Third-Party Notices

DeepSeek Harness is licensed under MIT. It depends on the third-party software listed below. Each project remains under its own license; nothing in this file changes those terms.

This file lists direct dependencies declared by the workspace and the explicitly disclosed official Claude platform payload closure. It is generated from the workspace manifests by scripts/gen-third-party-notices.ts: a pre-commit hook regenerates it whenever a staged file changes one of its inputs, and scripts/gen-third-party-notices.spec.ts asserts in the test lane that the committed bytes match. Deleting a manifest runs no hook, so that case is caught by the assertion instead. Run pnpm run verify-third-party-notices for the standalone check.

The complete npm transitive closure, including the Landlock launcher workspace, is recorded with exact pinned versions in pnpm-lock.yaml — inspect it with pnpm licenses list. The Python closure is recorded separately in python/sdk/uv.lock.

Vendored source (vendor/)

The Cordis framework and its foundation libraries are source-vendored into this repository rather than consumed from npm, and republished under the @deepseek-ai scope. All are MIT-licensed; each directory preserves its upstream LICENSE file. Exact upstream commits and local modifications are recorded in vendor/README.md.

Package Upstream name Upstream License
@deepseek-ai/cosmokit cosmokit github.com/deepseek-harness/cosmokit MIT
@deepseek-ai/schemastery schemastery github.com/deepseek-harness/schemastery MIT
@deepseek-ai/cordis cordis github.com/cordiverse/cordis MIT
@deepseek-ai/cordis-plugin-loader @cordisjs/plugin-loader github.com/cordiverse/cordis MIT
@deepseek-ai/cordis-plugin-include @cordisjs/plugin-include github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-group @cordisjs/plugin-group github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-timer @cordisjs/plugin-timer github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-hmr @cordisjs/plugin-hmr github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-logger-console @cordisjs/plugin-logger-console github.com/deepseek-harness/cordis MIT

Runtime npm dependencies

External packages that a workspace package resolves at runtime. The tier covers every plugin a user can mount from cordis.yml — not only what the dsh CLI, Web UI, and Python SDK runtime load by default.

Package License
@agentclientprotocol/sdk Apache-2.0
@anthropic-ai/claude-agent-sdk SEE LICENSE IN README.md
@anthropic-ai/sdk MIT
@babel/code-frame MIT
@earendil-works/pi-ai MIT
@joplin/turndown-plugin-gfm MIT
@jridgewell/gen-mapping MIT
@modelcontextprotocol/sdk MIT
@opentelemetry/api Apache-2.0
@opentelemetry/api-logs Apache-2.0
@opentelemetry/exporter-logs-otlp-http Apache-2.0
@opentelemetry/otlp-exporter-base Apache-2.0
@opentelemetry/resources Apache-2.0
@opentelemetry/sdk-logs Apache-2.0
@shikijs/langs MIT
@standard-schema/spec MIT
@tanstack/react-virtual MIT
@types/mdast MIT
@vscode/ripgrep MIT
anser MIT
chokidar MIT
clsx MIT
commander MIT
diff BSD-3-Clause
e2b MIT
eventsource-parser MIT
fflate MIT
immer MIT
js-yaml MIT
katex MIT
koffi MIT
mdast-util-from-markdown MIT
mdast-util-gfm MIT
mdast-util-math MIT
micromark-core-commonmark MIT
micromark-extension-gfm MIT
micromark-extension-math MIT
micromark-factory-space MIT
micromark-util-character MIT
micromark-util-classify-character MIT
micromark-util-sanitize-uri MIT
micromark-util-symbol MIT
micromark-util-types MIT
node-addon-require-builtin MIT
node-pty MIT
picomatch MIT
react MIT
react-dom MIT
sharp Apache-2.0
shiki MIT
supports-color MIT
tsx MIT
turndown MIT
typescript Apache-2.0
use-sync-external-store MIT
ws MIT
yaml ISC
zod MIT
zustand MIT

pnpm applies local patches to the following packages at install time, so shipped artifacts carry modified copies; each patch file is the complete record of the modification:

Official Claude Code platform payloads

The project owner authorizes distribution of every version of the official @anthropic-ai/claude-agent-sdk package and the official Claude Code CLI/platform payloads that each version declares through optionalDependencies. This identity-scoped authorization does not classify their declared terms as permissive and does not cover any unrelated runtime package; version, declared-license, and payload-set changes still require the ordinary dependency, lockfile, compatibility, terms, and notices review.

The installed SDK 0.3.220 declares the following optional platform packages. Each carries the official Claude Code 2.1.220 executable; the package identities and versions come from the SDK manifest, while the declared license field is verified against the platform payload installed for the current host.

Optional platform package Version Declared license
@anthropic-ai/claude-agent-sdk-darwin-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-darwin-x64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-arm64-musl 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-x64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-x64-musl 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-win32-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-win32-x64 0.3.220 SEE LICENSE IN LICENSE.md

Development-only npm dependencies

External packages directly declared only by repository tooling, test infrastructure, the documentation site, the demo leaves, or the native launcher's build workspace. No shipped surface names them itself. A package here may still be pulled in transitively by a runtime dependency — pnpm-lock.yaml is the authority on the full closure — so this tier records who declares a package, not what a build ultimately bundles.

