Third-Party Notices
ember itself is original work, released under the MIT License (see LICENSE).
This file lists the third-party code the project installs and runs, for license
compliance and audit. For data (model weights, brand assets, prompts), see
PROVENANCE.md instead.
The machine-readable inventory is provenance.json. Its
dependencies.inventory records every locked package in uv.lock, with its version,
registry source, artifact URLs and hashes, and the license metadata installed on this
machine. Check it offline with:
python3 scripts/check_provenance.py
Note: The licenses below are read from installed distribution metadata and are evidence only, not an SPDX-certified or complete legal audit.
provenance.jsonrecords missing metadata explicitly. Confirm a license at its source before relying on it.
Runtime dependencies
These ship as dependencies of the gut distribution and run when ember serves advice.
| Package | Version (as installed) | License (as installed) | Role |
|---|---|---|---|
| torch | 2.14.1 | Apache-2.0 with LLVM exception, BSD-2-Clause, BSD-3-Clause, BSL-1.0, MIT | Tensor runtime and the MPS backend |
| torchvision | 0.29.1 | BSD | Image transforms required by transformers |
| transformers | 5.18.0 | Apache-2.0 | Model loading and the Clef processor |
| safetensors | 0.8.0 | Apache-2.0 (classifier) | Weight file format |
| huggingface-hub | 1.33.0 | Apache-2.0 | Weight download and cache |
| accelerate | 1.15.0 | Apache-2.0 | Device placement helpers |
| pillow | 12.3.0 | MIT-CMU | Image decoding for vision inputs |
| fastapi | 0.142.2 | MIT | The model server HTTP API |
| uvicorn | 0.54.0 | BSD-3-Clause | ASGI server |
| pydantic | 2.13.5 | MIT | Request and response schemas |
| mcp | 2.3.0 | MIT | The MCP stdio server |
| httpx | 0.28.1 | BSD-3-Clause | MCP to server HTTP calls |
| prometheus-client | 0.26.0 | Apache-2.0, BSD-2-Clause | /metrics endpoint |
Note:
torchbundles many vendored components under their own licenses (for example CUDA, oneDNN, and protobuf). Its wheels carry those notices undertorch-*-dist-info/licenses/, andprovenance.jsonhashes each file. Review them for a distribution audit. The same applies totorchvision.
Development dependencies
Installed for contributors and CI. They are not part of the runtime distribution.
| Package | Version (as installed) | License | Role |
|---|---|---|---|
| ruff | 0.16.10 | MIT | Formatter and linter |
| mypy | 2.4.0 | MIT | Static type checker |
| bandit | 1.9.4 | Apache-2.0 | Security scanner |
| pytest | 9.1.1 | MIT | Test runner |
| pytest-cov | 7.1.0 | MIT | Coverage plugin |
| pyyaml | 6.0.3 | MIT | YAML parsing in tests and scripts |
| commitizen | 4.19.0 | MIT | Conventional commits and version bumps |
Model artifacts
The Clef model weights and joint_schema_model.py are upstream Cloudflare work, licensed
Apache-2.0. They are downloaded at runtime from Hugging Face and are not
redistributed in this repository or the gut distribution. provenance.json records each
model’s repository, pinned revision, license, and distribution status.
See also: PROVENANCE.md for material origins, and
COMPATIBILITY.md for tested versions.