow, case_workflow, forms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-015record 15
{
"id": "OSS-015",
"repo": "Redocly/redoc",
"url": "https://github.com/Redocly/redoc",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/Redocly/redoc API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"developer_docs_rendering"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 25888,
"pushed_at": "2026-08-20",
"days_since_push": 7,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 449,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 96054
},
"adaptation_risks": "MIT verified clean; API-docs renderer only",
"claim": "Redocly/redoc supplies portal at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED. Not client-capability supply: developer-facing docs rendering only, outside the 24-kind taxonomy.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed (OpenAPI reference RENDERER, no identity layer: contents = src, demo, benchmark, cypress.config.ts, webpack.config.ts — no server, no auth, no persistence). Repair subagent reassigned it to notes_docs; LANE OWNER OVERTURNED that. notes_docs in this taxonomy means Notion-like AUTHORING — creating and editing documents. Redoc renders a machine-generated spec to static HTML and no one authors in it, so counting it as notes_docs supply inflates that kind with a row that cannot serve the capability — the same inflation failure this pass exists to correct. Re-tagged developer_docs_rendering, a kind outside the 24-kind client-capability taxonomy, and dropped to reference so it is retained as evidence without counting as client-facing capability supply.",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only, extracted_package; an OpenAPI reference renderer component -> primitive"
}
OSS-016record 16
{
"id": "OSS-016",
"repo": "RocketChat/Rocket.Chat",
"url": "https://github.com/RocketChat/Rocket.Chat",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: apps/meteor/ee/ and ee/ under apps/meteor/ee/LICENSE; remainder permissive",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 46033,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 4008,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2108768
},
"adaptation_risks": "MIT outside ee/ dirs per LICENSE body; Meteor legacy",
"claim": "RocketChat/Rocket.Chat supplies messaging_notifications at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. Top-level `ee/` directory sits beside `apps/` and `packages/` under an MIT root, so the enterprise slice is carved out. A full Meteor/Node chat server is a product to run, not a seam to extract, and the client need is notifications rather than a chat platform.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-017record 17
{
"id": "OSS-017",
"repo": "SuiteCRM/SuiteCRM",
"url": "https://github.com/SuiteCRM/SuiteCRM",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/SuiteCRM/SuiteCRM API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 5695,
"pushed_at": "2026-07-31",
"days_since_push": 27,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 1373,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 148047
},
"adaptation_risks": "AGPL-3.0 verified; identity is SuiteCRM/SuiteCRM not salesagility/SuiteCRM. Legacy SugarCRM codebase",
"claim": "SuiteCRM/SuiteCRM supplies crm at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"salesagility/SuiteCRM"
],
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-018record 18
{
"id": "OSS-018",
"repo": "Sunbird-Ed/SunbirdEd-portal",
"url": "https://github.com/Sunbird-Ed/SunbirdEd-portal",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/Sunbird-Ed/SunbirdEd-portal API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 41,
"pushed_at": "2026-02-21",
"days_since_push": 187,
"maintenance": "slowing",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 109,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 334238
},
"adaptation_risks": "MIT clean but 41 stars and last push 2026-02-21; India-specific",
"claim": "Sunbird-Ed/SunbirdEd-portal supplies lms, portal at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. Repo is a single `src/` Angular portal wired to Sunbird's wider service mesh (Jenkinsfiles, deploy.sh, vcs-config.sh), so nothing detaches cleanly; maintenance is already slowing. Take the LMS-portal information architecture, not the code.",
"kind_revision_note": "Portal tag removed. SunbirdEd-portal is NAMED a portal but is an LMS front-end: learners are enrolled internal users of the platform, and the repo is a single src/ Angular app wired to Sunbird's service mesh with no independent identity or request-submission layer. The name is the only evidence for the tag, and a name is a claim, not a verdict. Retains lms.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-019record 19
{
"id": "OSS-019",
"repo": "Sylius/Sylius",
"url": "https://github.com/Sylius/Sylius",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/Sylius/Sylius API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 8516,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 215,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 363802
},
"adaptation_risks": "MIT verified; PHP/Symfony",
"claim": "Sylius/Sylius supplies e_commerce, inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Symfony application with `docker-compose.yml`, `bin/`, `config/`, `public/`, `templates/` and a full `src/` bundle tree under MIT. It is a deployable, well-factored e-commerce engine; running it intact and theming it is more defensible than reimplementing its catalogue/order model.",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents ui+data+workflow+host_chrome but distributed as Symfony bundles/components installed into your own app (sylius/sylius-standard is the runnable distribution) -> framework"
}
OSS-020record 20
{
"id": "OSS-020",
"repo": "ToolJet/ToolJet",
"url": "https://github.com/ToolJet/ToolJet",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/ToolJet/ToolJet API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"ui",
"data",
"workflow",
"connectors",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 40777,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 1169,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1692990
},
"adaptation_risks": "AGPL-3.0 verified; strong low-code fit but copyleft",
"claim": "ToolJet/ToolJet supplies admin_data, portal at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Observed repos/ToolJet/ToolJet/contents dirs = frontend, server, plugins, marketplace, queryPanel, deploy, docker — a low-code internal-tool builder in the same category as appsmith. Users are trusted staff building dashboards over internal data sources; no external-identity or request-submission surface. Retains admin_data. (Checked plans/ for an open-core carve-out: it holds only widget-css-class.md, so the AGPL posture already recorded stands.)",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,connectors,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-021record 21
{
"id": "OSS-021",
"repo": "TriliumNext/Trilium",
"url": "https://github.com/TriliumNext/Trilium",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/TriliumNext/Trilium API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 37608,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 700,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 652667
},
"adaptation_risks": "AGPL-3.0; identity moved from zadam/trilium to TriliumNext/Trilium",
"claim": "TriliumNext/Trilium supplies notes_docs at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"zadam/trilium"
],
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows apps/ + packages/ + docker-compose.yml; monorepo whose apps/ are the runnable notes server and desktop client -> product"
}
OSS-022record 22
{
"id": "OSS-022",
"repo": "TryGhost/Ghost",
"url": "https://github.com/TryGhost/Ghost",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/TryGhost/Ghost API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs",
"messaging_notifications",
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 55070,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 136,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 574523
},
"adaptation_risks": "MIT verified clean; identity is TryGhost/Ghost not ghost/Ghost. Publishing+membership+billing in one clean-rights package",
"claim": "TryGhost/Ghost supplies notes_docs, messaging_notifications, billing at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 10,
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,billing,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-023record 23
{
"id": "OSS-023",
"repo": "WordPress/wordpress-develop",
"url": "https://github.com/WordPress/wordpress-develop",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-2.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/WordPress/wordpress-develop API license.spdx_id = GPL-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3421,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 3482,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 372628
},
"adaptation_risks": "GPL-2.0 verified",
"claim": "WordPress/wordpress-develop supplies notes_docs at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-024record 24
{
"id": "OSS-024",
"repo": "Worklenz/worklenz",
"url": "https://github.com/Worklenz/worklenz",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/Worklenz/worklenz API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3151,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 76,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 13342
},
"adaptation_risks": "AGPL-3.0 verified",
"claim": "Worklenz/worklenz supplies project_management at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-025record 25
{
"id": "OSS-025",
"repo": "activepieces/activepieces",
"url": "https://github.com/activepieces/activepieces",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial packages/ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: packages/ee/ and server/api/src/app/ee under packages/ee/LICENSE; remainder MIT",
"capability_kinds": [
"approvals_workflow",
"connectors",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"connectors",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 24055,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 503,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 631405
},
"adaptation_risks": "MIT core but packages/ee/ is commercial; connector pieces are the reusable asset",
"claim": "activepieces/activepieces supplies approvals_workflow, connectors, messaging_notifications at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+connectors+auth+host_chrome, containerized monorepo; deployable automation product -> product"
}
OSS-026record 26
{
"id": "OSS-026",
"repo": "akaunting/akaunting",
"url": "https://github.com/akaunting/akaunting",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSL 1.1",
"license_class": "source-available",
"license_evidence": "LICENSE.txt body read: MariaDB Business Source License; Additional Use Grant caps production use at \"more than two users or one company\"",
"capability_kinds": [
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 10093,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 9,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 86569
},
"adaptation_risks": "BSL 1.1 with a hard \"two users or one company\" production cap read from LICENSE.txt",
"claim": "akaunting/akaunting supplies billing at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-027record 27
{
"id": "OSS-027",
"repo": "al1abb/invoify",
"url": "https://github.com/al1abb/invoify",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/al1abb/invoify API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing",
"forms"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 6345,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 39,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 4663
},
"adaptation_risks": "Invoice PDF generator, not a finance system; no persistence spine",
"claim": "al1abb/invoify supplies billing, forms at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows Next.js app/ + components/ + services/ + puppeteer.config + Dockerfile, but no migrations or auth; a runnable stateless invoice-PDF generator -> product (narrow: no persistence or identity)"
}
OSS-028record 28
{
"id": "OSS-028",
"repo": "apache/airflow",
"url": "https://github.com/apache/airflow",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/apache/airflow API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 46617,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 1964,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 698407
},
"adaptation_risks": "Apache-2.0 clean; batch DAG orchestration, wrong shape for human approval workflows",
"claim": "apache/airflow supplies approvals_workflow at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+host_chrome, intact_service; ships its own scheduler, webserver UI and metadata DB -> product (developer-facing orchestrator)"
}
OSS-029record 29
{
"id": "OSS-029",
"repo": "apache/superset",
"url": "https://github.com/apache/superset",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/apache/superset API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 74479,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 641,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1125229
},
"adaptation_risks": "Apache-2.0 verified clean; deploy alongside rather than embed",
"claim": "apache/superset supplies analytics_bi at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-030record 30
{
"id": "OSS-030",
"repo": "apostrophecms/apostrophe",
"url": "https://github.com/apostrophecms/apostrophe",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "undeclared at root (package.json license: null)",
"license_class": "none-declared",
"license_evidence": "no root LICENSE file via contents API; /license endpoint empty; package.json license field is null",
"capability_kinds": [
"notes_docs",
"admin_data"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4607,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 136,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 51728
},
"adaptation_risks": "NO license declared at root: no LICENSE file, empty /license endpoint, package.json license null. Rights unresolved",
"claim": "apostrophecms/apostrophe supplies notes_docs, admin_data at active maintenance under a none-declared rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome but npm module monorepo you require() into your own Node app; CMS framework -> framework"
}
OSS-031record 31
{
"id": "OSS-031",
"repo": "appsmithorg/appsmith",
"url": "https://github.com/appsmithorg/appsmith",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/appsmithorg/appsmith API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"ui",
"data",
"workflow",
"connectors",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 40755,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 4470,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 808316
},
"adaptation_risks": "Apache-2.0 verified; Java backend + heavy runtime, awkward to embed",
"claim": "appsmithorg/appsmith supplies admin_data, portal at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Observed repos/appsmithorg/appsmith/contents/app = client, server, util — an internal-tool BUILDER whose users are the trusted staff assembling admin UIs over company databases. Its auth model gates which employees may edit or run an app; there is no external-requester identity and no request-submission archetype. Retains admin_data, the honest tag.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,connectors,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-032record 32
{
"id": "OSS-032",
"repo": "appwrite/appwrite",
"url": "https://github.com/appwrite/appwrite",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-3-Clause",
"license_class": "permissive",
"license_evidence": "repos/appwrite/appwrite API license.spdx_id = BSD-3-Clause; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"files_documents",
"airtable_data"
],
"composite_contents": [
"data",
"auth",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 57135,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1013,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 449677
},
"adaptation_risks": "BSD-3-Clause verified clean; BaaS covering auth+storage+DB in one deployable",
"claim": "appwrite/appwrite supplies auth_identity, files_documents, airtable_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents data+auth+host_chrome, containerized; deployable BaaS with its own console -> product (developer platform)"
}
OSS-033record 33
{
"id": "OSS-033",
"repo": "authelia/authelia",
"url": "https://github.com/authelia/authelia",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/authelia/authelia API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 28717,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 129,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 82598
},
"adaptation_risks": "Apache-2.0 verified; gateway auth/2FA, not an app-level identity model",
"claim": "authelia/authelia supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents=[auth], but ships as a deployable authentication gateway with its own login portal -> product (narrow: gateway, not full IdP)"
}
OSS-034record 34
{
"id": "OSS-034",
"repo": "bagisto/bagisto",
"url": "https://github.com/bagisto/bagisto",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/bagisto/bagisto API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 28004,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 35,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 410085
},
"adaptation_risks": "MIT verified; PHP/Laravel",
"claim": "bagisto/bagisto supplies e_commerce, inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Laravel application root (`artisan`, `bootstrap/`, `routes/`, `database/`, `docker-compose.yml`, `docker/`) with an MIT LICENSE, plus a `packages/` tree of first-party modules. Deployable as-is; permissive rights mean there is no reason to reimplement.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, containerized Laravel monorepo; a runnable storefront+admin product -> product"
}
OSS-035record 35
{
"id": "OSS-035",
"repo": "baserow/baserow",
"url": "https://github.com/baserow/baserow",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial premium/ and enterprise/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: premium/ under premium/LICENSE, docs/ CC BY-SA 4.0, remainder permissive",
"capability_kinds": [
"airtable_data"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 5733,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 1223,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 266743
},
"adaptation_risks": "MIT core is real but premium/ and enterprise/ dirs are commercial; Python/Django + Nuxt",
"claim": "baserow/baserow supplies airtable_data at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern for rights reasons despite the permissive-open-core label: top-level `premium/` and `enterprise/` directories carve the paid surface out of the MIT root, and the row's value to the client is the Airtable-style grid/field model rather than a fork of the Django+Nuxt monolith.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-036record 36
{
"id": "OSS-036",
"repo": "better-auth/better-auth",
"url": "https://github.com/better-auth/better-auth",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/better-auth/better-auth API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 29711,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 684,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 154272
},
"adaptation_risks": "MIT verified clean; TS-native, framework-agnostic, plugin architecture. Young project, API still moving",
"claim": "better-auth/better-auth supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 9,
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[auth] only, extracted_package; a TypeScript auth library -> primitive"
}
OSS-037record 37
{
"id": "OSS-037",
"repo": "bigcapitalhq/bigcapital",
"url": "https://github.com/bigcapitalhq/bigcapital",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/bigcapitalhq/bigcapital API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing",
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3864,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 209,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 44159
},
"adaptation_risks": "AGPL-3.0 verified; TS monorepo, good structure but copyleft",
"claim": "bigcapitalhq/bigcapital supplies billing, analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-038record 38
{
"id": "OSS-038",
"repo": "bonitasoft/bonita-engine",
"url": "https://github.com/bonitasoft/bonita-engine",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "LGPL-2.1",
"license_class": "weak-copyleft",
"license_evidence": "repos/bonitasoft/bonita-engine API license.spdx_id = LGPL-2.1; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow",
"case_workflow"
],
"composite_contents": [
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 176,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 1,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 117555
},
"adaptation_risks": "LGPL-2.1 weak copyleft; 176 stars, narrow community",
"claim": "bonitasoft/bonita-engine supplies approvals_workflow, case_workflow at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow, no ui; a BPM engine component -> primitive"
}
OSS-039record 39
{
"id": "OSS-039",
"repo": "calcom/cal.diy",
"url": "https://github.com/calcom/cal.diy",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/calcom/cal.diy API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 47952,
"pushed_at": "2026-08-08",
"days_since_push": 19,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1430,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1146727
},
"adaptation_risks": "Canonical identity moved from calcom/cal.com to calcom/cal.diy; unpinned references drift. Large monorepo; booking engine is the valuable seam",
"claim": "calcom/cal.diy supplies calendar_scheduling, portal at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"calcom/cal.com"
],
"top10_rank": 3,
"kind_revision_note": "Portal tag removed. cal.diy's booker is an ANONYMOUS public booking page, not an authenticated external identity with scoped read of its own records — a visitor picks a slot and leaves. Under the strict archetype the middle element is absent. Retains calendar_scheduling, the capability it genuinely supplies and the basis for its top-10 slot.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+connectors+billing+host_chrome, containerized monorepo; full booking product -> product"
}
OSS-040record 40
{
"id": "OSS-040",
"repo": "camunda/camunda",
"url": "https://github.com/camunda/camunda",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0 + Camunda License 1.0",
"license_class": "source-available-mixed",
"license_evidence": "licenses/ dir listed via contents API: APACHE-2.0.txt and CAMUNDA-LICENSE-1.0.txt both present; no root LICENSE, /license endpoint empty",
"capability_kinds": [
"approvals_workflow",
"case_workflow"
],
"composite_contents": [
"data",
"workflow",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4255,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 2937,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1315411
},
"adaptation_risks": "No root LICENSE; licenses/ dir carries both APACHE-2.0.txt and CAMUNDA-LICENSE-1.0.txt — mixed, needs per-module resolution",
"claim": "camunda/camunda supplies approvals_workflow, case_workflow at active maintenance under a source-available-mixed rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow+host_chrome, no ui; a process-orchestration engine (Operate/Tasklist UIs are separate, non-open components) -> primitive"
}
OSS-041record 41
{
"id": "OSS-041",
"repo": "casdoor/casdoor",
"url": "https://github.com/casdoor/casdoor",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/casdoor/casdoor API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 14280,
"pushed_at": "2026-08-25",
"days_since_push": 2,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 111,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 46990
},
"adaptation_risks": "Apache-2.0 verified; Go+React, UI included",
"claim": "casdoor/casdoor supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, containerized; deployable IdP with admin UI -> product"
}
OSS-042record 42
{
"id": "OSS-042",
"repo": "chamilo/chamilo-lms",
