Files
peardock/docs/SBOM.md
T
2026-07-11 20:11:02 -04:00

1.6 KiB

Software bill of materials notes

peardock is a Node.js / Bare application. License: AGPL-3.0. For production releases, generate an SBOM from the lockfile.

Generate SBOM

# CycloneDX (requires @cyclonedx/cyclonedx-npm)
npx @cyclonedx/cyclonedx-npm --output-file peardock-sbom.json

# Or SPDX via syft if installed
# syft dir:. -o spdx-json > peardock-sbom.spdx.json

Runtime dependencies (direct)

See package.json / package-lock.json. Major surface:

Package Role
hyperdht P2P transport (Noise / DHT)
protomux / protomux-rpc Multiplexed RPC
compact-encoding / b4a Codecs
dockerode Docker Engine API
js-yaml Compose parse
dotenv Config
graceful-goodbye Shutdown
hypercore-crypto Key material
holesail Required P2P TCP/UDP tunnels (on by default; ENABLE_HOLESAIL=0 to disable). AGPL-3.0
pear-electron / pear-bridge Pear desktop shell
which-runtime Bare vs Node branching

Electron packaging (client) pulls additional deps via electron-forge / esbuild at build time; those are not all listed as runtime dependencies for the server.

Known-sensitive native deps

  • sodium-native / udx-native (via hyperdht tree): audit on upgrades

License

AGPL-3.0 (project, same family as Holesail). Holesail integration is also AGPL-3.0 (holesail / related packages). Review transitive licenses before redistribution. Network operators of modified builds should document AGPL source-offer obligations (AGPL §13).

Public notices: peardock.boats/legal/license.