DeepSeek Harness is licensed under BSD 3-Clause. It depends on the third-party open-source software listed below. Each project remains under its own license; nothing in this file changes those terms.
This file lists direct dependencies declared by the workspace. It is generated from the workspace manifests by scripts/gen-third-party-notices.ts: a pre-commit hook regenerates it whenever a staged file changes one of its inputs, and scripts/gen-third-party-notices.spec.ts asserts in the test lane that the committed bytes match. Deleting a manifest runs no hook, so that case is caught by the assertion instead. Run pnpm run verify-third-party-notices for the standalone check.
The complete npm transitive closure, with exact pinned versions, is recorded in pnpm-lock.yaml — inspect it with pnpm licenses list. The Python closure is recorded in python/sdk/uv.lock, and the Landlock launcher workspace keeps its own in native/landlock-run/pnpm-lock.yaml.
vendor/)The Cordis framework and its foundation libraries are source-vendored into this repository rather than consumed from npm. All are MIT-licensed; each directory preserves its upstream LICENSE file. Exact upstream commits and local modifications are recorded in vendor/README.md.
| Package | Upstream | License |
|---|---|---|
cosmokit |
github.com/deepseek-harness/cosmokit | MIT |
schemastery |
github.com/deepseek-harness/schemastery | MIT |
cordis |
github.com/cordiverse/cordis | MIT |
@cordisjs/plugin-loader |
github.com/cordiverse/cordis | MIT |
@cordisjs/plugin-include |
github.com/deepseek-harness/cordis | MIT |
@cordisjs/plugin-group |
github.com/deepseek-harness/cordis | MIT |
@cordisjs/plugin-timer |
github.com/deepseek-harness/cordis | MIT |
@cordisjs/plugin-hmr |
github.com/deepseek-harness/cordis | MIT |
@cordisjs/plugin-logger-console |
github.com/deepseek-harness/cordis | MIT |
External packages that a workspace package resolves at runtime. scripts/install.sh installs this repository itself, so the tier covers every plugin a user can mount from cordis.yml — not only what the dsh CLI/TUI, the Web UI, and the Python SDK runtime load by default.
pnpm applies local patches to the following packages at install time, so shipped artifacts carry modified copies; each patch file is the complete record of the modification:
node-pty@1.1.0 — patches/node-pty@1.1.0.patchExternal packages directly declared only by repository tooling, test infrastructure, the documentation site, the demo leaves, or the native launcher's build workspace. No shipped surface names them itself. A package here may still be pulled in transitively by a runtime dependency — pnpm-lock.yaml is the authority on the full closure — so this tier records who declares a package, not what a build ultimately bundles.
eslint-plugin-sonarjs (LGPL-3.0-only) and lightningcss (MPL-2.0) run only as development tooling; their code is not linked into or distributed with any DeepSeek Harness artifact.
python/)Direct dependencies of the pyproject.toml manifests, plus uv as the development workflow tool.
| Package | License | Role |
|---|---|---|
hatchling |
MIT | build backend |
pydantic |
MIT | runtime dependency of deepseek-harness |
pytest |
MIT | test-only |
uv |
MIT / Apache-2.0 | development workflow tool |
| Package | License | Role |
|---|---|---|
@yao-pkg/pkg |
MIT | invoked by scripts/build-exe-for-python-sdk.ts to assemble the single-file SDK runtime executable |
node-addon-landlock-run (and its platform packages) is released from a DeepSeek Harness sibling repository under BSD 3-Clause. It is listed here for completeness; it is first-party, not third-party.