Back to home
Open sourceDependenciesRelease review

Third-Party Notices

Open-source dependency notice process for backend, frontend, tests, build tooling, and scripts.

Last updated: May 9, 2026

Notice Process

  • Install dependencies from committed lockfiles before each production release.
  • Generate dependency and license reports for root, backend, frontend, and landing packages.
  • Review copyleft, source-available, commercial, unknown, deprecated, or unlicensed packages.
  • Include required license texts and attributions in distributed product or customer documentation.

Direct Package Areas

The current product uses React, Material UI, Express, Prisma, PostgreSQL, Socket.IO, PDF, spreadsheet, authentication, email, and monitoring-related packages. Transitive dependencies must be scanned before distribution.

Release Archive

A dependency tree, license scan, attribution file, and any source-offer instructions required by third-party licenses should be archived with each production release artifact.

Third-Party Notices — Hevra ERP