"url": "https://github.com/chamilo/chamilo-lms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/chamilo/chamilo-lms API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 985,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 454,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1569393
},
"adaptation_risks": "GPL-3.0 verified; PHP",
"claim": "chamilo/chamilo-lms supplies lms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-043record 43
{
"id": "OSS-043",
"repo": "chatwoot/chatwoot",
"url": "https://github.com/chatwoot/chatwoot",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial enterprise/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: content under \"enterprise/\" is under enterprise/LICENSE; content outside it is MIT",
"capability_kinds": [
"support_desk",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 36249,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 1358,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 318530
},
"adaptation_risks": "Rails stack diverges from a JS/TS spine; enterprise/ dir must be excluded from any copy",
"claim": "chatwoot/chatwoot supplies support_desk, messaging_notifications at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,connectors,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-044record 44
{
"id": "OSS-044",
"repo": "civicrm/civicrm-core",
"url": "https://github.com/civicrm/civicrm-core",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/civicrm/civicrm-core API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 768,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 258,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 401683
},
"adaptation_risks": "AGPL-3.0 verified; nonprofit-specific, CMS-coupled",
"claim": "civicrm/civicrm-core supplies crm at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,host_chrome] carries ui + data + host_chrome; a deployable app with its own chrome -> product"
}
OSS-045record 45
{
"id": "OSS-045",
"repo": "craftcms/cms",
"url": "https://github.com/craftcms/cms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Craft proprietary license",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: Pixel & Tonic, Inc. license with a \"Don't plagiarize\" clause; not an OSI license",
"capability_kinds": [
"notes_docs",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3604,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 538,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1052434
},
"adaptation_risks": "Craft proprietary license read from LICENSE.md",
"claim": "craftcms/cms supplies notes_docs, files_documents at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-046record 46
{
"id": "OSS-046",
"repo": "crater-invoice-inc/crater",
"url": "https://github.com/crater-invoice-inc/crater",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/crater-invoice-inc/crater API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 8340,
"pushed_at": "2024-08-10",
"days_since_push": 747,
"maintenance": "stale",
"archived": false,
"primary_language": "PHP",
"open_issues": 425,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 45705
},
"adaptation_risks": "AGPL-3.0 and last push 2024-08-10 — roughly two years stale",
"claim": "crater-invoice-inc/crater supplies billing at stale maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"crater-invoice/crater"
],
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-047record 47
{
"id": "OSS-047",
"repo": "cube-js/cube",
"url": "https://github.com/cube-js/cube",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0 default, some MIT",
"license_class": "permissive",
"license_evidence": "LICENSE body read: \"default license throughout the repository is Apache License 2.0\"; a small MIT subset",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 20714,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 1137,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 488033
},
"adaptation_risks": "Apache-2.0 default per LICENSE body; semantic layer, a clean headless seam",
"claim": "cube-js/cube supplies analytics_bi at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only, embedded_module; a semantic/metrics API layer with no end-user BI UI of its own -> primitive"
}
OSS-048record 48
{
"id": "OSS-048",
"repo": "decaporg/decap-cms",
"url": "https://github.com/decaporg/decap-cms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/decaporg/decap-cms API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs",
"admin_data"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 19318,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 590,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 99419
},
"adaptation_risks": "MIT verified; identity moved from netlify/netlify-cms. Git-backed, maintenance has slowed",
"claim": "decaporg/decap-cms supplies notes_docs, admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"netlify/netlify-cms"
],
"shape_revision_note": "`packages/` lerna monorepo publishing decap-cms-app and its widget packages to npm under MIT, with `.storybook/` confirming component-level packaging. This is a CMS admin UI you mount into an existing site — embedded_module is the actual seam.",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + dev-test/ + lerna.json, composite_contents=[ui]; a git-backed CMS widget mounted into your own static site -> framework"
}
OSS-049record 49
{
"id": "OSS-049",
"repo": "directus/directus",
"url": "https://github.com/directus/directus",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Monospace Sustainable Core License 1.0 (MSCL-1.0-GPL)",
"license_class": "source-available",
"license_evidence": "license body read: \"# Monospace Sustainable Core License, Version 1.0\" — NOT the BSL/MIT it is often cited as",
"capability_kinds": [
"admin_data",
"airtable_data",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 37635,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 386,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 451645
},
"adaptation_risks": "Monospace Sustainable Core License 1.0 read from license file — widely miscited as BSL/MIT; source-available, not permissive",
"claim": "directus/directus supplies admin_data, airtable_data, files_documents at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,connectors,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-050record 50
{
"id": "OSS-050",
"repo": "docmost/docmost",
"url": "https://github.com/docmost/docmost",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/docmost/docmost API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 21480,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 321,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 14038
},
"adaptation_risks": "AGPL-3.0 verified; the closest Notion-like TS/React fit but copyleft",
"claim": "docmost/docmost supplies notes_docs, portal at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Docmost is a Notion-style team wiki — collaborative internal documentation with workspace/space membership, not an external-identity surface. Same reasoning as BookStack: shared internal editing is not scoped external read plus request submission. Retains notes_docs.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-051record 51
{
"id": "OSS-051",
"repo": "documenso/documenso",
"url": "https://github.com/documenso/documenso",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/documenso/documenso API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"e_sign",
"approvals_workflow",
"case_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 14777,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 255,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 287956
},
"adaptation_risks": "AGPL-3.0 confirmed; closest e-sign fit but copyleft blocks source reuse in a client deliverable",
"claim": "documenso/documenso supplies e_sign, approvals_workflow, case_workflow at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+host_chrome, containerized monorepo; full DocuSign-class signing product with signer identity and audit trail -> product"
}
OSS-052record 52
{
"id": "OSS-052",
"repo": "dotCMS/core",
"url": "https://github.com/dotCMS/core",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSL-style with $5M revenue cap",
"license_class": "source-available",
"license_evidence": "LICENSE body read: \"Additional Use Grant: You may use the Licensed Work in Production ... as long as your Total Finances do not exceed US $5,000,000\"",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 948,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 1084,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1182463
},
"adaptation_risks": "BSL-style license with a $5M revenue cap read from LICENSE — a per-client legal check, not a shelf item",
"claim": "dotCMS/core supplies notes_docs, portal at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. dotCMS is a content management platform; the 'portal' framing upstream is marketing for content delivery, not the authorization archetype. No external-requester identity model observed. Retains notes_docs. Row remains a reject on licence grounds (BSL-style $5M revenue cap) independently of this re-tag.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-053record 53
{
"id": "OSS-053",
"repo": "drizzle-team/drizzle-orm",
"url": "https://github.com/drizzle-team/drizzle-orm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/drizzle-team/drizzle-orm API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 35601,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1987,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 57587
},
"adaptation_risks": "Apache-2.0 verified clean; TS-native, lighter than Prisma",
"claim": "drizzle-team/drizzle-orm supplies admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data], extracted_package; an ORM -> primitive"
}
OSS-054record 54
{
"id": "OSS-054",
"repo": "elastic/elasticsearch",
"url": "https://github.com/elastic/elasticsearch",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 / SSPL / ELv2 triple + Apache parts",
"license_class": "source-available",
"license_evidence": "LICENSE.txt body read: \"triple license under the GNU Affero General Public License v3.0 only, the Server Side Public License, v 1, and the Elastic License 2.0\"",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 77869,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 5947,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1731463
},
"adaptation_risks": "AGPL/SSPL/ELv2 triple per LICENSE.txt — SSPL and ELv2 both hostile to hosted client delivery",
"claim": "elastic/elasticsearch supplies search at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search engine, the UI (Kibana) is a separate product -> primitive"
}
OSS-055record 55
{
"id": "OSS-055",
"repo": "espocrm/espocrm",
"url": "https://github.com/espocrm/espocrm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/espocrm/espocrm API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3299,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 64,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 90462
},
"adaptation_risks": "AGPL-3.0 verified; PHP, mature and actively maintained",
"claim": "espocrm/espocrm supplies crm at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-056record 56
{
"id": "OSS-056",
"repo": "ever-co/ever-gauzy",
"url": "https://github.com/ever-co/ever-gauzy",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/ever-co/ever-gauzy API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm",
"project_management",
"field_ops"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4349,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 455,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 262302
},
"adaptation_risks": "AGPL-3.0 verified; broad ERP surface, Angular/Nest",
"claim": "ever-co/ever-gauzy supplies crm, project_management, field_ops at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-057record 57
{
"id": "OSS-057",
"repo": "ever-co/ever-teams",
"url": "https://github.com/ever-co/ever-teams",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/ever-co/ever-teams API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 545,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 237,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 70568
},
"adaptation_risks": "AGPL-3.0 verified; 545 stars",
"claim": "ever-co/ever-teams supplies project_management at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows a large app monorepo with .env.docker/.env.compose deployment configs; the runnable Ever Teams work app -> product"
}
OSS-058record 58
{
"id": "OSS-058",
"repo": "evidence-dev/evidence",
"url": "https://github.com/evidence-dev/evidence",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/evidence-dev/evidence API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 6884,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 24,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 315447
},
"adaptation_risks": "MIT verified clean; markdown-driven BI, small clean seam",
"claim": "evidence-dev/evidence supplies analytics_bi at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows cli/ + core/ + packages via pnpm-workspace, no deployable server; a BI-as-code framework you author a project in -> framework"
}
OSS-059record 59
{
"id": "OSS-059",
"repo": "excalidraw/excalidraw",
"url": "https://github.com/excalidraw/excalidraw",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/excalidraw/excalidraw API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 130613,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 3408,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 102887
},
"adaptation_risks": "MIT verified clean; whiteboard canvas as an embeddable React component",
"claim": "excalidraw/excalidraw supplies notes_docs at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only, extracted_package; a canvas drawing component published as an npm package (the hosted app is separate) -> primitive"
}
OSS-060record 60
{
"id": "OSS-060",
"repo": "firefly-iii/firefly-iii",
"url": "https://github.com/firefly-iii/firefly-iii",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/firefly-iii/firefly-iii API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 24428,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 165,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 318975
},
"adaptation_risks": "AGPL-3.0 verified; personal finance, not B2B finance ops",
"claim": "firefly-iii/firefly-iii supplies billing at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-061record 61
{
"id": "OSS-061",
"repo": "flowable/flowable-engine",
"url": "https://github.com/flowable/flowable-engine",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/flowable/flowable-engine API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow",
"case_workflow"
],
"composite_contents": [
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 9495,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 404,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 242021
},
"adaptation_risks": "Apache-2.0 verified; BPMN/CMMN engine — CMMN is a genuine case_workflow primitive. Java",
"claim": "flowable/flowable-engine supplies approvals_workflow, case_workflow at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow, no ui; a BPMN engine library embedded in your Java app -> primitive"
}
OSS-062record 62
{
"id": "OSS-062",
"repo": "formbricks/formbricks",
"url": "https://github.com/formbricks/formbricks",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 core + commercial ee/ + MIT SDK packages",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE body read: apps/web/modules/ee under separate ee LICENSE; packages/js|android|ios|api carved out separately",
"capability_kinds": [
"forms",
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 12829,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 234,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 385503
},
"adaptation_risks": "AGPL core confirmed by LICENSE read — prior sweep called this permissive; ee/ carve-out on top",
"claim": "formbricks/formbricks supplies forms, analytics_bi at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-063record 63
{
"id": "OSS-063",
"repo": "formio/formio",
"url": "https://github.com/formio/formio",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "OSL-3.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/formio/formio API license.spdx_id = OSL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 2312,
"pushed_at": "2026-08-11",
"days_since_push": 16,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 62,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 25549
},
"adaptation_risks": "OSL-3.0 — a strong-ish copyleft that is rare and legally awkward; enterprise server is separate",
"claim": "formio/formio supplies forms at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows server.js + main.js + src/ + portal/ + install.js + docker-compose.yml; a deployable form/API server with auth -> product"
}
OSS-064record 64
{
"id": "OSS-064",
"repo": "frappe/crm",
"url": "https://github.com/frappe/crm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/crm API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3402,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Vue",
"open_issues": 305,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 112521
},
"adaptation_risks": "AGPL-3.0 verified; needs the Frappe runtime",
"claim": "frappe/crm supplies crm at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-065record 65
{
"id": "OSS-065",
"repo": "frappe/drive",
"url": "https://github.com/frappe/drive",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/drive API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 732,
"pushed_at": "2026-07-01",
"days_since_push": 57,
"maintenance": "active",
"archived": true,
"primary_language": "Vue",
"open_issues": 58,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 44343
},
"adaptation_risks": "ARCHIVED (archived:true), last push 2026-07-01",
"claim": "frappe/drive supplies files_documents at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows drive/ (Frappe app) + frontend/ + docker/ + pyproject.toml; deployable file-sharing product -> product"
}
OSS-066record 66
{
"id": "OSS-066",
"repo": "frappe/erpnext",
"url": "https://github.com/frappe/erpnext",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/erpnext API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory",
"billing",
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 38558,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 1825,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1863531
},
"adaptation_risks": "GPL-3.0 verified; requires the whole Frappe runtime",
"claim": "frappe/erpnext supplies inventory, billing, crm at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-067record 67
{
"id": "OSS-067",
"repo": "frappe/helpdesk",
"url": "https://github.com/frappe/helpdesk",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/helpdesk API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3341,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Vue",
"open_issues": 190,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 63530
},
"adaptation_risks": "AGPL-3.0 verified; Frappe runtime dependency",
"claim": "frappe/helpdesk supplies support_desk at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-068record 68
{
"id": "OSS-068",
"repo": "frappe/hrms",
"url": "https://github.com/frappe/hrms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/hrms API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"case_workflow",
"field_ops"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 8680,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 494,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 91374
},
"adaptation_risks": "GPL-3.0 confirmed; also requires the whole Frappe/ERPNext runtime — not extractable standalone",
"claim": "frappe/hrms supplies case_workflow, field_ops at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-069record 69
{
"id": "OSS-069",
"repo": "frappe/insights",
"url": "https://github.com/frappe/insights",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/insights API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 1009,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 216,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 55477
},
"adaptation_risks": "AGPL-3.0 verified; Frappe runtime dependency",
"claim": "frappe/insights supplies analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows insights/ (Frappe app) + frontend/ + docker/ + pyproject.toml; deployable BI product on the Frappe platform -> product"
}
OSS-070record 70
{
"id": "OSS-070",
"repo": "frappe/lms",
"url": "https://github.com/frappe/lms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/frappe/lms API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3167,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 100,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 106225
},
"adaptation_risks": "AGPL-3.0 verified; Frappe runtime dependency",
"claim": "frappe/lms supplies lms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-071record 71
{
"id": "OSS-071",
"repo": "freescout-help-desk/freescout",
"url": "https://github.com/freescout-help-desk/freescout",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/freescout-help-desk/freescout API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4508,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 32,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 27905
},
"adaptation_risks": "AGPL-3.0 verified; PHP; module ecosystem is paid",
"claim": "freescout-help-desk/freescout supplies support_desk at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-072record 72
{
"id": "OSS-072",
"repo": "getlago/lago",
"url": "https://github.com/getlago/lago",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/getlago/lago API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 10418,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 26,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 156219
},
"adaptation_risks": "AGPL-3.0 verified; identity is getlago/lago not lago-money/lago",
"claim": "getlago/lago supplies billing at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, containerized; deployable billing product -> product"
}
OSS-073record 73
{
"id": "OSS-073",
"repo": "gitlabhq/gitlabhq",
"url": "https://github.com/gitlabhq/gitlabhq",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial ee/ and jh/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: ee/ and jh/ under their own LICENSE files, doc/ CC BY-SA 4.0, remainder permissive",
"capability_kinds": [
"project_management",
"case_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 24540,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 36,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2817714
},
"adaptation_risks": "MIT outside ee/ and jh/ per LICENSE body; enormous Rails monolith",
"claim": "gitlabhq/gitlabhq supplies project_management, case_workflow at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. The root MIT applies to Community Edition only while `ee/` holds the proprietary slice, and the repo is a Rails monolith of exceptional size (`app/`, `lib/`, `qa/`, `workhorse/`, `gems/`, dual Gemfiles). Nothing here is liftable at client scale; the issue/board workflow model is the takeaway.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-074record 74
{
"id": "OSS-074",
"repo": "glpi-project/glpi",
"url": "https://github.com/glpi-project/glpi",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/glpi-project/glpi API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk",
"inventory",
"field_ops"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 6272,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 494,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1117053
},
"adaptation_risks": "GPL-3.0 verified; ITSM+asset, mature",
"claim": "glpi-project/glpi supplies support_desk, inventory, field_ops at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-075record 75
{
"id": "OSS-075",
"repo": "grafana/grafana",
"url": "https://github.com/grafana/grafana",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/grafana/grafana API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 76446,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 3333,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1947192
},
"adaptation_risks": "AGPL-3.0 verified; relicensed from Apache in 2021",
"claim": "grafana/grafana supplies analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-076record 76
{