Package License
@braintree/sanitize-url MIT
@modelcontextprotocol/server-everything MIT / Apache-2.0
@modelcontextprotocol/server-filesystem MIT / Apache-2.0
@openai/codex Apache-2.0
@stylistic/eslint-plugin MIT
@testing-library/dom MIT
@testing-library/react MIT
@types/babel__code-frame MIT
@types/js-yaml MIT
@types/jsdom MIT
@types/node MIT
@types/picomatch MIT
@types/react MIT
@types/react-dom MIT
@types/spdx-expression-parse MIT
@types/turndown MIT
@types/ws MIT
@vitejs/plugin-react MIT
@vitest/coverage-v8 MIT
@yarnpkg/cli-dist BSD-2-Clause
cytoscape MIT
cytoscape-cose-bilkent MIT
dayjs MIT
debug MIT
esbuild MIT
eslint-plugin-sonarjs LGPL-3.0-only
execa MIT
fast-check MIT
istanbul-lib-report BSD-3-Clause
jscpd MIT
jsdom MIT
knip ISC
lefthook MIT
lightningcss MPL-2.0
mermaid MIT
oxlint MIT
oxlint-tsgolint MIT
playwright Apache-2.0
publint MIT
smol-toml BSD-3-Clause
spdx-expression-parse MIT
tsdown MIT
typescript-language-server Apache-2.0
vite MIT
vite-tsconfig-paths MIT
vitepress MIT
vitepress-plugin-mermaid MIT
vitest MIT

eslint-plugin-sonarjs (LGPL-3.0-only) and lightningcss (MPL-2.0) run only as development tooling; their code is not linked into or distributed with any DeepSeek Harness artifact.

Python SDK dependencies (python/)

Direct dependencies of the pyproject.toml manifests, plus uv as the development workflow tool.

Package License Role
hatchling MIT build backend
pydantic MIT runtime dependency of deepseek-harness-sdk
pytest MIT test-only
uv MIT / Apache-2.0 development workflow tool

Fetched at build time

Package License Role
@yao-pkg/pkg MIT invoked by scripts/build-exe-for-python-sdk.ts to assemble the single-file SDK runtime executable

First-party native packages

@deepseek-ai/node-addon-landlock-run (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.

This page has no Chinese translation yet; showing the English source.本页暂无中文版,以下为英文原文。

Third-Party Notices

DeepSeek Harness is licensed under MIT. It depends on the third-party software listed below. Each project remains under its own license; nothing in this file changes those terms.

This file lists direct dependencies declared by the workspace and the explicitly disclosed official Claude platform payload closure. It is generated from the workspace manifests by scripts/gen-third-party-notices.ts: a pre-commit hook regenerates it whenever a staged file changes one of its inputs, and scripts/gen-third-party-notices.spec.ts asserts in the test lane that the committed bytes match. Deleting a manifest runs no hook, so that case is caught by the assertion instead. Run pnpm run verify-third-party-notices for the standalone check.

The complete npm transitive closure, including the Landlock launcher workspace, is recorded with exact pinned versions in pnpm-lock.yaml — inspect it with pnpm licenses list. The Python closure is recorded separately in python/sdk/uv.lock.

Vendored source (vendor/)

The Cordis framework and its foundation libraries are source-vendored into this repository rather than consumed from npm, and republished under the @deepseek-ai scope. All are MIT-licensed; each directory preserves its upstream LICENSE file. Exact upstream commits and local modifications are recorded in vendor/README.md.

Package Upstream name Upstream License
@deepseek-ai/cosmokit cosmokit github.com/deepseek-harness/cosmokit MIT
@deepseek-ai/schemastery schemastery github.com/deepseek-harness/schemastery MIT
@deepseek-ai/cordis cordis github.com/cordiverse/cordis MIT
@deepseek-ai/cordis-plugin-loader @cordisjs/plugin-loader github.com/cordiverse/cordis MIT
@deepseek-ai/cordis-plugin-include @cordisjs/plugin-include github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-group @cordisjs/plugin-group github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-timer @cordisjs/plugin-timer github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-hmr @cordisjs/plugin-hmr github.com/deepseek-harness/cordis MIT
@deepseek-ai/cordis-plugin-logger-console @cordisjs/plugin-logger-console github.com/deepseek-harness/cordis MIT

Runtime npm dependencies

External packages that a workspace package resolves at runtime. The tier covers every plugin a user can mount from cordis.yml — not only what the dsh CLI, Web UI, and Python SDK runtime load by default.

