ember

Third-Party Notices

ember itself is original work, released under the MIT License (see LICENSE). This file lists the third-party code the project installs and runs, for license compliance and audit. For data (model weights, brand assets, prompts), see PROVENANCE.md instead.

The machine-readable inventory is provenance.json. Its dependencies.inventory records every locked package in uv.lock, with its version, registry source, artifact URLs and hashes, and the license metadata installed on this machine. Check it offline with:

python3 scripts/check_provenance.py

Note: The licenses below are read from installed distribution metadata and are evidence only, not an SPDX-certified or complete legal audit. provenance.json records missing metadata explicitly. Confirm a license at its source before relying on it.

Runtime dependencies

These ship as dependencies of the gut distribution and run when ember serves advice.

Package Version (as installed) License (as installed) Role
torch 2.14.1 Apache-2.0 with LLVM exception, BSD-2-Clause, BSD-3-Clause, BSL-1.0, MIT Tensor runtime and the MPS backend
torchvision 0.29.1 BSD Image transforms required by transformers
transformers 5.18.0 Apache-2.0 Model loading and the Clef processor
safetensors 0.8.0 Apache-2.0 (classifier) Weight file format
huggingface-hub 1.33.0 Apache-2.0 Weight download and cache
accelerate 1.15.0 Apache-2.0 Device placement helpers
pillow 12.3.0 MIT-CMU Image decoding for vision inputs
fastapi 0.142.2 MIT The model server HTTP API
uvicorn 0.54.0 BSD-3-Clause ASGI server
pydantic 2.13.5 MIT Request and response schemas
mcp 2.3.0 MIT The MCP stdio server
httpx 0.28.1 BSD-3-Clause MCP to server HTTP calls
prometheus-client 0.26.0 Apache-2.0, BSD-2-Clause /metrics endpoint

Note: torch bundles many vendored components under their own licenses (for example CUDA, oneDNN, and protobuf). Its wheels carry those notices under torch-*-dist-info/licenses/, and provenance.json hashes each file. Review them for a distribution audit. The same applies to torchvision.

Development dependencies

Installed for contributors and CI. They are not part of the runtime distribution.

Package Version (as installed) License Role
ruff 0.16.10 MIT Formatter and linter
mypy 2.4.0 MIT Static type checker
bandit 1.9.4 Apache-2.0 Security scanner
pytest 9.1.1 MIT Test runner
pytest-cov 7.1.0 MIT Coverage plugin
pyyaml 6.0.3 MIT YAML parsing in tests and scripts
commitizen 4.19.0 MIT Conventional commits and version bumps

Model artifacts

The Clef model weights and joint_schema_model.py are upstream Cloudflare work, licensed Apache-2.0. They are downloaded at runtime from Hugging Face and are not redistributed in this repository or the gut distribution. provenance.json records each model’s repository, pinned revision, license, and distribution status.

See also: PROVENANCE.md for material origins, and COMPATIBILITY.md for tested versions.