"id": "OSS-076",
"repo": "grocy/grocy",
"url": "https://github.com/grocy/grocy",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/grocy/grocy API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 9430,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Blade",
"open_issues": 134,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 24426
},
"adaptation_risks": "MIT verified clean but household/groceries domain — wrong denominator for B2B",
"claim": "grocy/grocy supplies inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Self-contained PHP app: `app.php`, `routes.php`, `controllers/`, `services/`, `views/`, `migrations/`, `config-dist.php` and a published `grocy.openapi.json`, MIT-licensed. A small deployable inventory service with a documented API — run it intact and integrate over the API.",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows controllers/ services/ migrations/ routes.php views/ + config-dist.php; a deployable household ERP product -> product"
}
OSS-077record 77
{
"id": "OSS-077",
"repo": "grokability/snipe-it",
"url": "https://github.com/grokability/snipe-it",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/grokability/snipe-it API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 14877,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 955,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 320285
},
"adaptation_risks": "AGPL-3.0 verified; identity moved from snipe/snipe-it",
"claim": "grokability/snipe-it supplies inventory at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"snipe/snipe-it"
],
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-078record 78
{
"id": "OSS-078",
"repo": "hasura/graphql-engine",
"url": "https://github.com/hasura/graphql-engine",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/hasura/graphql-engine API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 32099,
"pushed_at": "2026-08-19",
"days_since_push": 8,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 2373,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 5198460
},
"adaptation_risks": "Apache-2.0 at root, but v3/DDN moved to a different model — verify per-version before adopting",
"claim": "hasura/graphql-engine supplies admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Ships `docker-compose.yaml`, `docker-compose/`, `install-manifests/` and a compiled Haskell `server/` under Apache-2.0. The product is a deployable GraphQL gateway over an existing database; you deploy it and point it at Postgres, you do not reimplement it.",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+auth, no ui; a GraphQL API layer over your DB -> primitive"
}
OSS-079record 79
{
"id": "OSS-079",
"repo": "hcengineering/platform",
"url": "https://github.com/hcengineering/platform",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "EPL-2.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/hcengineering/platform API license.spdx_id = EPL-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management",
"crm",
"support_desk",
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 27471,
"pushed_at": "2026-08-11",
"days_since_push": 16,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 848,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 313861
},
"adaptation_risks": "EPL-2.0 weak copyleft; Huly platform — unusually broad capability bundle in one TS monorepo",
"claim": "hcengineering/platform supplies project_management, crm, support_desk, notes_docs at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+host_chrome, monorepo; Huly is a deployable all-in-one work product -> product"
}
OSS-080record 80
{
"id": "OSS-080",
"repo": "helpyio/helpy",
"url": "https://github.com/helpyio/helpy",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/helpyio/helpy API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 2472,
"pushed_at": "2023-03-08",
"days_since_push": 1268,
"maintenance": "stale",
"archived": false,
"primary_language": "Ruby",
"open_issues": 230,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 90540
},
"adaptation_risks": "MIT is clean but last push 2023-03-08 — roughly three years stale",
"claim": "helpyio/helpy supplies support_desk at stale maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. Rights are fine (permissive) but maintenance is stale and the repo is a full Rails 5-era app carrying `bower.json`, `.travis.yml` and a vendored tree. Adopting a stale Ruby monolith imports the maintenance burden; take the ticket/knowledge-base model instead.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-081record 81
{
"id": "OSS-081",
"repo": "heyform/heyform",
"url": "https://github.com/heyform/heyform",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/heyform/heyform API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 8951,
"pushed_at": "2026-08-19",
"days_since_push": 8,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 9,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 176156
},
"adaptation_risks": "AGPL-3.0 verified; TS monorepo",
"claim": "heyform/heyform supplies forms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-082record 82
{
"id": "OSS-082",
"repo": "instructure/canvas-lms",
"url": "https://github.com/instructure/canvas-lms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/instructure/canvas-lms API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 6784,
"pushed_at": "2026-04-30",
"days_since_push": 119,
"maintenance": "slowing",
"archived": false,
"primary_language": "Ruby",
"open_issues": 466,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2263312
},
"adaptation_risks": "AGPL-3.0 verified; canvas-lms/canvas-lms does not resolve — instructure/canvas-lms is canonical",
"claim": "instructure/canvas-lms supplies lms at slowing maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-083record 83
{
"id": "OSS-083",
"repo": "inventree/InvenTree",
"url": "https://github.com/inventree/InvenTree",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/inventree/InvenTree API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 7457,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 192,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 362698
},
"adaptation_risks": "MIT verified clean; Python/Django, active, real stock-movement ledger. The cleanest-rights inventory system found",
"claim": "inventree/InvenTree supplies inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 6,
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-084record 84
{
"id": "OSS-084",
"repo": "invoiceninja/invoiceninja",
"url": "https://github.com/invoiceninja/invoiceninja",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Elastic License 2.0",
"license_class": "source-available",
"license_evidence": "LICENSE body read: verbatim \"Elastic License 2.0 (ELv2)\" — hosting/managed-service limitation applies",
"capability_kinds": [
"billing"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 10029,
"pushed_at": "2026-08-25",
"days_since_push": 2,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 926,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 4234944
},
"adaptation_risks": "ELv2 confirmed from LICENSE body — hosting restriction is fatal for client delivery",
"claim": "invoiceninja/invoiceninja supplies billing at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-085record 85
{
"id": "OSS-085",
"repo": "ixartz/SaaS-Boilerplate",
"url": "https://github.com/ixartz/SaaS-Boilerplate",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/ixartz/SaaS-Boilerplate API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"billing"
],
"composite_contents": [
"ui",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 7381,
"pushed_at": "2026-08-21",
"days_since_push": 6,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 6730
},
"adaptation_risks": "Scaffold with no domain model; Clerk/Stripe vendor coupling baked in",
"claim": "ixartz/SaaS-Boilerplate supplies auth_identity, billing at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows src/ + migrations/ + drizzle.config.ts + tests, a Next.js starter template you fork and fill in; substrate not finished product -> framework"
}
OSS-086record 86
{
"id": "OSS-086",
"repo": "jentic/jentic-sdks",
"url": "https://github.com/jentic/jentic-sdks",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/jentic/jentic-sdks API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"connectors"
],
"composite_contents": [
"connectors"
],
"composite_repo": false,
"reuse_shape_recommendation": "adapter",
"quality_signals": {
"stars": 25,
"pushed_at": "2026-06-12",
"days_since_push": 76,
"maintenance": "slowing",
"archived": true,
"primary_language": "Python",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 571
},
"adaptation_risks": "ARCHIVED (archived:true) with 25 stars; dead supply",
"claim": "jentic/jentic-sdks supplies connectors at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Top level is only `mcp/` and `python/` beside LICENSE/NOTICE — this is a thin client SDK to Jentic's hosted API, not a connector corpus. If used at all its shape is an adapter wrapping an external service; that framing is also why the row stays a reject.",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[connectors], adapter shape, 571 kb, 25 stars; an SDK -> primitive"
}
OSS-087record 87
{
"id": "OSS-087",
"repo": "kaleidos-ventures/taiga",
"url": "https://github.com/kaleidos-ventures/taiga",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MPL-2.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/kaleidos-ventures/taiga API license.spdx_id = MPL-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 569,
"pushed_at": "2023-12-13",
"days_since_push": 988,
"maintenance": "stale",
"archived": false,
"primary_language": "Python",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 84834
},
"adaptation_risks": "MPL-2.0 clean but last push 2023-12-13; identity moved from taigaio/taiga",
"claim": "kaleidos-ventures/taiga supplies project_management at stale maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"taigaio/taiga"
],
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-088record 88
{
"id": "OSS-088",
"repo": "kanboard/kanboard",
"url": "https://github.com/kanboard/kanboard",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/kanboard/kanboard API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 9826,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 160,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 76812
},
"adaptation_risks": "MIT verified clean, actively pushed; simple PHP, easy to reason about",
"claim": "kanboard/kanboard supplies project_management at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-089record 89
{
"id": "OSS-089",
"repo": "kestra-io/kestra",
"url": "https://github.com/kestra-io/kestra",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/kestra-io/kestra API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 27934,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 703,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 132133
},
"adaptation_risks": "Apache-2.0 verified; Java, declarative YAML orchestration",
"claim": "kestra-io/kestra supplies approvals_workflow at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+host_chrome, containerized intact_service; deployable orchestrator with its own UI -> product"
}
OSS-090record 90
{
"id": "OSS-090",
"repo": "keycloak/keycloak",
"url": "https://github.com/keycloak/keycloak",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/keycloak/keycloak API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"data",
"auth",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 36441,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 3125,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 608933
},
"adaptation_risks": "Apache-2.0 verified; heavyweight Java IdP, deploy-alongside not embed",
"claim": "keycloak/keycloak supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents data+auth+host_chrome; a deployable IdP with its own admin console and account UI -> product"
}
OSS-091record 91
{
"id": "OSS-091",
"repo": "keystonejs/keystone",
"url": "https://github.com/keystonejs/keystone",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/keystonejs/keystone API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data",
"airtable_data"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 9963,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 137,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 384529
},
"adaptation_risks": "MIT verified clean; schema-driven CRUD + generated admin UI, TS-native",
"claim": "keystonejs/keystone supplies admin_data, airtable_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 8,
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + examples/ + tests/ with no app entrypoint; a headless CMS/admin framework you build your product on -> framework"
}
OSS-092record 92
{
"id": "OSS-092",
"repo": "kiegroup/jbpm",
"url": "https://github.com/kiegroup/jbpm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "contents API: root file LICENSE-Apache-2.0.txt (11358b) present; /license endpoint empty because filename is non-standard",
"capability_kinds": [
"approvals_workflow",
"case_workflow"
],
"composite_contents": [
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 1739,
"pushed_at": "2026-07-01",
"days_since_push": 57,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 44,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 336692
},
"adaptation_risks": "Apache-2.0 confirmed via non-standard root filename; last push 2026-07-01, slowing",
"claim": "kiegroup/jbpm supplies approvals_workflow, case_workflow at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Maven reactor of ~25 discrete `jbpm-*` modules (`jbpm-flow`, `jbpm-human-task`, `jbpm-case-mgmt`, `jbpm-workitems`) under Apache-2.0. Individual artifacts are consumable from Maven Central, so the honest shape is extracted_package rather than reimplementation.",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow, extracted_package; a BPM engine library -> primitive"
}
OSS-093record 93
{
"id": "OSS-093",
"repo": "killbill/killbill",
"url": "https://github.com/killbill/killbill",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/killbill/killbill API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing"
],
"composite_contents": [
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 5707,
"pushed_at": "2026-08-22",
"days_since_push": 5,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 267,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 682597
},
"adaptation_risks": "Apache-2.0 verified; mature subscription billing engine. Java, no UI in this repo",
"claim": "killbill/killbill supplies billing at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow, no ui; a billing platform core consumed via API/plugins (KAUI admin is separate) -> primitive"
}
OSS-094record 94
{
"id": "OSS-094",
"repo": "knadh/listmonk",
"url": "https://github.com/knadh/listmonk",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/knadh/listmonk API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 23143,
"pushed_at": "2026-08-25",
"days_since_push": 2,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 111,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 52307
},
"adaptation_risks": "AGPL-3.0 verified; Go, single-binary newsletter",
"claim": "knadh/listmonk supplies messaging_notifications at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows cmd/ + frontend/ + schema.sql + queries.sql + docker-compose.yml; deployable newsletter product with its own admin -> product"
}
OSS-095record 95
{
"id": "OSS-095",
"repo": "lightdash/lightdash",
"url": "https://github.com/lightdash/lightdash",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: packages/backend/src/ee under its own LICENSE; remainder permissive",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 6091,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1039,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 537277
},
"adaptation_risks": "MIT core with ee/ carve-out; dbt-coupled",
"claim": "lightdash/lightdash supplies analytics_bi at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern for rights reasons: MIT root, but `packages/` splits into community and paid tiers and the row is already classed permissive-open-core. The client value is the semantic-layer/metrics modelling approach, not a fork of the dbt-coupled BI stack.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-096record 96
{
"id": "OSS-096",
"repo": "logseq/logseq",
"url": "https://github.com/logseq/logseq",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/logseq/logseq API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 44650,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Clojure",
"open_issues": 952,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 179447
},
"adaptation_risks": "AGPL-3.0; ClojureScript stack is a hiring/maintenance risk",
"claim": "logseq/logseq supplies notes_docs at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows src/ deps/ android/ ios/ + Dockerfile + capacitor.config.ts; a runnable notes application (desktop/mobile) -> product"
}
OSS-097record 97
{
"id": "OSS-097",
"repo": "lucia-auth/lucia",
"url": "https://github.com/lucia-auth/lucia",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/lucia-auth/lucia API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 10450,
"pushed_at": "2026-08-08",
"days_since_push": 19,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 24,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 5916
},
"adaptation_risks": "MIT, but the library was deprecated in favour of a learning resource — check current shape before adopting",
"claim": "lucia-auth/lucia supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Repo is `code/` plus a `lucia-auth.com` docs site under MIT — a published session-management library. Since v3 upstream positions it as a learning resource, but it is still consumed as a package, so extracted_package is the accurate seam.",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[auth] only, extracted_package, 5916 kb; an auth library/reference -> primitive"
}
OSS-098record 98
{
"id": "OSS-098",
"repo": "maildev/maildev",
"url": "https://github.com/maildev/maildev",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/maildev/maildev API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 6035,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 40,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 23468
},
"adaptation_risks": "MIT clean but a dev-only SMTP catcher, not production infra",
"claim": "maildev/maildev supplies messaging_notifications at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Root `Dockerfile`, `.devcontainer/` and a `packages/` npm workspace under MIT. MailDev is a dev-only SMTP capture service you run beside the app — deploy the container intact; there is nothing to reimplement.",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows packages/ + Dockerfile, runs as a standalone SMTP-catching web app; deployable dev-mail product -> product"
}
OSS-099record 99
{
"id": "OSS-099",
"repo": "manticoresoftware/manticoresearch",
"url": "https://github.com/manticoresoftware/manticoresearch",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/manticoresoftware/manticoresearch API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 11956,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "C++",
"open_issues": 722,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 106944
},
"adaptation_risks": "GPL-3.0 verified",
"claim": "manticoresoftware/manticoresearch supplies search at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search engine -> primitive"
}
OSS-100record 100
{
"id": "OSS-100",
"repo": "marmelab/atomic-crm",
"url": "https://github.com/marmelab/atomic-crm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/marmelab/atomic-crm API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 1206,
"pushed_at": "2026-08-21",
"days_since_push": 6,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 24,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 47730
},
"adaptation_risks": "Supabase-coupled; small demo-grade surface, thin domain depth",
"claim": "marmelab/atomic-crm supplies crm at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows full Vite app (index.html, src/, supabase/ migrations, e2e/, demo/); a runnable CRM built on react-admin, deployable as-is -> product"
}
OSS-101record 101
{
"id": "OSS-101",
"repo": "marmelab/react-admin",
"url": "https://github.com/marmelab/react-admin",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/marmelab/react-admin API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data",
"crm"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 26915,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 74,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 449314
},
"adaptation_risks": "Framework; MIT core but enterprise modules are a separate paid package (ra-enterprise)",
"claim": "marmelab/react-admin supplies admin_data, crm, portal at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Observed repos/marmelab/react-admin/contents/packages = ra-core, ra-ui-materialui, ra-data-json-server, ra-data-graphql, ra-data-simple-rest, ra-data-fakerest, ra-data-local-storage and similar — DATA-PROVIDER adapters plus a CRUD UI kit for building trusted-staff admin screens. It ships no identity product at all: authProvider is an interface the integrator implements. Retains admin_data and crm.",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents ui+data+auth but extracted_package monorepo of npm packages; an admin-UI framework you assemble a product from -> framework"
}
OSS-102record 102
{
"id": "OSS-102",
"repo": "matomo-org/matomo",
"url": "https://github.com/matomo-org/matomo",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/matomo-org/matomo API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 21809,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 2568,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 369903
},
"adaptation_risks": "GPL-3.0 verified",
"claim": "matomo-org/matomo supplies analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-103record 103
{
"id": "OSS-103",
"repo": "mattermost-community/focalboard",
"url": "https://github.com/mattermost-community/focalboard",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 source / MIT compiled",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE.txt body read: Mattermost licensing; compiled MIT, source AGPL v3.0 with exceptions",
"capability_kinds": [
"project_management",
"airtable_data"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 26434,
"pushed_at": "2026-05-18",
"days_since_push": 101,
"maintenance": "slowing",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 784,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 59223
},
"adaptation_risks": "AGPL source per LICENSE.txt; identity moved from mattermost/focalboard and upstream is effectively wound down (last push 2026-05-18)",
"claim": "mattermost-community/focalboard supplies project_management, airtable_data at slowing maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"mattermost/focalboard"
],
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows server/ + webapp/ + docker/ + Makefile; deployable project/board product -> product"
}
OSS-104record 104
{
"id": "OSS-104",
"repo": "mattermost/mattermost",
"url": "https://github.com/mattermost/mattermost",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 source / MIT compiled + commercial",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE.txt body read: compiled binaries MIT; source under \"GNU AGPL v3.0, subject to the exceptions\" or a commercial subscription",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 38910,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 978,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1274456
},
"adaptation_risks": "AGPL source / MIT compiled per LICENSE.txt; source reuse is copyleft",
"claim": "mattermost/mattermost supplies messaging_notifications at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-105record 105
{
"id": "OSS-105",
"repo": "mautic/mautic",
"url": "https://github.com/mautic/mautic",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0-or-later",
"license_class": "strong-copyleft",
"license_evidence": "LICENSE.txt body read: \"GNU General Public License ... either version 3 of the License, or (at your option) any later version\"",
"capability_kinds": [