Package License
@agentclientprotocol/sdk Apache-2.0
@anthropic-ai/claude-agent-sdk SEE LICENSE IN README.md
@anthropic-ai/sdk MIT
@babel/code-frame MIT
@earendil-works/pi-ai MIT
@joplin/turndown-plugin-gfm MIT
@jridgewell/gen-mapping MIT
@modelcontextprotocol/sdk MIT
@opentelemetry/api Apache-2.0
@opentelemetry/api-logs Apache-2.0
@opentelemetry/exporter-logs-otlp-http Apache-2.0
@opentelemetry/otlp-exporter-base Apache-2.0
@opentelemetry/resources Apache-2.0
@opentelemetry/sdk-logs Apache-2.0
@shikijs/langs MIT
@standard-schema/spec MIT
@tanstack/react-virtual MIT
@types/mdast MIT
@vscode/ripgrep MIT
anser MIT
chokidar MIT
clsx MIT
commander MIT
diff BSD-3-Clause
e2b MIT
eventsource-parser MIT
fflate MIT
immer MIT
js-yaml MIT
katex MIT
koffi MIT
mdast-util-from-markdown MIT
mdast-util-gfm MIT
mdast-util-math MIT
micromark-core-commonmark MIT
micromark-extension-gfm MIT
micromark-extension-math MIT
micromark-factory-space MIT
micromark-util-character MIT
micromark-util-classify-character MIT
micromark-util-sanitize-uri MIT
micromark-util-symbol MIT
micromark-util-types MIT
node-addon-require-builtin MIT
node-pty MIT
picomatch MIT
react MIT
react-dom MIT
sharp Apache-2.0
shiki MIT
supports-color MIT
tsx MIT
turndown MIT
typescript Apache-2.0
use-sync-external-store MIT
ws MIT
yaml ISC
zod MIT
zustand MIT

pnpm applies local patches to the following packages at install time, so shipped artifacts carry modified copies; each patch file is the complete record of the modification:

Official Claude Code platform payloads

The project owner authorizes distribution of every version of the official @anthropic-ai/claude-agent-sdk package and the official Claude Code CLI/platform payloads that each version declares through optionalDependencies. This identity-scoped authorization does not classify their declared terms as permissive and does not cover any unrelated runtime package; version, declared-license, and payload-set changes still require the ordinary dependency, lockfile, compatibility, terms, and notices review.

The installed SDK 0.3.220 declares the following optional platform packages. Each carries the official Claude Code 2.1.220 executable; the package identities and versions come from the SDK manifest, while the declared license field is verified against the platform payload installed for the current host.

Optional platform package Version Declared license
@anthropic-ai/claude-agent-sdk-darwin-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-darwin-x64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-arm64-musl 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-x64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-linux-x64-musl 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-win32-arm64 0.3.220 SEE LICENSE IN LICENSE.md
@anthropic-ai/claude-agent-sdk-win32-x64 0.3.220 SEE LICENSE IN LICENSE.md

Development-only npm dependencies

External packages directly declared only by repository tooling, test infrastructure, the documentation site, the demo leaves, or the native launcher's build workspace. No shipped surface names them itself. A package here may still be pulled in transitively by a runtime dependency — pnpm-lock.yaml is the authority on the full closure — so this tier records who declares a package, not what a build ultimately bundles.

Package License
@braintree/sanitize-url MIT
@modelcontextprotocol/server-everything MIT / Apache-2.0
@modelcontextprotocol/server-filesystem MIT / Apache-2.0
@openai/codex Apache-2.0
@stylistic/eslint-plugin MIT
@testing-library/dom MIT
@testing-library/react MIT
@types/babel__code-frame MIT
@types/js-yaml MIT
@types/jsdom MIT
@types/node MIT
@types/picomatch MIT
@types/react MIT
@types/react-dom MIT
@types/spdx-expression-parse MIT
@types/turndown MIT
@types/ws MIT
@vitejs/plugin-react MIT
@vitest/coverage-v8 MIT
@yarnpkg/cli-dist BSD-2-Clause
cytoscape MIT
cytoscape-cose-bilkent MIT
dayjs MIT
debug MIT
esbuild MIT
eslint-plugin-sonarjs LGPL-3.0-only
execa MIT
fast-check MIT
istanbul-lib-report BSD-3-Clause
jscpd MIT
jsdom MIT
knip ISC
lefthook MIT
lightningcss MPL-2.0
mermaid MIT
oxlint MIT
oxlint-tsgolint MIT
playwright Apache-2.0
publint MIT
smol-toml BSD-3-Clause
spdx-expression-parse MIT
tsdown MIT
typescript-language-server Apache-2.0
vite MIT
vite-tsconfig-paths MIT
vitepress MIT
vitepress-plugin-mermaid MIT
vitest MIT

eslint-plugin-sonarjs (LGPL-3.0-only) and lightningcss (MPL-2.0) run only as development tooling; their code is not linked into or distributed with any DeepSeek Harness artifact.

Python SDK dependencies (python/)

Direct dependencies of the pyproject.toml manifests, plus uv as the development workflow tool.

Package License Role
hatchling MIT build backend
pydantic MIT runtime dependency of deepseek-harness-sdk
pytest MIT test-only
uv MIT / Apache-2.0 development workflow tool

Fetched at build time

Package License Role
@yao-pkg/pkg MIT invoked by scripts/build-exe-for-python-sdk.ts to assemble the single-file SDK runtime executable

First-party native packages

@deepseek-ai/node-addon-landlock-run (and its platform packages) is built and released from this repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.