"crm",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 10396,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 188,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 307402
},
"adaptation_risks": "GPL-3.0 per LICENSE.txt body; marketing automation",
"claim": "mautic/mautic supplies crm, messaging_notifications at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-106record 106
{
"id": "OSS-106",
"repo": "medusajs/medusa",
"url": "https://github.com/medusajs/medusa",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT + Enterprise Edition carve-out",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: \"Except for the Enterprise Edition materials identified in ENTERPRISE-LICENSE.md, the repository is licensed under the MIT License\"",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"data",
"workflow",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 36023,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 180,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 870682
},
"adaptation_risks": "MIT except Enterprise Edition materials per LICENSE body; headless, TS-native, strong module seams",
"claim": "medusajs/medusa supplies e_commerce, inventory at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 4,
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents lacks ui, embedded_module monorepo of npm packages; a headless commerce framework you build a storefront on -> framework"
}
OSS-107record 107
{
"id": "OSS-107",
"repo": "meilisearch/meilisearch",
"url": "https://github.com/meilisearch/meilisearch",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT AND BUSL-1.1",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: explicit \"SPDX-License-Identifier: MIT AND BUSL-1.1\"; EE parts BSL 1.1, rest MIT",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 59105,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 318,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 91460
},
"adaptation_risks": "MIT AND BUSL-1.1 per LICENSE; the MIT core is usable, EE parts are BSL",
"claim": "meilisearch/meilisearch supplies search at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search engine consumed via API -> primitive"
}
OSS-108record 108
{
"id": "OSS-108",
"repo": "metabase/metabase",
"url": "https://github.com/metabase/metabase",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 + Metabase Commercial (enterprise/)",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE.txt body read: outside top-level \"enterprise\" dir = AGPL; inside = Metabase Commercial License",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 48955,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Clojure",
"open_issues": 4497,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2234878
},
"adaptation_risks": "AGPL outside enterprise/ per LICENSE.txt; Clojure backend",
"claim": "metabase/metabase supplies analytics_bi at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-109record 109
{
"id": "OSS-109",
"repo": "minio/minio",
"url": "https://github.com/minio/minio",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/minio/minio API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 61372,
"pushed_at": "2026-04-24",
"days_since_push": 125,
"maintenance": "slowing",
"archived": true,
"primary_language": "Go",
"open_issues": 80,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 125263
},
"adaptation_risks": "ARCHIVED (archived:true, last push 2026-04-24) and AGPL-3.0",
"claim": "minio/minio supplies files_documents at slowing maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only; an S3-compatible object-storage engine, infrastructure not an end-user document product -> primitive"
}
OSS-110record 110
{
"id": "OSS-110",
"repo": "moasq/production-saas-starter",
"url": "https://github.com/moasq/production-saas-starter",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/moasq/production-saas-starter API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"billing",
"case_workflow"
],
"composite_contents": [
"ui",
"data",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 530,
"pushed_at": "2026-01-25",
"days_since_push": 214,
"maintenance": "slowing",
"archived": false,
"primary_language": "Go",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": false,
"containerized": true,
"repo_size_kb": 1452
},
"adaptation_risks": "Go primary language despite SaaS-starter framing; 530 stars",
"claim": "moasq/production-saas-starter supplies auth_identity, billing, case_workflow at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "transplant shape, 1452 kb, 530 stars; a Go SaaS starter template, substrate for building a product -> framework"
}
OSS-111record 111
{
"id": "OSS-111",
"repo": "moodle/moodle",
"url": "https://github.com/moodle/moodle",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/moodle/moodle API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 7356,
"pushed_at": "2026-08-18",
"days_since_push": 9,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 2,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 966072
},
"adaptation_risks": "GPL-3.0 verified; the LMS incumbent but a very large legacy PHP codebase",
"claim": "moodle/moodle supplies lms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-112record 112
{
"id": "OSS-112",
"repo": "mozilla/pdf.js",
"url": "https://github.com/mozilla/pdf.js",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/mozilla/pdf.js API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 53788,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 418,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 194747
},
"adaptation_risks": "Apache-2.0 verified clean; PDF rendering primitive",
"claim": "mozilla/pdf.js supplies files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only, extracted_package; a PDF rendering library -> primitive"
}
OSS-113record 113
{
"id": "OSS-113",
"repo": "n8n-io/n8n",
"url": "https://github.com/n8n-io/n8n",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Sustainable Use License + enterprise .ee files",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: non-main branches \"are not licensed\"; files with \".ee.\" require a valid n8n Enterprise License",
"capability_kinds": [
"approvals_workflow",
"connectors",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 202568,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1105,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 543648
},
"adaptation_risks": "Sustainable Use License; non-main branches explicitly \"not licensed\"; .ee files need an enterprise key",
"claim": "n8n-io/n8n supplies approvals_workflow, connectors, messaging_notifications at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+connectors+host_chrome, containerized monorepo; deployable automation product (source-available) -> product"
}
OSS-114record 114
{
"id": "OSS-114",
"repo": "netdata/netdata",
"url": "https://github.com/netdata/netdata",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/netdata/netdata API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 80316,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 388,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 306707
},
"adaptation_risks": "GPL-3.0 verified; infrastructure monitoring, not business analytics",
"claim": "netdata/netdata supplies analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows src/ + system/ + packaging/ + netdata-installer.sh + Dockerfile; a deployable monitoring product with its own dashboard -> product"
}
OSS-115record 115
{
"id": "OSS-115",
"repo": "nextauthjs/next-auth",
"url": "https://github.com/nextauthjs/next-auth",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "ISC",
"license_class": "permissive",
"license_evidence": "repos/nextauthjs/next-auth API license.spdx_id = ISC; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 28345,
"pushed_at": "2026-07-22",
"days_since_push": 36,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 598,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 70532
},
"adaptation_risks": "ISC verified clean; the default JS/TS auth seam. Next.js-centric",
"claim": "nextauthjs/next-auth supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[auth] only, extracted_package; an auth library for Next.js -> primitive"
}
OSS-116record 116
{
"id": "OSS-116",
"repo": "nextcloud/server",
"url": "https://github.com/nextcloud/server",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/nextcloud/server API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents",
"portal"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 36598,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 3659,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 6980117
},
"adaptation_risks": "AGPL-3.0 verified; PHP, very large",
"claim": "nextcloud/server supplies files_documents, portal at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag KEPT, narrowly and on observed evidence. repos/nextcloud/server/contents/apps includes files_sharing, sharebymail, federatedfilesharing, oauth2 and user_ldap — Nextcloud genuinely models an external recipient who authenticates against a share, receives scoped read of only what was shared, and can upload (File Drop) as a request-submission path. It qualifies as an external-identity surface, but it is a file-sharing product rather than a purpose-built portal, so it must not be read as supplying the archetype whole. Retains files_documents.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-117record 117
{
"id": "OSS-117",
"repo": "nhost/nhost",
"url": "https://github.com/nhost/nhost",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/nhost/nhost API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"files_documents"
],
"composite_contents": [
"data",
"auth",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 9280,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 138,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 753031
},
"adaptation_risks": "MIT verified; Hasura-coupled, and Hasura itself changed licensing",
"claim": "nhost/nhost supplies auth_identity, files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Root carries `docker-compose`-adjacent `build/`, `services/`, `cli/`, `dashboard/` and Nix flakes under MIT. Nhost is a deployable backend-as-a-service bundling Hasura + auth + storage; the defensible use is standing up the stack, not rewriting it.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents data+auth+host_chrome, containerized; deployable BaaS stack -> product (developer platform)"
}
OSS-118record 118
{
"id": "OSS-118",
"repo": "nocodb/nocodb",
"url": "https://github.com/nocodb/nocodb",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Sustainable Use License",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: \"Content in the \"master\" branch is available under the \"Sustainable Use License\"\" — non-compete internal-business-use restriction",
"capability_kinds": [
"airtable_data",
"admin_data"
],
"composite_contents": [
"ui",
"data",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 64752,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 715,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1467311
},
"adaptation_risks": "Sustainable Use License (read from LICENSE.md) — non-compete clause blocks the obvious client use",
"claim": "nocodb/nocodb supplies airtable_data, admin_data at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,connectors,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-119record 119
{
"id": "OSS-119",
"repo": "novuhq/novu",
"url": "https://github.com/novuhq/novu",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial enterprise/packages",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE-ENTERPRISE body read: enterprise/packages under EE-PACKAGES-LICENSE; remainder permissive",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 39678,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 100,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 490559
},
"adaptation_risks": "MIT outside enterprise/packages per LICENSE-ENTERPRISE; notification infra is a clean seam for portals/case updates",
"claim": "novuhq/novu supplies messaging_notifications at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows apps/ + packages/ + docker/ + libs; apps/ contains the deployable notification API and web dashboard -> product"
}
OSS-120record 120
{
"id": "OSS-120",
"repo": "odoo/odoo",
"url": "https://github.com/odoo/odoo",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "LGPL-3.0",
"license_class": "weak-copyleft",
"license_evidence": "LICENSE body read: \"Odoo is published under the GNU LESSER GENERAL PUBLIC LICENSE, Version 3 (LGPLv3)\"",
"capability_kinds": [
"crm",
"inventory",
"billing",
"case_workflow",
"field_ops"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 53979,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 10430,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 17395142
},
"adaptation_risks": "LGPL-3.0 per LICENSE body; enterprise modules are a separate proprietary repo. Huge Python monolith",
"claim": "odoo/odoo supplies crm, inventory, billing, case_workflow, field_ops at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,connectors,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-121record 121
{
"id": "OSS-121",
"repo": "ohmyform/ohmyform",
"url": "https://github.com/ohmyform/ohmyform",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/ohmyform/ohmyform API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 2892,
"pushed_at": "2024-10-31",
"days_since_push": 665,
"maintenance": "stale",
"archived": true,
"primary_language": "TypeScript",
"open_issues": 56,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 24008
},
"adaptation_risks": "ARCHIVED (archived:true), last push 2024-10-31",
"claim": "ohmyform/ohmyform supplies forms at stale maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows api/ + ui/ + docker-compose.yml + Procfile; deployable forms product -> product"
}
OSS-122record 122
{
"id": "OSS-122",
"repo": "open-formulieren/open-forms",
"url": "https://github.com/open-formulieren/open-forms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "EUPL-1.2",
"license_class": "weak-copyleft",
"license_evidence": "LICENCE.md body read: \"Licensed under the EUPL\", EUROPEAN UNION PUBLIC LICENCE v. 1.2",
"capability_kinds": [
"forms",
"portal",
"case_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 59,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 576,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 108564
},
"adaptation_risks": "EUPL-1.2 per LICENCE.md; Dutch-government forms with genuine case/submission workflow, but only 59 stars and NL-specific integrations",
"claim": "open-formulieren/open-forms supplies forms, portal, case_workflow at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag KEPT. This is the archetype, and the only unambiguous instance in the file. Observed repos/open-formulieren/open-forms/contents/src/openforms = authentication, submissions, prefill, payments, appointments, registrations, validations, products, formio. All three archetype elements are first-class subsystems: authentication/ carries an external citizen identity (DigiD-class), prefill/ performs scoped read of that identity's own held data, and submissions/ plus registrations/ is request submission routed into a back-office case system. Built for untrusted members of the public by construction.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-123record 123
{
"id": "OSS-123",
"repo": "open-mercato/open-mercato",
"url": "https://github.com/open-mercato/open-mercato",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/open-mercato/open-mercato API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory",
"e_commerce"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 1686,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 870,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 349678
},
"adaptation_risks": "1686 stars but young; maintenance owner unproven",
"claim": "open-mercato/open-mercato supplies inventory, e_commerce at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows apps/ + docker-compose.fullapp.yml + config/ + docker/; a deployable commerce/back-office app -> product"
}
OSS-124record 124
{
"id": "OSS-124",
"repo": "openboxes/openboxes",
"url": "https://github.com/openboxes/openboxes",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "EPL-1.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/openboxes/openboxes API license.spdx_id = EPL-1.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory",
"field_ops"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 883,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Groovy",
"open_issues": 187,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 109631
},
"adaptation_risks": "EPL-1.0 weak copyleft; Groovy/Grails",
"claim": "openboxes/openboxes supplies inventory, field_ops at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-125record 125
{
"id": "OSS-125",
"repo": "openedx/openedx-platform",
"url": "https://github.com/openedx/openedx-platform",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/openedx/openedx-platform API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 8173,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 536,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2322580
},
"adaptation_risks": "AGPL-3.0 verified; identity moved from openedx/edx-platform. Very heavy",
"claim": "openedx/openedx-platform supplies lms at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"openedx/edx-platform"
],
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-126record 126
{
"id": "OSS-126",
"repo": "opensearch-project/OpenSearch",
"url": "https://github.com/opensearch-project/OpenSearch",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/opensearch-project/OpenSearch API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 13586,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 3136,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 624025
},
"adaptation_risks": "Apache-2.0 verified clean; the correct answer where Elasticsearch licensing blocks",
"claim": "opensearch-project/OpenSearch supplies search at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search engine; OpenSearch Dashboards is a separate repo -> primitive"
}
OSS-127record 127
{
"id": "OSS-127",
"repo": "opensupports/opensupports",
"url": "https://github.com/opensupports/opensupports",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/opensupports/opensupports API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 1038,
"pushed_at": "2024-04-22",
"days_since_push": 857,
"maintenance": "stale",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 615,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 9776
},
"adaptation_risks": "GPL-3.0 and last push 2024-04-22",
"claim": "opensupports/opensupports supplies support_desk at stale maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-128record 128
{
"id": "OSS-128",
"repo": "oppia/oppia",
"url": "https://github.com/oppia/oppia",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/oppia/oppia API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"lms"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 6780,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 1808,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 436299
},
"adaptation_risks": "Apache-2.0 verified clean; interactive-lesson focus, not general LMS",
"claim": "oppia/oppia supplies lms at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-129record 129
{
"id": "OSS-129",
"repo": "ory/kratos",
"url": "https://github.com/ory/kratos",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/ory/kratos API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 13849,
"pushed_at": "2026-07-29",
"days_since_push": 29,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 222,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 98364
},
"adaptation_risks": "Apache-2.0 verified; headless identity, clean API seam. Ory ecosystem has separate paid hosted tier",
"claim": "ory/kratos supplies auth_identity at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+auth, no ui; headless identity API - you must build the login UI and product around it -> primitive"
}
OSS-130record 130
{
"id": "OSS-130",
"repo": "osTicket/osTicket",
"url": "https://github.com/osTicket/osTicket",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-2.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/osTicket/osTicket API license.spdx_id = GPL-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3898,
"pushed_at": "2026-06-17",
"days_since_push": 71,
"maintenance": "slowing",
"archived": false,
"primary_language": "PHP",
"open_issues": 1203,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": false,
"containerized": false,
"repo_size_kb": 77372
},
"adaptation_risks": "GPL-2.0 verified; legacy PHP",
"claim": "osTicket/osTicket supplies support_desk at slowing maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-131record 131
{
"id": "OSS-131",
"repo": "outline/outline",
"url": "https://github.com/outline/outline",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSL 1.1",
"license_class": "source-available",
"license_evidence": "LICENSE body read: \"Business Source License 1.1\", Additional Use Grant forbids use for a \"Document Service\" commercial offering",
"capability_kinds": [
"notes_docs",
"search"
],
"composite_contents": [
"ui",
"data",
"auth",
"search",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 40348,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 88,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 327398
},
"adaptation_risks": "BSL 1.1 with a Document Service use grant exclusion — precisely the use Actionist would make of it",
"claim": "outline/outline supplies notes_docs, search, portal at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Outline is an internal team knowledge base; its sharing feature produces public read-only links, which is anonymous publishing rather than an authenticated external identity with scoped access and a submission path. Retains notes_docs and search. Row remains a reject on licence grounds (BSL 1.1 Document Service exclusion) independently of this re-tag.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,search,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-132record 132
{
"id": "OSS-132",
"repo": "owncloud/ocis",
"url": "https://github.com/owncloud/ocis",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/owncloud/ocis API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"data",
"auth",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 2105,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 610,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 829493
},
"adaptation_risks": "Apache-2.0 verified clean; Go microservices",
"claim": "owncloud/ocis supplies files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents data+auth+host_chrome, containerized; a deployable file-platform server (Infinite Scale) with identity -> product"
}
OSS-133record 133
{
"id": "OSS-133",
"repo": "paperless-ngx/paperless-ngx",
"url": "https://github.com/paperless-ngx/paperless-ngx",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/paperless-ngx/paperless-ngx API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents",
"search"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 44637,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 11,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 198665
},
"adaptation_risks": "GPL-3.0 verified; strong document ingest/OCR pipeline",
"claim": "paperless-ngx/paperless-ngx supplies files_documents, search at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-134record 134
{
"id": "OSS-134",
"repo": "papermerge/papermerge-core",
"url": "https://github.com/papermerge/papermerge-core",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/papermerge/papermerge-core API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 528,
"pushed_at": "2026-03-21",
"days_since_push": 159,
"maintenance": "slowing",
"archived": false,
"primary_language": "Python",
"open_issues": 35,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 24593
},
"adaptation_risks": "Apache-2.0 clean but 528 stars and last push 2026-03-21",
"claim": "papermerge/papermerge-core supplies files_documents at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Clean split of `papermerge/` (Python core), `frontend/`, `docker/`, `alembic.ini` and `pyproject.toml` under Apache-2.0 — a deployable DMS with a packaged core. Slowing maintenance is a risk to note, not a reason to reimplement permissive code.",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows papermerge/ + frontend/ + alembic.ini migrations + docker/; a deployable DMS product -> product"
}
OSS-135record 135
{
"id": "OSS-135",
"repo": "paradedb/paradedb",
"url": "https://github.com/paradedb/paradedb",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/paradedb/paradedb API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 9201,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 190,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 232674
},
"adaptation_risks": "AGPL-3.0 verified; Postgres extension — colocating search with the app DB is architecturally attractive",
"claim": "paradedb/paradedb supplies search at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; Postgres search extensions -> primitive"
}
OSS-136record 136
{
"id": "OSS-136",
"repo": "parse-community/parse-server",
"url": "https://github.com/parse-community/parse-server",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/parse-community/parse-server API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"airtable_data"
],
"composite_contents": [
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 21411,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 552,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 148780
},
"adaptation_risks": "Apache-2.0 verified clean; mature but a legacy BaaS generation",
"claim": "parse-community/parse-server supplies auth_identity, airtable_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents data+auth, no ui; a backend-as-a-service framework you build apps on -> framework"
}
OSS-137record 137
{
"id": "OSS-137",
"repo": "payloadcms/payload",
"url": "https://github.com/payloadcms/payload",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/payloadcms/payload API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data",
"files_documents",
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 44425,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1092,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 213799
},
"adaptation_risks": "MIT verified clean; TS-native headless CMS that installs INTO a Next.js app — the seam shape Actionist wants",
"claim": "payloadcms/payload supplies admin_data, files_documents, notes_docs at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 2,
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + examples/ + app/ dev harness, pnpm-workspace; a Next.js-native CMS framework installed into your own app -> framework"
}
OSS-138record 138
{
"id": "OSS-138",
"repo": "pdovhomilja/nextcrm-app",
"url": "https://github.com/pdovhomilja/nextcrm-app",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/pdovhomilja/nextcrm-app API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm",
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 684,
"pushed_at": "2026-08-10",
"days_since_push": 17,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 24,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 7668
},
"adaptation_risks": "684 stars, single-maintainer; MongoDB+Prisma coupling",
"claim": "pdovhomilja/nextcrm-app supplies crm, project_management at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-139record 139
{
"id": "OSS-139",
"repo": "plankanban/planka",
"url": "https://github.com/plankanban/planka",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "PLANKA Community License 1.1",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: \"**PLANKA Community License** Version 1.1\" with a separate PLANKA Commercial License",
"capability_kinds": [
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 12456,
"pushed_at": "2026-08-10",
"days_since_push": 17,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 448,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 58560
},
"adaptation_risks": "PLANKA Community License 1.1 read from LICENSE.md — bespoke non-OSI license with a paired commercial license",
"claim": "plankanban/planka supplies project_management at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-140record 140
{
"id": "OSS-140",
"repo": "plausible/analytics",
"url": "https://github.com/plausible/analytics",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/plausible/analytics API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 28766,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Elixir",
"open_issues": 60,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 662183
},
"adaptation_risks": "AGPL-3.0 verified; Elixir stack",
"claim": "plausible/analytics supplies analytics_bi at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-141record 141
{
"id": "OSS-141",
"repo": "pocketbase/pocketbase",
"url": "https://github.com/pocketbase/pocketbase",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/pocketbase/pocketbase API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"airtable_data",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 60837,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 19,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 144013
},
"adaptation_risks": "MIT verified clean; single Go binary with auth, DB, files and an admin UI. Exceptional rights/effort ratio for small client apps",
"claim": "pocketbase/pocketbase supplies auth_identity, airtable_data, files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 1,
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome; single binary with an admin UI and auth -> product (developer platform)"
}
OSS-142record 142
{
"id": "OSS-142",
"repo": "prisma/orm",
"url": "https://github.com/prisma/orm",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/prisma/orm API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 47564,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 2567,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 255604
},
"adaptation_risks": "Apache-2.0 verified clean; identity moved from prisma/prisma",
"claim": "prisma/orm supplies admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"prisma/prisma"
],
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data], extracted_package; an ORM -> primitive"
}
OSS-143record 143
{
"id": "OSS-143",
"repo": "quickwit-oss/quickwit",
"url": "https://github.com/quickwit-oss/quickwit",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/quickwit-oss/quickwit API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search",
"analytics_bi"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 11549,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 802,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 89313
},
"adaptation_risks": "Apache-2.0 verified clean; log/trace search focus",
"claim": "quickwit-oss/quickwit supplies search, analytics_bi at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search/log engine -> primitive"
}
OSS-144record 144
{
"id": "OSS-144",
"repo": "redmine/redmine",
"url": "https://github.com/redmine/redmine",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-2.0-or-later",
"license_class": "strong-copyleft",
"license_evidence": "LICENSE.txt body read: \"GNU General Public License ... either version 2 of the License, or (at your option) any later version\"",
"capability_kinds": [
"project_management",
"case_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 6021,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 105115
},
"adaptation_risks": "GPL-2.0-or-later per LICENSE.txt; very mature issue/workflow state machine",
"claim": "redmine/redmine supplies project_management, case_workflow at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-145record 145
{
"id": "OSS-145",
"repo": "refinedev/refine",
"url": "https://github.com/refinedev/refine",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/refinedev/refine API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"crm",
"admin_data"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 35586,
"pushed_at": "2026-06-05",
"days_since_push": 83,
"maintenance": "slowing",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 89,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 8285031
},
"adaptation_risks": "Framework not a template; supplies headless CRUD hooks, you still build the domain model",
"claim": "refinedev/refine supplies crm, admin_data, portal at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Observed repos/refinedev/refine/contents/packages = core, rest, simple-rest, supabase, hasura, strapi, medusa, airtable, antd, mui, mantine, chakra-ui, inferencer, devtools — headless CRUD hooks plus backend adapters and UI-kit bindings. Same category as react-admin: an internal-admin framework where authProvider is an unimplemented interface, not an authorization product. Retains crm and admin_data.",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + examples/ + templates/ + documentation/, no deployable app; React framework for building admin/CRM products -> framework"
}
OSS-146record 146
{
"id": "OSS-146",
"repo": "saeloun/miru-web",
"url": "https://github.com/saeloun/miru-web",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/saeloun/miru-web API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"billing",
"project_management"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 266,
"pushed_at": "2026-08-22",
"days_since_push": 5,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 0,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 55614
},
"adaptation_risks": "266 stars, thin maintenance base; Rails+TS hybrid",
"claim": "saeloun/miru-web supplies billing, project_management at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Rails + Vite product surface (`app/`, `apps/`, `db/`, `config/`, six Dockerfiles, `.kamal/`) under MIT. There is no extractable library here; it is a finished time-tracking/invoicing product you would fork and own outright, which is transplant, not pattern.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-147record 147
{
"id": "OSS-147",
"repo": "saleor/saleor",
"url": "https://github.com/saleor/saleor",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-3-Clause",
"license_class": "permissive",
"license_evidence": "repos/saleor/saleor API license.spdx_id = BSD-3-Clause; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"data",
"connectors",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 23266,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 245,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 246558
},
"adaptation_risks": "BSD-3-Clause verified clean; Python/GraphQL",
"claim": "saleor/saleor supplies e_commerce, inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents lacks ui but ships a deployable GraphQL commerce server with its own data model and permissions; the dashboard is a sibling repo -> product (headless backend)"
}
OSS-148record 148
{
"id": "OSS-148",
"repo": "sanity-io/sanity",
"url": "https://github.com/sanity-io/sanity",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/sanity-io/sanity API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"admin_data",
"notes_docs"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 6298,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 204,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 219825
},
"adaptation_risks": "MIT repo but the content lake is a paid hosted service — capability is not self-hostable from this repo",
"claim": "sanity-io/sanity supplies admin_data, notes_docs at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "`packages/` pnpm workspace publishing `sanity` and the Studio packages to npm under MIT, with `dev/`, `e2e/` and `examples/` confirming component packaging. Sanity Studio is explicitly designed to be mounted inside a host app — embedded_module.",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + examples/ + dev/ + perf/, pnpm-workspace, no deployable server; content platform toolkit (Studio is embedded into your app) -> framework"
}
OSS-149record 149
{
"id": "OSS-149",
"repo": "seaweedfs/seaweedfs",
"url": "https://github.com/seaweedfs/seaweedfs",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/seaweedfs/seaweedfs API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"files_documents"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 34305,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 763,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 231414
},
"adaptation_risks": "Apache-2.0 verified clean; object store primitive",
"claim": "seaweedfs/seaweedfs supplies files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only; a distributed filesystem/object store, infrastructure -> primitive"
}
OSS-150record 150
{
"id": "OSS-150",
"repo": "sendgrid/sendgrid-nodejs",
"url": "https://github.com/sendgrid/sendgrid-nodejs",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/sendgrid/sendgrid-nodejs API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [],
"composite_repo": false,
"reuse_shape_recommendation": "adapter",
"quality_signals": {
"stars": 3053,
"pushed_at": "2026-06-25",
"days_since_push": 63,
"maintenance": "slowing",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 102,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2412
},
"adaptation_risks": "MIT clean but a thin SDK to a paid Twilio API — Composio-shaped trap; no capability in the repo itself",
"claim": "sendgrid/sendgrid-nodejs supplies messaging_notifications at slowing maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[] empty, adapter shape, 2412 kb; an API client SDK for a hosted service -> primitive"
}
OSS-151record 151
{
"id": "OSS-151",
"repo": "siyuan-note/siyuan",
"url": "https://github.com/siyuan-note/siyuan",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/siyuan-note/siyuan API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 46004,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 49,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 746607
},
"adaptation_risks": "AGPL-3.0; desktop-first, Chinese-primary docs",
"claim": "siyuan-note/siyuan supplies notes_docs at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows app/ + kernel/ + Dockerfile; a runnable self-hosted notes product -> product"
}
OSS-152record 152
{
"id": "OSS-152",
"repo": "solidusio/solidus",
"url": "https://github.com/solidusio/solidus",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-3-Clause (Spree License)",
"license_class": "permissive",
"license_evidence": "LICENSE.md body read: \"Spree License\" with BSD-3-Clause redistribution conditions verbatim",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"ui",
"data",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 5322,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 119,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 125240
},
"adaptation_risks": "BSD-3-Clause (Spree License) confirmed by body read despite NOASSERTION badge; Rails",
"claim": "solidusio/solidus supplies e_commerce, inventory at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Repo is a set of Ruby gems (`core/`, `api/`, `admin/`, `backend/`, `storefront/`, `promotions/`, `solidus.gemspec`) under BSD-3-Clause. Solidus is consumed by adding selected gems to a host Rails app — extracted_package is exactly its distribution model.",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows core/ api/ admin/ backend/ storefront/ promotions/ + solidus.gemspec; a set of mountable Rails engines, not a standalone app -> framework"
}
OSS-153record 153
{
"id": "OSS-153",
"repo": "spree/spree",
"url": "https://github.com/spree/spree",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-3-Clause",
"license_class": "permissive",
"license_evidence": "repos/spree/spree API license.spdx_id = BSD-3-Clause; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"inventory",
"e_commerce"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 15647,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 132,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 302014
},
"adaptation_risks": "Ruby/Rails; BSD-3 is clean but stack diverges from JS/TS spine",
"claim": "spree/spree supplies inventory, e_commerce at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "`spree/` gem tree plus a `packages/` JS workspace under BSD-3-Clause; Spree mounts into a host Rails application as engine gems. Same reasoning as Solidus: the code is meant to be taken as packages.",
"supply_tier": "framework",
"supply_tier_evidence": "extracted_package shape, Rails engine gems (core/api/admin) mounted into a host app -> framework"
}
OSS-154record 154
{
"id": "OSS-154",
"repo": "statamic/cms",
"url": "https://github.com/statamic/cms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Statamic proprietary license",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: Statamic, LLC license with a \"Do not plagiarize\" clause; not an OSI license",
"capability_kinds": [
"notes_docs",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4877,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 297,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 103134
},
"adaptation_risks": "Statamic proprietary license read from LICENSE.md",
"claim": "statamic/cms supplies notes_docs, files_documents at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-155record 155
{
"id": "OSS-155",
"repo": "strapi/strapi",
"url": "https://github.com/strapi/strapi",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT core + commercial ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: any component under an \"ee/\" directory is Enterprise Edition and NOT MIT; remainder MIT Expat",
"capability_kinds": [
"admin_data",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 73018,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 547,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 673031
},
"adaptation_risks": "MIT core confirmed, but any ee/ directory content is Enterprise and excluded",
"claim": "strapi/strapi supplies admin_data, files_documents at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, embedded_module monorepo; headless CMS framework scaffolded per-project via create-strapi-app -> framework"
}
OSS-156record 156
{
"id": "OSS-156",
"repo": "supabase/supabase",
"url": "https://github.com/supabase/supabase",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/supabase/supabase API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"airtable_data",
"files_documents",
"search"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 108465,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1038,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 2440846
},
"adaptation_risks": "Apache-2.0 at repo root, but this monorepo bundles many sub-projects with their own licenses; per-package check required",
"claim": "supabase/supabase supplies auth_identity, airtable_data, files_documents, search at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+auth+host_chrome, containerized monorepo; deployable BaaS with Studio UI -> product (developer platform)"
}
OSS-157record 157
{
"id": "OSS-157",
"repo": "supertokens/supertokens-core",
"url": "https://github.com/supertokens/supertokens-core",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0 core + commercial ee/",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE.md body read: ee/ under ee/LICENSE.md; remainder Apache-2.0",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 15285,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 174,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 705451
},
"adaptation_risks": "Apache-2.0 outside ee/ per LICENSE.md read",
"claim": "supertokens/supertokens-core supplies auth_identity at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+auth, no ui; a headless auth core consumed via SDKs -> primitive"
}
OSS-158record 158
{
"id": "OSS-158",
"repo": "surveyjs/survey-library",
"url": "https://github.com/surveyjs/survey-library",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/surveyjs/survey-library API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 4857,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 490,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 303338
},
"adaptation_risks": "MIT verified clean; the form/survey renderer only. Creator UI is a separate paid product",
"claim": "surveyjs/survey-library supplies forms at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only, extracted_package monorepo; a form-rendering widget library, no backend or response store -> primitive"
}
OSS-159record 159
{
"id": "OSS-159",
"repo": "teableio/teable",
"url": "https://github.com/teableio/teable",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 core apps",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE body read: apps/nestjs-backend and apps/nextjs-app are AGPL-3.0; deliberate multi-license split for commercial services",
"capability_kinds": [
"airtable_data"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 21720,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 127,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 73239
},
"adaptation_risks": "AGPL-3.0 on the core apps per LICENSE body; deliberate commercial split",
"claim": "teableio/teable supplies airtable_data at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-160record 160
{
"id": "OSS-160",
"repo": "tellform/tellform",
"url": "https://github.com/tellform/tellform",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "LICENSE.md body read: \"(The MIT License)\" verbatim; repo ARCHIVED per repos API archived:true",
"capability_kinds": [
"forms"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 3023,
"pushed_at": "2019-10-09",
"days_since_push": 2514,
"maintenance": "stale",
"archived": true,
"primary_language": "JavaScript",
"open_issues": 70,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": false,
"containerized": true,
"repo_size_kb": 22489
},
"adaptation_risks": "ARCHIVED (archived:true), last push 2019-10-09; MIT is clean but the code is seven years stale",
"claim": "tellform/tellform supplies forms at stale maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern. Permissive, but the tree is abandoned AngularJS-era tooling (`bower.json`, `gruntfile.js`, `karma.conf.js`, `protractor.conf.js`, Vagrantfile) and the row is already a reject. Only the form-builder data model is worth carrying forward.",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows app/ + config/ + server.js + public/ + docker-compose.yml; deployable forms product (unmaintained) -> product"
}
OSS-161record 161
{
"id": "OSS-161",
"repo": "temporalio/temporal",
"url": "https://github.com/temporalio/temporal",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/temporalio/temporal API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"approvals_workflow"
],
"composite_contents": [
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 22558,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 936,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 157596
},
"adaptation_risks": "MIT verified; durable execution engine — the right primitive for case_workflow state machines but you write all domain logic",
"claim": "temporalio/temporal supplies approvals_workflow at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"top10_rank": 7,
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+workflow, no ui; a durable-execution engine, requires you to write the workflows and product around it -> primitive"
}
OSS-162record 162
{
"id": "OSS-162",
"repo": "tinacms/tinacms",
"url": "https://github.com/tinacms/tinacms",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/tinacms/tinacms API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs",
"admin_data"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 13757,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 435,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 932752
},
"adaptation_risks": "Apache-2.0 verified; git-backed editing, coupled to a paid cloud tier",
"claim": "tinacms/tinacms supplies notes_docs, admin_data at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "`packages/` pnpm monorepo publishing tinacms and its field/editor packages to npm under Apache-2.0. TinaCMS is installed into an existing Next.js app as a mounted editing layer — embedded_module.",
"supply_tier": "framework",
"supply_tier_evidence": "gh api contents shows packages/ + examples/ + _docs/, pnpm-workspace turbo monorepo; a CMS toolkit you add to an existing site -> framework"
}
OSS-163record 163
{
"id": "OSS-163",
"repo": "tldraw/tldraw",
"url": "https://github.com/tldraw/tldraw",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "tldraw License (proprietary, watermark)",
"license_class": "source-available",
"license_evidence": "LICENSE.md body read: \"This License from tldraw, Inc. governs your use\"; alternative commercial licenses sold separately",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 49984,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 719,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1544576
},
"adaptation_risks": "tldraw proprietary License read from LICENSE.md — watermark/commercial terms, not open source",
"claim": "tldraw/tldraw supplies notes_docs at active maintenance under a source-available rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only; an infinite-canvas SDK/component library, source-available -> primitive"
}
OSS-164record 164
{
"id": "OSS-164",
"repo": "toeverything/AFFiNE",
"url": "https://github.com/toeverything/AFFiNE",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT frontend + separate backend license",
"license_class": "permissive-open-core",
"license_evidence": "LICENSE body read: packages/backend and packages/common/native under packages/backend/server/LICENSE; remainder permissive",
"capability_kinds": [
"notes_docs",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 71940,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 712,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 451687
},
"adaptation_risks": "Permissive frontend but backend carved out under a separate license; heavy custom runtime",
"claim": "toeverything/AFFiNE supplies notes_docs, files_documents at active maintenance under a permissive-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Kept as pattern for rights reasons. Two licence files at root (`LICENSE`, `LICENSE-MIT`) signal a mixed posture over an open-core product, and the repo is a very large Yarn+Cargo hybrid (`blocksuite/`, `packages/`, `.cargo/`). The block-editor data model is the transferable asset.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-165record 165
{
"id": "OSS-165",
"repo": "tracim/tracim",
"url": "https://github.com/tracim/tracim",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT backend / LGPLv3 frontend / AGPLv3 agenda",
"license_class": "mixed-copyleft",
"license_evidence": "LICENSE.md body read: 4 distinct licenses — AGPLv3 agenda app, LGPLv3 other frontends, MIT backend, CC-BY docs",
"capability_kinds": [
"files_documents",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 275,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 1536,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 61807
},
"adaptation_risks": "Four different licenses across dirs per LICENSE.md; 275 stars",
"claim": "tracim/tracim supplies files_documents, messaging_notifications at active maintenance under a mixed-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-166record 166
{
"id": "OSS-166",
"repo": "twentyhq/twenty",
"url": "https://github.com/twentyhq/twenty",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 + commercial (open-core)",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE body read: \"mostly licensed under the GNU Affero General Public License v3.0 (AGPLv3)\" with files marked /* @license Enterprise */ carved out under a commercial license",
"capability_kinds": [
"crm"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 55651,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 173,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1759372
},
"adaptation_risks": "Enterprise-marked files must be stripped file-by-file; AGPL core makes source-derived client delivery a legal decision",
"claim": "twentyhq/twenty supplies crm at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-167record 167
{
"id": "OSS-167",
"repo": "typesense/typesense",
"url": "https://github.com/typesense/typesense",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/typesense/typesense API license.spdx_id = GPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search"
],
"composite_contents": [
"data",
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 26481,
"pushed_at": "2026-08-18",
"days_since_push": 9,
"maintenance": "active",
"archived": false,
"primary_language": "C++",
"open_issues": 873,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 14679
},
"adaptation_risks": "GPL-3.0 verified; as a separate-process service the copyleft reach is narrower than for linked code",
"claim": "typesense/typesense supplies search at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents data+search, no ui; a search engine -> primitive"
}
OSS-168record 168
{
"id": "OSS-168",
"repo": "umami-software/umami",
"url": "https://github.com/umami-software/umami",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/umami-software/umami API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"analytics_bi"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 38389,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 110,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 30750
},
"adaptation_risks": "MIT verified clean; Next.js+Prisma matches the JS/TS spine exactly. Narrow scope (web analytics only)",
"claim": "umami-software/umami supplies analytics_bi at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-169record 169
{
"id": "OSS-169",
"repo": "usememos/memos",
"url": "https://github.com/usememos/memos",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/usememos/memos API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"notes_docs"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 62581,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 49,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 39003
},
"adaptation_risks": "MIT and clean, but a lightweight microblog — far below Notion-class depth",
"claim": "usememos/memos supplies notes_docs at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"shape_revision_note": "Go service root (`cmd/`, `server/`, `store/`, `proto/`, `internal/`) with an embedded `web/` frontend under MIT — a single deployable binary. Run it intact behind the portal rather than reimplementing note storage.",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows cmd/ server/ store/ web/ + Dockerfile; deployable notes product with its own auth -> product"
}
OSS-170record 170
{
"id": "OSS-170",
"repo": "valeriansaliou/sonic",
"url": "https://github.com/valeriansaliou/sonic",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MPL-2.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/valeriansaliou/sonic API license.spdx_id = MPL-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"search"
],
"composite_contents": [
"search"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 21320,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 62,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 3186
},
"adaptation_risks": "MPL-2.0 weak copyleft; very lightweight, no relevance ranking depth",
"claim": "valeriansaliou/sonic supplies search at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[search] only, 3186 kb; a lightweight search index backend -> primitive"
}
OSS-171record 171
{
"id": "OSS-171",
"repo": "vendurehq/vendure",
"url": "https://github.com/vendurehq/vendure",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0 (CE) or Vendure Commercial License",
"license_class": "strong-copyleft-dual",
"license_evidence": "LICENSE.md body read: \"The default Vendure license, without a valid Vendure Commercial License agreement, is the Open-Source GPLv3 license\"",
"capability_kinds": [
"e_commerce",
"inventory"
],
"composite_contents": [
"data",
"workflow",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 8376,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 200,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 155596
},
"adaptation_risks": "GPLv3 by default per LICENSE.md unless you buy the Vendure Commercial License; identity moved from vendure-ecommerce/vendure",
"claim": "vendurehq/vendure supplies e_commerce, inventory at active maintenance under a strong-copyleft-dual rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"stale_identity_aliases_observed": [
"vendure-ecommerce/vendure"
],
"supply_tier": "framework",
"supply_tier_evidence": "composite_contents data+workflow+host_chrome, no ui; a headless Node commerce framework (admin UI is a separate package) -> framework"
}
OSS-172record 172
{
"id": "OSS-172",
"repo": "wasp-lang/open-saas",
"url": "https://github.com/wasp-lang/open-saas",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/wasp-lang/open-saas API license.spdx_id = MIT; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity",
"billing",
"crm"
],
"composite_contents": [
"ui",
"data",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 15643,
"pushed_at": "2026-08-06",
"days_since_push": 21,
"maintenance": "active",
"archived": false,
"primary_language": "MDX",
"open_issues": 104,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 141021
},
"adaptation_risks": "Requires the Wasp DSL/compiler — a framework lock-in, not plain React/Node",
"claim": "wasp-lang/open-saas supplies auth_identity, billing, crm at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "framework",
"supply_tier_evidence": "transplant shape, MDX primary language; a SaaS starter template you clone and build on -> framework"
}
OSS-173record 173
{
"id": "OSS-173",
"repo": "windmill-labs/windmill",
"url": "https://github.com/windmill-labs/windmill",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0 default + Apache-2.0 parts + proprietary EE",
"license_class": "strong-copyleft-open-core",
"license_evidence": "LICENSE body read: \"Every file is under License AGPL unless otherwise specified\"; Apache and proprietary enterprise carve-outs",
"capability_kinds": [
"approvals_workflow",
"admin_data"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 17693,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Rust",
"open_issues": 834,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 504355
},
"adaptation_risks": "AGPL default per LICENSE body with Apache and proprietary EE carve-outs",
"claim": "windmill-labs/windmill supplies approvals_workflow, admin_data at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-174record 174
{
"id": "OSS-174",
"repo": "zammad/zammad",
"url": "https://github.com/zammad/zammad",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/zammad/zammad API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"support_desk"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 5871,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 458,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 1049566
},
"adaptation_risks": "AGPL-3.0 verified; Rails, mature",
"claim": "zammad/zammad supplies support_desk at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,workflow,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-175record 175
{
"id": "OSS-175",
"repo": "zitadel/zitadel",
"url": "https://github.com/zitadel/zitadel",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/zitadel/zitadel API license.spdx_id = AGPL-3.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"auth_identity"
],
"composite_contents": [
"data",
"auth",
"host_chrome"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 14868,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 1135,
"monorepo_layout": true,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 592196
},
"adaptation_risks": "AGPL-3.0 verified",
"claim": "zitadel/zitadel supplies auth_identity at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents data+auth+host_chrome; deployable IdP with console -> product"
}
OSS-176record 176
{
"id": "OSS-176",
"repo": "zulip/zulip",
"url": "https://github.com/zulip/zulip",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/zulip/zulip API license.spdx_id = Apache-2.0; standard OSI identifier, LICENSE body not separately re-read",
"capability_kinds": [
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 25775,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 2051,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 640694
},
"adaptation_risks": "Apache-2.0 verified clean; Python/Django, strong threading model",
"claim": "zulip/zulip supplies messaging_notifications at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy, auth-authority or security review. Sub-directory and transitive-dependency licenses are UNVERIFIED.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents [ui,data,auth,host_chrome] carries ui + data + host_chrome + auth; a deployable app with its own chrome -> product"
}
OSS-177record 177
{
"id": "OSS-177",
"repo": "docusealco/docuseal",
"url": "https://github.com/docusealco/docuseal",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/docusealco/docuseal API license.spdx_id = AGPL-3.0. LICENSE body fetched via repos/.../contents/LICENSE and decoded: 'GNU AFFERO GENERAL PUBLIC LICENSE Version 3'. A second root file LICENSE_ADDITIONAL_TERMS was fetched and decoded: 'In accordance with Section 7(b) of the GNU Affero General Public License, a covered work must retain the original DocuSeal attribution in interactive user interfaces.' No /ee or /enterprise directory exists (contents dirs = .github app bin config db docs lib log public spec tmp), so this is single-licence AGPL plus a binding attribution rider, not open-core.",
"capability_kinds": [
"e_sign",
"forms",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 18388,
"pushed_at": "2026-08-25",
"days_since_push": 2,
"maintenance": "active",
"archived": false,
"primary_language": "Ruby",
"open_issues": 119,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 7845
},
"adaptation_risks": "AGPL-3.0 blocks source reuse in a proprietary client deliverable. The Section 7(b) additional term additionally forbids removing DocuSeal attribution from the UI, so even a permitted self-hosted deployment cannot be white-labelled — a direct conflict with a client-branded portal.",
"claim": "docusealco/docuseal supplies e_sign, forms, files_documents at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+host_chrome, containerized; complete signing product (templates, submitters, audit) -> product"
}
OSS-178record 178
{
"id": "OSS-178",
"repo": "OpenSignLabs/OpenSign",
"url": "https://github.com/OpenSignLabs/OpenSign",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "NOASSERTION",
"license_class": "strong-copyleft-open-core",
"license_evidence": "repos/OpenSignLabs/OpenSign API license.spdx_id = NOASSERTION, so repos/.../license was fetched and decoded. The header carves out a directory before granting AGPL: 'All content that resides under the apps/OpenSignServer/cloud/customRoute directory of this repository, if that directory exists, is licensed under the license defined in apps/OpenSignServer/cloud/customRoute' ... 'Content outside of the above mentioned directories or restrictions above is available under the GNU AFFERO GENERAL PUBLIC LICENSE'. That directory DOES exist: repos/.../contents/apps/OpenSignServer/cloud/customRoute returns customApp.js, decryptpdf.js, deleteAccount (dir), docxtopdf.js — and a filter for any file matching licen[cs]e in that directory returns 0. The referenced carve-out licence is therefore absent, leaving those four items under no stated grant.",
"capability_kinds": [
"e_sign",
"files_documents",
"approvals_workflow"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 6919,
"pushed_at": "2026-08-21",
"days_since_push": 6,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 146,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 167271
},
"adaptation_risks": "Two compounding problems: AGPL on the bulk of the code, plus a carved-out customRoute directory whose governing licence file is missing from the repo. decryptpdf.js and docxtopdf.js sit inside that carve-out and are core document-processing paths, so the unlicensed slice is not peripheral. Treat as no-reuse until upstream publishes the missing terms.",
"claim": "OpenSignLabs/OpenSign supplies e_sign, files_documents, approvals_workflow at active maintenance under a strong-copyleft-open-core rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+connectors+host_chrome, containerized monorepo; full signing product -> product"
}
OSS-179record 179
{
"id": "OSS-179",
"repo": "LibreSign/libresign",
"url": "https://github.com/LibreSign/libresign",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/LibreSign/libresign API license.spdx_id = AGPL-3.0. Root contents include COPYING, REUSE.toml and a LICENSES/ directory; repos/.../contents/LICENSES lists AGPL-3.0-or-later.txt, CC0-1.0.txt, MIT.txt, OFL-1.1.txt — a REUSE-compliant layout where AGPL-3.0-or-later is the code licence and the others cover assets/fonts. No proprietary tier directory present.",
"capability_kinds": [
"e_sign",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"workflow",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 790,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 91,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 123078
},
"adaptation_risks": "AGPL-3.0-or-later blocks source reuse. Architecturally it is a Nextcloud app (appinfo/, l10n/, templates/, 3rdparty/) and cannot run standalone — adopting it means adopting Nextcloud as the host platform.",
"claim": "LibreSign/libresign supplies e_sign, files_documents at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents/lib shows Controller, Db, Migration, Notification, Service, Settings + appinfo/routes.php -> a complete Nextcloud signing app with its own workflow and identity -> product"
}
OSS-180record 180
{
"id": "OSS-180",
"repo": "vbuch/node-signpdf",
"url": "https://github.com/vbuch/node-signpdf",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/vbuch/node-signpdf API license.spdx_id = MIT; standard OSI identifier. Root contents show a lerna monorepo (lerna.json, packages/) and repos/.../contents/packages lists signpdf, signer-p12, placeholder-pdf-lib, placeholder-pdfkit, placeholder-plain, utils, internal-utils, examples, eslint-config — discrete publishable npm packages under one MIT root.",
"capability_kinds": [
"e_sign"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 942,
"pushed_at": "2026-07-20",
"days_since_push": 38,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 28,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 4914
},
"adaptation_risks": "A cryptographic signing primitive only: it applies a PKCS#7 signature to a PDF that already contains a signature placeholder. It supplies no signing workflow, no signer identity, no audit trail and no UI, so it covers roughly the bottom layer of an e-signature product. Certificate custody remains the integrator's problem.",
"claim": "vbuch/node-signpdf supplies e_sign at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only, extracted_package, single npm package; PDF byte-range signing library, no UI/signer identity/audit -> primitive"
}
OSS-181record 181
{
"id": "OSS-181",
"repo": "MatthiasValvekens/pyHanko",
"url": "https://github.com/MatthiasValvekens/pyHanko",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/MatthiasValvekens/pyHanko API license.spdx_id = MIT; standard OSI identifier. repos/.../contents/pkgs lists pyhanko, pyhanko-cli, pyhanko-certvalidator — three separately publishable PyPI distributions under the single MIT root, confirming library rather than service packaging.",
"capability_kinds": [
"e_sign",
"files_documents"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 759,
"pushed_at": "2026-08-23",
"days_since_push": 4,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 5,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 18523
},
"adaptation_risks": "Library, not a product: it signs and validates PDFs (PAdES, LTV, timestamping) but provides no request/collect workflow or signer UI. Only 5 open issues against 759 stars suggests a tightly scoped, well-maintained library rather than a neglected one, but standards depth means a real learning curve on PAdES profile selection.",
"claim": "MatthiasValvekens/pyHanko supplies e_sign, files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only, extracted_package, single Python package; PDF signing/stamping library, no workflow or signer identity -> primitive"
}
OSS-182record 182
{
"id": "OSS-182",
"repo": "digitorus/pdfsign",
"url": "https://github.com/digitorus/pdfsign",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-2-Clause",
"license_class": "permissive",
"license_evidence": "repos/digitorus/pdfsign API license.spdx_id = BSD-2-Clause; standard OSI identifier. Root contents are a flat Go package (go.mod, sign/, verify/, forms/, revocation/, appearance.go, verify.go) plus a cli/ directory — a Go module consumed by import path.",
"capability_kinds": [
"e_sign"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 164,
"pushed_at": "2026-08-25",
"days_since_push": 2,
"maintenance": "active",
"archived": false,
"primary_language": "Go",
"open_issues": 5,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 10182
},
"adaptation_risks": "Pure-Go AES/QES signing and verification with no external native dependency, which makes deployment simple, but at 164 stars the community is small and the API surface is comparatively unsettled. Same scope limit as the other libraries: signature primitive, not signing workflow.",
"claim": "digitorus/pdfsign supplies e_sign at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only, extracted_package, 164 stars, Go library for PDF signatures; no UI or workflow -> primitive"
}
OSS-183record 183
{
"id": "OSS-183",
"repo": "esig/dss",
"url": "https://github.com/esig/dss",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "LGPL-2.1",
"license_class": "weak-copyleft",
"license_evidence": "repos/esig/dss API license.spdx_id = LGPL-2.1. LGPL permits linking from proprietary code provided the LGPL component stays replaceable and its own modifications are published; this is materially weaker than the AGPL posture of the e-sign products in this kind.",
"capability_kinds": [
"e_sign",
"files_documents"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 1025,
"pushed_at": "2026-08-18",
"days_since_push": 9,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 4,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": false,
"containerized": false,
"repo_size_kb": 274796
},
"adaptation_risks": "LGPL-2.1 obligations attach to the library itself, so dynamic linking must be preserved and any modification to DSS published. It is the European Commission's eIDAS reference implementation, which is a strong correctness signal but also means heavy standards machinery (Java, XAdES/CAdES/PAdES/ASiC) for a client who may only need a signed PDF.",
"claim": "esig/dss supplies e_sign, files_documents at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "gh api contents shows Maven multi-module library (dss-cades, dss-xades, dss-asic-*, dss-document, dss-cookbook); a signature-validation/creation SDK, no deployable signing app -> primitive"
}
OSS-184record 184
{
"id": "OSS-184",
"repo": "Keyfactor/signserver-ce",
"url": "https://github.com/Keyfactor/signserver-ce",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "LGPL-2.1",
"license_class": "weak-copyleft",
"license_evidence": "repos/Keyfactor/signserver-ce API license.spdx_id = LGPL-2.1. Repo name '-ce' plus vendor Keyfactor indicates a Community Edition of a commercial product; the LGPL grant covers this CE repository as published.",
"capability_kinds": [
"e_sign",
"auth_identity"
],
"composite_contents": [
"data",
"workflow",
"auth"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 431,
"pushed_at": "2026-01-30",
"days_since_push": 209,
"maintenance": "stale",
"archived": false,
"primary_language": "Java",
"open_issues": 11,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 520658
},
"adaptation_risks": "Community Edition of a commercial product, so feature gaps versus the paid edition are expected and undocumented here. pushed_at 2026-01-30 makes it the least actively maintained item in this kind. It is a signing server you deploy and call over an API — a real seam, but it is PKI infrastructure requiring HSM/keystore operations, not a document-signing UX.",
"claim": "Keyfactor/signserver-ce supplies e_sign, auth_identity at stale maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "LANE OWNER CORRECTION (was 'product'). The subagent's own evidence disqualifies it: 'a signing-authority/HSM service, not a DocuSign-class signer-workflow app... no document-sending workflow'. That is the definition of a primitive — signing infrastructure you build an e-signature product around, with no signer identity, no document routing and no audit surface. Original evidence retained: gh api contents shows single signserver/ module with bin/ conf/ modules/ doc/ (deployable, but deployable infrastructure is not a product for the capability it is tagged with)."
}
OSS-185record 185
{
"id": "OSS-185",
"repo": "intoolswetrust/jsignpdf",
"url": "https://github.com/intoolswetrust/jsignpdf",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "NOASSERTION",
"license_class": "weak-copyleft",
"license_evidence": "repos/intoolswetrust/jsignpdf API license.spdx_id = NOASSERTION, so repos/.../license was fetched and decoded. The body is a pointer file, not a licence text: '### Mozilla Public License Version 2.0 / Please see MPL-2.0.txt' and '### GNU Lesser General Public License 2.1 / Please see lgpl-2.1.txt', both under distribution/licenses/. So the real posture is MPL-2.0 plus LGPL-2.1 across components — file-level weak copyleft, not the unclassifiable NOASSERTION the API reports.",
"capability_kinds": [
"e_sign"
],
"composite_contents": [
"ui",
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 462,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "Java",
"open_issues": 20,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 210033
},
"adaptation_risks": "The GitHub API reports NOASSERTION and any automated licence scan will flag this repo as unknown; the actual grant is only discoverable by reading a pointer file and then two files under distribution/licenses/ that were not themselves fetched here, so the component-to-licence mapping is inferred rather than observed. Delivery shape is a JavaFX desktop tool plus CLI, which does not fit a web portal.",
"claim": "intoolswetrust/jsignpdf supplies e_sign at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "gh api contents shows pom.xml + jsignpdf/{pom.xml,src} + engines/ + installcert/; a desktop/CLI PDF signing tool and library, no server, no multi-party workflow -> primitive"
}
OSS-186record 186
{
"id": "OSS-186",
"repo": "24eme/signaturepdf",
"url": "https://github.com/24eme/signaturepdf",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/24eme/signaturepdf API license.spdx_id = AGPL-3.0; standard OSI identifier as reported by the repos API.",
"capability_kinds": [
"e_sign",
"files_documents"
],
"composite_contents": [
"ui",
"data",
"workflow"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 826,
"pushed_at": "2026-08-03",
"days_since_push": 24,
"maintenance": "active",
"archived": false,
"primary_language": "JavaScript",
"open_issues": 67,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 7458
},
"adaptation_risks": "AGPL-3.0 blocks source reuse. Built by a French public-sector body with a French-first UI and a workflow oriented to handwritten-image signatures rather than PKI, so the compliance posture differs from what an eIDAS/ESIGN-conscious client may assume.",
"claim": "24eme/signaturepdf supplies e_sign, files_documents at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows public/ templates/ lib/ config/ app.php + Dockerfile; a runnable PHP web app for PDF signing, but stateless (no data model/identity) -> product (narrow, single-user)"
}
OSS-187record 187
{
"id": "OSS-187",
"repo": "alextselegidis/easyappointments",
"url": "https://github.com/alextselegidis/easyappointments",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "GPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/alextselegidis/easyappointments API license.spdx_id = GPL-3.0. repos/.../license body was fetched and decoded, opening 'GNU GENERAL PUBLIC LICENSE Version 3, 29 June 2007' — GPL-3.0, not the AGPL used by most products in this kind. Note the org: the commonly cited 'easyappointments/easyappointments' path does not exist (gh api repos/easyappointments/easyappointments returns HTTP 404 Not Found); the canonical repo is under alextselegidis.",
"capability_kinds": [
"calendar_scheduling",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 4341,
"pushed_at": "2026-08-26",
"days_since_push": 1,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 171,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 49645
},
"adaptation_risks": "GPL-3.0 blocks source reuse in a proprietary deliverable, though as a non-network copyleft it does not trigger AGPL's remote-interaction clause on a self-hosted deployment. CodeIgniter/PHP stack with a published openapi.yml, so API-level integration is viable where code reuse is not. The frequently quoted org path is wrong and will 404 in any automated pipeline.",
"claim": "alextselegidis/easyappointments supplies calendar_scheduling, portal, messaging_notifications at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Same reasoning as cal.diy: Easy!Appointments exposes an anonymous public booking form plus an internal staff back office, with no authenticated external identity holding scoped read of its own history. Retains calendar_scheduling and messaging_notifications.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+connectors+host_chrome, containerized; complete booking product -> product"
}
OSS-188record 188
{
"id": "OSS-188",
"repo": "lukevella/rallly",
"url": "https://github.com/lukevella/rallly",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/lukevella/rallly API license.spdx_id = AGPL-3.0; repos/.../license body decoded and confirmed 'GNU AFFERO GENERAL PUBLIC LICENSE Version 3'. Checked for an open-core carve-out: repos/.../contents dirs = .agents .claude .github .husky .vscode apps assets biome-plugins docker packages scripts, with apps = docs landing web and packages = billing database dayjs emails languages logger posthog screenshots tailwind-config test-helpers tsconfig ui utils. No ee/ or enterprise/ directory, so it is single-licence AGPL despite shipping a billing package.",
"capability_kinds": [
"calendar_scheduling",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 5225,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 5,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 48436
},
"adaptation_risks": "AGPL-3.0 blocks source reuse. Scope is group poll scheduling (Doodle-style consensus on a time) rather than the availability-and-booking model a client-facing booking page needs — a capability mismatch on top of the rights problem. A first-party packages/billing module signals hosted-tier ambitions worth re-checking before any adoption.",
"claim": "lukevella/rallly supplies calendar_scheduling, portal, messaging_notifications at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Rallly is anonymous group poll participation — invitees follow a link and vote on times without accounts, the weakest possible external-identity story. Retains calendar_scheduling and messaging_notifications.",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+billing+host_chrome, containerized monorepo; complete scheduling/poll product -> product"
}
OSS-189record 189
{
"id": "OSS-189",
"repo": "thunderbird/appointment",
"url": "https://github.com/thunderbird/appointment",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MPL-2.0",
"license_class": "weak-copyleft",
"license_evidence": "repos/thunderbird/appointment API license.spdx_id = MPL-2.0. MPL-2.0 is file-level weak copyleft: modified MPL files must be published, but the code can be combined with proprietary code in a larger work — the most permissive rights posture of any full scheduling product found in this kind.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"connectors",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 550,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 212,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 17563
},
"adaptation_risks": "MPL-2.0 file-level reciprocity is manageable but must be tracked per modified file. Clean backend/ + frontend/ + docker-compose.yml split makes it genuinely deployable; the pulumi/ directory shows the upstream deployment target is their own cloud, so self-hosting is a less-travelled path. 212 open issues against 550 stars indicates a young product still stabilising.",
"claim": "thunderbird/appointment supplies calendar_scheduling, portal at active maintenance under a weak-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. thunderbird/appointment is a personal availability-sharing tool: the booker is an anonymous visitor on a share link. Retains calendar_scheduling. (Self-correction: this tag was applied by me earlier in this same repair pass; under the strict archetype it does not hold.)",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows backend/ + frontend/ + docker-compose.yml + test/; deployable booking product -> product"
}
OSS-190record 190
{
"id": "OSS-190",
"repo": "Tymeslot/tymeslot",
"url": "https://github.com/Tymeslot/tymeslot",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "AGPL-3.0",
"license_class": "strong-copyleft",
"license_evidence": "repos/Tymeslot/tymeslot API license.spdx_id = AGPL-3.0; standard OSI identifier as reported by the repos API. Description confirms the paired hosted offering ('Self-host or use the managed cloud at tymeslot.app'), the usual AGPL-plus-SaaS commercial pattern.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 180,
"pushed_at": "2026-08-22",
"days_since_push": 5,
"maintenance": "active",
"archived": false,
"primary_language": "Elixir",
"open_issues": 6,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 179648
},
"adaptation_risks": "AGPL-3.0 blocks source reuse, and the upstream runs a managed cloud on the same code so relicensing is unlikely. Elixir/Phoenix LiveView is a stack mismatch for a TypeScript client estate; at 180 stars the bus factor is thin.",
"claim": "Tymeslot/tymeslot supplies calendar_scheduling, portal at active maintenance under a strong-copyleft rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. Tymeslot is the same anonymous-booker model as cal.diy and Rallly. Retains calendar_scheduling. (Self-correction: applied by me earlier in this repair pass.)",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows lib/ priv/ config/ assets/ + mix.exs + multiple Dockerfiles/docker-compose; a deployable Phoenix booking product -> product"
}
OSS-191record 191
{
"id": "OSS-191",
"repo": "adamspd/django-appointment",
"url": "https://github.com/adamspd/django-appointment",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "Apache-2.0",
"license_class": "permissive",
"license_evidence": "repos/adamspd/django-appointment API license.spdx_id = Apache-2.0; standard OSI identifier, and the Apache grant includes an explicit patent licence. Root contents show pyproject.toml, setup.py, setup.cfg and MANIFEST.in alongside the appointment/ package — a PyPI distribution, not an application.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"data",
"workflow",
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 278,
"pushed_at": "2026-08-24",
"days_since_push": 3,
"maintenance": "active",
"archived": false,
"primary_language": "Python",
"open_issues": 14,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 3094
},
"adaptation_risks": "Reusable Django app installed into a host project (the appointments/ directory is only a demo host). Value is therefore bounded by the client already being on Django; a compatibility_matrix.md and django_compatible.json at root show the maintainer tracks framework version drift, which is a maintenance signal but also a coupling risk.",
"claim": "adamspd/django-appointment supplies calendar_scheduling at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "gh api contents shows setup.py + pyproject.toml + MANIFEST.in + appointment/ package (installable Django app) with appointments/ demo project; a pluggable component you mount in your own Django site, no standalone identity or product chrome -> primitive"
}
OSS-192record 192
{
"id": "OSS-192",
"repo": "rbbydotdev/someday",
"url": "https://github.com/rbbydotdev/someday",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/rbbydotdev/someday API license.spdx_id = MIT; standard OSI identifier. Repo size is 253 KB, small enough that the whole surface is a thin application rather than a platform.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 1061,
"pushed_at": "2026-07-20",
"days_since_push": 38,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 5,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": false,
"containerized": false,
"repo_size_kb": 253
},
"adaptation_risks": "Explicitly built on Google Apps Script and targeted at Gmail users, so it is hard-coupled to Google Calendar with no other provider path — the connector assumption is the whole architecture, not a swappable adapter. Small enough (253 KB) to fork and own outright, which is the honest shape; treat as a starting point, not a dependency.",
"claim": "rbbydotdev/someday supplies calendar_scheduling at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows frontend/{src,index.html,vite.config} + backend/{src,package.json} + appsscript.json + deploy.sh; a deployable self-hosted Calendly alternative (1061 stars, pushed 2026-07-20) -> product, but NARROWER than cal.diy: Google-Apps-Script/Gmail-bound, no identity system or tenancy of its own"
}
OSS-193record 193
{
"id": "OSS-193",
"repo": "linkedin/oncall",
"url": "https://github.com/linkedin/oncall",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-2-Clause",
"license_class": "permissive",
"license_evidence": "repos/linkedin/oncall API license.spdx_id = BSD-2-Clause; standard OSI identifier. Corporate-authored (LinkedIn) BSD, so no dual-licence or hosted-tier pattern applies.",
"capability_kinds": [
"calendar_scheduling",
"admin_data"
],
"composite_contents": [
"ui",
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 1258,
"pushed_at": "2025-08-20",
"days_since_push": 372,
"maintenance": "stale",
"archived": false,
"primary_language": "Python",
"open_issues": 78,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 5704
},
"adaptation_risks": "Domain is on-call shift rotation, not customer appointment booking — the scheduling model is recurring team coverage with no external-booker concept. pushed_at 2025-08-20 makes it over a year stale, consistent with a corporate project in maintenance mode. Useful where the client need is internal rota rather than client-facing booking.",
"claim": "linkedin/oncall supplies calendar_scheduling, admin_data at stale maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows src/ db/ ops/ configs/ e2e/ + Dockerfile + docker-compose.yml; deployable product, but on-call rota management not customer booking -> product (adjacent capability)"
}
OSS-194record 194
{
"id": "OSS-194",
"repo": "karanshukla/openresto",
"url": "https://github.com/karanshukla/openresto",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/karanshukla/openresto API license.spdx_id = MIT; standard OSI identifier. repos/.../contents dirs = .claude .github .husky .vscode OpenRestoApi.Tests OpenRestoApi docs nginx-vps nginx openresto-frontend scripts — a plain API + frontend split with no ee/ or premium/ carve-out.",
"capability_kinds": [
"calendar_scheduling",
"messaging_notifications"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "intact_service",
"quality_signals": {
"stars": 85,
"pushed_at": "2026-08-27",
"days_since_push": 0,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 7,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": true,
"repo_size_kb": 10924
},
"adaptation_risks": "MIT and actively pushed (same-day as observation), with an explicit API/frontend/nginx deployment split. The severe caveat is scale: 85 stars and a single-maintainer profile mean essentially no production track record, and the domain model is restaurant table reservations (covers, seatings) rather than generic appointment slots.",
"claim": "karanshukla/openresto supplies calendar_scheduling, portal, messaging_notifications at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "hold",
"provenance_lane": "s1l2_oss_survey",
"kind_revision_note": "Portal tag removed. openresto takes anonymous restaurant table reservations confirmed by email; there is no guest account with scoped read. Retains calendar_scheduling and messaging_notifications. (Self-correction: applied by me earlier in this repair pass.)",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows OpenRestoApi/ + openresto-frontend/ + 5 docker-compose files + nginx/; deployable restaurant reservation product -> product"
}
OSS-195record 195
{
"id": "OSS-195",
"repo": "clawnify/OpenSalon",
"url": "https://github.com/clawnify/OpenSalon",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/clawnify/OpenSalon API license.spdx_id = MIT; standard OSI identifier. Repo size is 1282 KB against 32 stars — a young, small codebase.",
"capability_kinds": [
"calendar_scheduling",
"crm",
"billing"
],
"composite_contents": [
"ui",
"data",
"workflow",
"auth",
"billing",
"host_chrome"
],
"composite_repo": true,
"reuse_shape_recommendation": "transplant",
"quality_signals": {
"stars": 32,
"pushed_at": "2026-08-22",
"days_since_push": 5,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 1282
},
"adaptation_risks": "At 32 stars with a 2026 first push this has no production evidence whatsoever and the maintainer operates a family of similarly-named vertical clones (OpenDentist, and others surfaced by the same search), which is a template-farm signal rather than a sustained project. Listed as an honest data point on what appointment-vertical OSS actually looks like at the small end, not as a recommendation.",
"claim": "clawnify/OpenSalon supplies calendar_scheduling, crm, billing at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reject",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "composite_contents ui+data+workflow+auth+billing+host_chrome; salon booking app, but 32 stars and disposition=reject -> product (unmaintained)"
}
OSS-196record 196
{
"id": "OSS-196",
"repo": "UretzkyZvi/planner",
"url": "https://github.com/UretzkyZvi/planner",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/UretzkyZvi/planner API license.spdx_id = MIT; standard OSI identifier. Described upstream as a React component integrating with shadcn/ui, consistent with component-library rather than application packaging.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 443,
"pushed_at": "2024-11-03",
"days_since_push": 662,
"maintenance": "stale",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 3,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": false,
"containerized": false,
"repo_size_kb": 3393
},
"adaptation_risks": "A scheduling UI component only — drag-and-drop appointment surface with no availability engine, no persistence and no booking rules behind it. pushed_at 2024-11-03 makes it stale by roughly 21 months. Solves the calendar-rendering half of the problem, which is the half that is least scarce.",
"claim": "UretzkyZvi/planner supplies calendar_scheduling at stale maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "gh api contents shows Next.js scaffold with src/ + components.json + tailwind config, composite_contents=[ui] only; a scheduling UI component/demo, no data model or identity -> primitive"
}
OSS-197record 197
{
"id": "OSS-197",
"repo": "City-of-Helsinki/respa",
"url": "https://github.com/City-of-Helsinki/respa",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/City-of-Helsinki/respa API license.spdx_id = MIT, and the repos API reports archived = true with pushed_at 2024-04-05 — an archived repository, read-only upstream.",
"capability_kinds": [
"calendar_scheduling",
"admin_data"
],
"composite_contents": [
"data",
"workflow",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "pattern",
"quality_signals": {
"stars": 83,
"pushed_at": "2024-04-05",
"days_since_push": 874,
"maintenance": "archived",
"archived": true,
"primary_language": "Python",
"open_issues": 0,
"monorepo_layout": false,
"tests_visible_at_root": false,
"docs_dir_visible": true,
"ci_configured": false,
"containerized": true,
"repo_size_kb": 2638
},
"adaptation_risks": "ARCHIVED upstream (repos API archived=true), so there will be no security fixes and no dependency updates on a Python/Django codebase last pushed 2024-04-05. MIT rights are clean and the resource-reservation domain model (bookable resources with availability rules) is genuinely well-designed by a municipal team, which is why it is worth reading — but it must not be adopted as a live dependency.",
"claim": "City-of-Helsinki/respa supplies calendar_scheduling, admin_data at archived maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "reference",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "product",
"supply_tier_evidence": "gh api contents shows manage.py + respa/ respa_admin/ users/ payments/ notifications/ reports/ + Dockerfile + docker-compose.yml; full Django resource-reservation product -> product"
}
OSS-198record 198
{
"id": "OSS-198",
"repo": "jkbrzt/rrule",
"url": "https://github.com/jkbrzt/rrule",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "NOASSERTION",
"license_class": "permissive",
"license_evidence": "repos/jkbrzt/rrule API license.spdx_id = NOASSERTION, so repos/.../license was fetched and decoded. The body is a verbatim three-clause BSD text — 'Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met' with the retain-notice, reproduce-notice and no-endorsement clauses — i.e. BSD-3-Clause. The API's NOASSERTION is a detection artefact of the file being named LICENCE (British spelling), not an actual absence of grant.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"data"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 3742,
"pushed_at": "2024-06-27",
"days_since_push": 791,
"maintenance": "stale",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 211,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 4601
},
"adaptation_risks": "The API reports NOASSERTION and any automated licence gate will wrongly flag this widely-used package as unlicensed; the real grant is BSD-3-Clause, readable only from the LICENCE body. Scope is recurrence-rule computation (RFC 5545 RRULE) alone — no availability model, no booking — but it is the correct primitive for the recurrence half and pushed_at 2024-06-27 reflects a stable, finished library rather than abandonment.",
"claim": "jkbrzt/rrule supplies calendar_scheduling at stale maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data] only, extracted_package; RFC-5545 recurrence-rule library -> primitive"
}
OSS-199record 199
{
"id": "OSS-199",
"repo": "fullcalendar/fullcalendar",
"url": "https://github.com/fullcalendar/fullcalendar",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "MIT",
"license_class": "permissive",
"license_evidence": "repos/fullcalendar/fullcalendar API license.spdx_id = MIT; standard OSI identifier. Note the historical trap: FullCalendar's premium/Scheduler timeline features are distributed separately under a paid commercial licence, so the MIT here covers this repository's standard views only and does not extend to the Scheduler add-on.",
"capability_kinds": [
"calendar_scheduling"
],
"composite_contents": [
"ui"
],
"composite_repo": false,
"reuse_shape_recommendation": "embedded_module",
"quality_signals": {
"stars": 20621,
"pushed_at": "2026-07-24",
"days_since_push": 34,
"maintenance": "active",
"archived": false,
"primary_language": "TypeScript",
"open_issues": 1130,
"monorepo_layout": true,
"tests_visible_at_root": false,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 33777
},
"adaptation_risks": "MIT covers this repo, but the resource-timeline/Scheduler views many booking UIs actually want are a separately licensed commercial product from the same vendor — the classic way an MIT badge understates the real cost of the feature set. Rendering only: no availability engine, no persistence, no booking workflow.",
"claim": "fullcalendar/fullcalendar supplies calendar_scheduling at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[ui] only, embedded_module monorepo; calendar rendering widget, no backend/data/identity -> primitive"
}
OSS-200record 200
{
"id": "OSS-200",
"repo": "sabre-io/dav",
"url": "https://github.com/sabre-io/dav",
"observed_date": "2026-08-27",
"evidence_class": "E",
"license_declared": "BSD-3-Clause",
"license_class": "permissive",
"license_evidence": "repos/sabre-io/dav API license.spdx_id = BSD-3-Clause; standard OSI identifier. It is the PHP CalDAV/CardDAV framework underneath several products in this survey (tchapi/davis is an admin UI over it), which makes it infrastructure rather than an endpoint product.",
"capability_kinds": [
"calendar_scheduling",
"files_documents"
],
"composite_contents": [
"data",
"auth"
],
"composite_repo": false,
"reuse_shape_recommendation": "extracted_package",
"quality_signals": {
"stars": 1720,
"pushed_at": "2026-08-02",
"days_since_push": 25,
"maintenance": "active",
"archived": false,
"primary_language": "PHP",
"open_issues": 191,
"monorepo_layout": false,
"tests_visible_at_root": true,
"docs_dir_visible": false,
"ci_configured": true,
"containerized": false,
"repo_size_kb": 15130
},
"adaptation_risks": "Protocol framework, not a booking product: it gives you a CalDAV/CardDAV server to build on, with no availability rules, no booking page and no scheduling UX. PHP-only, which constrains where it can sit. Correct choice if the requirement is standards-based calendar interoperability; wrong one if the requirement is a client booking flow.",
"claim": "sabre-io/dav supplies calendar_scheduling, files_documents at active maintenance under a permissive rights posture.",
"limitations": "Metadata, LICENSE body and top-level contents observed via GitHub API only. No clone, build, execution, dependency-tree/SBOM scan, runtime, tenancy or performance verification was performed in this lane.",
"disposition": "candidate",
"provenance_lane": "s1l2_oss_survey",
"supply_tier": "primitive",
"supply_tier_evidence": "composite_contents=[data,auth], extracted_package; CalDAV/CardDAV server library you embed in a PHP app -> primitive"
}
SUMMARYrecord 201
{
"id": "SUMMARY",
"provenance_lane": "s1l2_oss_survey",
"observed_date": "2026-08-27",
"repos_queried": 237,
"repos_resolved_by_api": 236,
"api_errors": 1,
"unique_repos_after_redirect_dedupe": 205,
"stale_identity_redirects_observed": 24,
"license_bodies_fetched_and_read": 60,
"verified_records_written": 200,
"distinct_capability_kinds": 24,
"counts_by_capability_kind": {
"files_documents": 27,
"notes_docs": 23,
"admin_data": 22,
"auth_identity": 19,
"crm": 17,
"inventory": 17,
"billing": 17,
"messaging_notifications": 16,
"analytics_bi": 15,
"calendar_scheduling": 15,
"approvals_workflow": 14,
"case_workflow": 13,
"project_management": 13,
"airtable_data": 11,
"forms": 11,
"e_sign": 11,
"search": 11,
"support_desk": 10,
"e_commerce": 8,
"lms": 7,
"field_ops": 5,
"connectors": 4,
"portal": 2,
"developer_docs_rendering": 1
},
"counts_by_license_class": {
"weak-copyleft": 13,
"strong-copyleft": 63,
"permissive": 85,
"source-available": 14,
"permissive-open-core": 13,
"none-declared": 1,
"source-available-mixed": 1,
"strong-copyleft-open-core": 8,
"mixed-copyleft": 1,
"strong-copyleft-dual": 1
},
"counts_by_disposition": {
"reference": 101,
"candidate": 69,
"reject": 21,
"hold": 9
},
"counts_by_reuse_shape": {
"pattern": 108,
"intact_service": 44,
"extracted_package": 23,
"embedded_module": 13,
"transplant": 10,
"adapter": 2
},
"archived_repos_detected": [
"jentic/jentic-sdks",
"Peppermint-Lab/peppermint",
"minio/minio",
"ohmyform/ohmyform",
"tellform/tellform",
"frappe/drive",
"City-of-Helsinki/respa"
],
"top10_by_client_adaptation_value": [
"pocketbase/pocketbase",
"payloadcms/payload",
"calcom/cal.diy",
"medusajs/medusa",
"BookStackApp/BookStack",
"inventree/InvenTree",
"temporalio/temporal",
"keystonejs/keystone",
"better-auth/better-auth",
"TryGhost/Ghost"
],
"method": "gh api repos/{owner}/{repo} for metadata; gh api repos/{owner}/{repo}/license with base64-decoded body for every NOASSERTION/OTHER/null row; gh api repos/{owner}/{repo}/contents for top-level structure signals. Prior 500-row corpus and Phase-8 template shelf mined for seeds only; no metadata inherited as a rights verdict. REPAIR PASS 2026-08-27: calendar_scheduling and e_sign re-surveyed via gh search repos across topic (digital-signature, esignature, pdf-signature, scheduling, scheduler, booking, appointment-scheduling, calendar, reservation, caldav) and keyword lanes; each candidate verified with gh api repos/{owner}/{repo}, with repos/{owner}/{repo}/license base64-decoded for every NOASSERTION and repos/{owner}/{repo}/contents read for open-core carve-outs. Separately, the 27 permissive-and-'pattern' rows had their reuse shape re-derived from observed top-level structure. No clone, build, or execution at any point.",
"not_established": "No clone, build, execution, benchmark, dependency-tree or SBOM scan, runtime behaviour, tenancy isolation, auth authority, security or legal review. No repo is admitted. Sub-directory and transitive dependency licenses are UNVERIFIED. Capability-kind assignment and reuse-shape recommendation are I-class judgement over E-class observations. Additionally: for OSS-185 (jsignpdf) the per-component licence mapping is INFERRED from a pointer file, since distribution/licenses/MPL-2.0.txt and distribution/licenses/lgpl-2.1.txt were not themselves fetched. For OSS-178 (OpenSign) the terms governing apps/OpenSignServer/cloud/customRoute are NOT ESTABLISHED: the LICENSE header defers to a licence file in that directory, the directory exists with four code items, and no licence file is present in it.",
"api_error_detail": "gh api repos/easyappointments/easyappointments -> HTTP 404 Not Found. The widely cited org path does not exist; canonical repo resolved to alextselegidis/easyappointments and recorded as OSS-187.",
"repair_pass_added_rows": {
"total": 24,
"calendar_scheduling": 14,
"e_sign": 10,
"final_calendar_scheduling_count": 15,
"final_e_sign_count": 11,
"reason": "Parent audit found calendar_scheduling=1 and e_sign=1 in the pre-repair file, which was a survey gap presenting as supply scarcity and corrupting the commodity/scarce/missing classification. Both kinds were re-surveyed from GitHub topic and keyword search and every new repo verified via repos API metadata, with the LICENSE body decoded wherever spdx_id was NOASSERTION.",
"scarcity_finding": "Neither kind is scarce in raw count, but both are scarce in the only dimension that matters for a proprietary client deliverable. Of 15 calendar_scheduling rows only 9 are permissive/weak-copyleft, and every full booking PRODUCT found (easyappointments GPL-3.0, rallly AGPL-3.0, tymeslot AGPL-3.0, timegrid AGPL-3.0-and-archived, cal.diy the sole MIT exception) is copyleft or is the one MIT outlier. The permissive scheduling supply is components (fullcalendar, rrule, planner) and frameworks (sabre/dav), not booking systems. E-sign is sharper still: every one of the four DocuSign-alternative PRODUCTS is AGPL (documenso, docuseal, OpenSign, libresign) and all six permissive/weak-copyleft e_sign rows are signing LIBRARIES with no request/collect workflow, no signer identity and no audit trail. So the honest finding is: for both kinds the reusable-under-permissive supply covers the primitive layer only, and the product layer would have to be built.",
"repos_added": [
"docusealco/docuseal",
"OpenSignLabs/OpenSign",
"LibreSign/libresign",
"vbuch/node-signpdf",
"MatthiasValvekens/pyHanko",
"digitorus/pdfsign",
"esig/dss",
"Keyfactor/signserver-ce",
"intoolswetrust/jsignpdf",
"24eme/signaturepdf",
"alextselegidis/easyappointments",
"lukevella/rallly",
"thunderbird/appointment",
"Tymeslot/tymeslot",
"adamspd/django-appointment",
"rbbydotdev/someday",
"linkedin/oncall",
"karanshukla/openresto",
"clawnify/OpenSalon",
"UretzkyZvi/planner",
"City-of-Helsinki/respa",
"jkbrzt/rrule",
"fullcalendar/fullcalendar",
"sabre-io/dav"
]
},
"repair_pass_shape_revisions": {
"rows_examined": 27,
"scope": "Rows where license_class is permissive or permissive-open-core AND reuse_shape_recommendation was 'pattern'. Copyleft and source-available rows were deliberately not touched: 'pattern' is correct there for rights reasons, not technical ones.",
"reassigned": 18,
"kept_as_pattern": 9,
"note": "Original count was 27, not the ~28 estimated by the audit. Shapes were decided from observed top-level repository structure via gh api repos/{owner}/{repo}/contents, and each row now carries a shape_revision_note recording the seam evidence.",
"changes": [
{
"id": "OSS-005",
"repo": "BuilderIO/builder",
"from": "pattern",
"to": "extracted_package"
},
{
"id": "OSS-019",
"repo": "Sylius/Sylius",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-034",
"repo": "bagisto/bagisto",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-048",
"repo": "decaporg/decap-cms",
"from": "pattern",
"to": "embedded_module"
},
{
"id": "OSS-076",
"repo": "grocy/grocy",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-078",
"repo": "hasura/graphql-engine",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-086",
"repo": "jentic/jentic-sdks",
"from": "pattern",
"to": "adapter"
},
{
"id": "OSS-092",
"repo": "kiegroup/jbpm",
"from": "pattern",
"to": "extracted_package"
},
{
"id": "OSS-097",
"repo": "lucia-auth/lucia",
"from": "pattern",
"to": "extracted_package"
},
{
"id": "OSS-098",
"repo": "maildev/maildev",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-117",
"repo": "nhost/nhost",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-134",
"repo": "papermerge/papermerge-core",
"from": "pattern",
"to": "intact_service"
},
{
"id": "OSS-146",
"repo": "saeloun/miru-web",
"from": "pattern",
"to": "transplant"
},
{
"id": "OSS-148",
"repo": "sanity-io/sanity",
"from": "pattern",
"to": "embedded_module"
},
{
"id": "OSS-152",
"repo": "solidusio/solidus",
"from": "pattern",
"to": "extracted_package"
},
{
"id": "OSS-153",
"repo": "spree/spree",
"from": "pattern",
"to": "extracted_package"
},
{
"id": "OSS-162",
"repo": "tinacms/tinacms",
"from": "pattern",
"to": "embedded_module"
},
{
"id": "OSS-169",
"repo": "usememos/memos",
"from": "pattern",
"to": "intact_service"
}
],
"kept": [
{
"id": "OSS-012",
"repo": "PostHog/posthog",
"shape": "pattern"
},
{
"id": "OSS-016",
"repo": "RocketChat/Rocket.Chat",
"shape": "pattern"
},
{
"id": "OSS-018",
"repo": "Sunbird-Ed/SunbirdEd-portal",
"shape": "pattern"
},
{
"id": "OSS-035",
"repo": "baserow/baserow",
"shape": "pattern"
},
{
"id": "OSS-073",
"repo": "gitlabhq/gitlabhq",
"shape": "pattern"
},
{
"id": "OSS-080",
"repo": "helpyio/helpy",
"shape": "pattern"
},
{
"id": "OSS-095",
"repo": "lightdash/lightdash",
"shape": "pattern"
},
{
"id": "OSS-160",
"repo": "tellform/tellform",
"shape": "pattern"
},
{
"id": "OSS-164",
"repo": "toeverything/AFFiNE",
"shape": "pattern"
}
]
},
"top10_revision_note": "Unchanged. The top 10 was re-evaluated against all 24 newly surveyed scheduling and e-sign rows and none displaces an incumbent. The reason is structural rather than a matter of degree: entry to this list requires a repo that is both permissively licensed and a deployable/adoptable product, and the repair pass established that for these two kinds that combination essentially does not exist. Every scheduling and e-signature PRODUCT found is copyleft (easyappointments GPL-3.0; rallly, tymeslot, documenso, docuseal, libresign, signaturepdf AGPL-3.0; OpenSign AGPL with an unlicensed customRoute carve-out), and every permissive row is a component or library that is too narrow to carry a top-10 slot (rrule is recurrence maths, fullcalendar is rendering, node-signpdf/pyHanko/pdfsign are signature primitives, sabre/dav is a protocol framework). The two closest near-misses are recorded here rather than promoted: thunderbird/appointment (MPL-2.0, the only full scheduling product with a non-blocking licence, held back by 212 open issues against 550 stars and a pulumi/ deployment path aimed at the vendor's own cloud) and MatthiasValvekens/pyHanko (MIT, high-quality, but a library rather than an e-sign product). calcom/cal.diy therefore remains the correct scheduling entry, and this pass strengthens rather than weakens its position: it is now demonstrably the only permissively licensed full scheduling product in a field of 15.",
"lane_owner_kind_revisions": 19,
"lane_owner_kind_revision_note": "Portal re-tag applied against the Phase-8 archetype bar (untrusted external identity + scoped read + request submission). 19 rows demoted on observed repo auth-surface evidence (contents API), not descriptions. Lane owner's first pass demoted 13; the repair subagent's independent pass demoted 19 with stronger evidence and was adopted, including the correction that anonymous public booking forms (easyappointments, rallly, tymeslot, thunderbird/appointment, openresto) are NOT scoped-read portals. Survivors: open-formulieren/open-forms (EUPL-1.2, the unambiguous archetype instance) and nextcloud/server (AGPL-3.0, external-share identity, file-sharing product not a purpose-built portal). Portal clean permissive+candidate supply = 0.",
"redoc_reassignment_note": "Repair subagent reassigned Redocly/redoc portal->notes_docs to avoid a kindless row. Lane owner overturned: re-tagged developer_docs_rendering (outside the 24-kind client-capability taxonomy) and dropped to reference. Rationale: notes_docs means authoring; a spec renderer cannot serve it, and counting it there would inflate the kind.",
"counts_by_supply_tier": {
"primitive": 46,
"product": 134,
"framework": 20
},
"product_primitive_pass_date": "2026-08-27",
"lane_owner_tier_corrections": 1,
"lane_owner_tier_correction_note": "Keyfactor/signserver-ce re-tiered product -> primitive by lane owner. The subagent's evidence string already said it lacks signer workflow; a signing-authority/HSM service is infrastructure, not an e-signature product."
}