Skip to content

Third-Party Component Inventory ​

INFO

This page lists every third-party component distributed with this product: name, version, license, and upstream source. It matches the release you are reading.

This is the complete machine-generated inventory referenced by the Third-Party Notices. Every component distributed with the Software is listed below with its version, license, and upstream source, grouped by license.

Summary ​

LicenseComponents
Apache-2.035
BSD-2-Clause4
BSD-3-Clause28
ISC3
MIT74
MPL-2.04
OFL-1.13
Unlicense2
Undetermined1
Total154

Apache-2.0 ​

ComponentVersionEcosystemSource
github.com/akrylysov/pogrebv0.10.1Gohttps://github.com/akrylysov/pogreb
github.com/aws/aws-sdk-go-v2v1.41.7Gohttps://github.com/aws/aws-sdk-go-v2
github.com/aws/aws-sdk-go-v2/configv1.32.7Gohttps://github.com/aws/aws-sdk-go-v2/config
github.com/aws/aws-sdk-go-v2/credentialsv1.19.7Gohttps://github.com/aws/aws-sdk-go-v2/credentials
github.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.17Gohttps://github.com/aws/aws-sdk-go-v2/feature/ec2/imds
github.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.23Gohttps://github.com/aws/aws-sdk-go-v2/internal/configsources
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.23Gohttps://github.com/aws/aws-sdk-go-v2/internal/endpoints/v2
github.com/aws/aws-sdk-go-v2/internal/iniv1.8.4Gohttps://github.com/aws/aws-sdk-go-v2/internal/ini
github.com/aws/aws-sdk-go-v2/service/iamv1.53.10Gohttps://github.com/aws/aws-sdk-go-v2/service/iam
github.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.7Gohttps://github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
github.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.21Gohttps://github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
github.com/aws/aws-sdk-go-v2/service/signinv1.0.5Gohttps://github.com/aws/aws-sdk-go-v2/service/signin
github.com/aws/aws-sdk-go-v2/service/ssov1.30.9Gohttps://github.com/aws/aws-sdk-go-v2/service/sso
github.com/aws/aws-sdk-go-v2/service/ssooidcv1.35.13Gohttps://github.com/aws/aws-sdk-go-v2/service/ssooidc
github.com/aws/aws-sdk-go-v2/service/stsv1.41.6Gohttps://github.com/aws/aws-sdk-go-v2/service/sts
github.com/aws/smithy-gov1.25.1Gohttps://github.com/aws/smithy-go
github.com/dimchansky/utfbomv1.1.1Gohttps://github.com/dimchansky/utfbom
github.com/docker/go-unitsv0.5.0Gohttps://github.com/docker/go-units
github.com/ebitengine/puregov0.10.0Gohttps://github.com/ebitengine/purego
github.com/flier/gohsv1.2.2Gohttps://github.com/flier/gohs
github.com/glaslos/tlshv0.4.0Gohttps://github.com/glaslos/tlsh
github.com/google/shlexv0.0.0-20191202100458-e7afc7fbc510Gohttps://github.com/google/shlex
github.com/gosimple/unidecodev1.0.1Gohttps://github.com/gosimple/unidecode
github.com/klauspost/compressv1.18.5Gohttps://github.com/klauspost/compress
github.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddGohttps://github.com/modern-go/concurrent
github.com/modern-go/reflect2v1.0.2Gohttps://github.com/modern-go/reflect2
github.com/praetorian-inc/titusv1.2.0Gohttps://github.com/praetorian-inc/titus
github.com/sashabaranov/go-openaiv1.37.0Gohttps://github.com/sashabaranov/go-openai
github.com/tklauser/numcpusv0.11.0Gohttps://github.com/tklauser/numcpus
github.com/vulncheck-oss/go-exploitv1.51.0Gohttps://github.com/vulncheck-oss/go-exploit
github.com/xdg-go/pbkdf2v1.0.0Gohttps://github.com/xdg-go/pbkdf2
github.com/zmap/rc2v0.0.0-20190804163417-abaa70531248Gohttps://github.com/zmap/rc2
github.com/zmap/zcryptov0.0.0-20240803002437-3a861682ac77Gohttps://github.com/zmap/zcrypto
gopkg.in/yaml.v2v2.4.0Gohttps://gopkg.in/yaml.v2
gopkg.in/yaml.v3v3.0.1Gohttps://gopkg.in/yaml.v3

BSD-2-Clause ​

ComponentVersionEcosystemSource
github.com/Mzack9999/go-http-digest-auth-clientv0.6.1-0.20220414142836-eb8883508809Gohttps://github.com/Mzack9999/go-http-digest-auth-client
github.com/andybalholm/cascadiav1.3.3Gohttps://github.com/andybalholm/cascadia
github.com/pkg/errorsv0.9.1Gohttps://github.com/pkg/errors
github.com/syndtr/goleveldbv1.0.0Gohttps://github.com/syndtr/goleveldb

BSD-3-Clause ​

ComponentVersionEcosystemSource
github.com/PuerkitoBio/goqueryv1.12.0Gohttps://github.com/PuerkitoBio/goquery
github.com/cloudflare/ahocorasickv0.0.0-20240916140611-054963ec9396Gohttps://github.com/cloudflare/ahocorasick
github.com/dsnet/compressv0.0.2-0.20230904184137-39efe44ab707Gohttps://github.com/dsnet/compress
github.com/elazarl/goproxyv1.8.4Gohttps://github.com/elazarl/goproxy
github.com/golang/snappyv0.0.4Gohttps://github.com/golang/snappy
github.com/google/go-github/v57v57.0.0Gohttps://github.com/google/go-github/v57
github.com/google/go-querystringv1.2.0Gohttps://github.com/google/go-querystring
github.com/google/uuidv1.6.0Gohttps://github.com/google/uuid
github.com/gorilla/cssv1.0.1Gohttps://github.com/gorilla/css
github.com/lufia/plan9statsv0.0.0-20211012122336-39d0f177ccd0Gohttps://github.com/lufia/plan9stats
github.com/microcosm-cc/bluemondayv1.0.27Gohttps://github.com/microcosm-cc/bluemonday
github.com/miekg/dnsv1.1.72Gohttps://github.com/miekg/dns
github.com/projectdiscovery/jarm-gov0.0.0-20260910160638-430e2bae86f6Gohttps://github.com/projectdiscovery/jarm-go
github.com/refraction-networking/utlsv1.8.2Gohttps://github.com/refraction-networking/utls
github.com/shirou/gopsutil/v4v4.26.3Gohttps://github.com/shirou/gopsutil/v4
github.com/spaolacci/murmur3v1.1.0Gohttps://github.com/spaolacci/murmur3
github.com/tklauser/go-sysconfv0.3.16Gohttps://github.com/tklauser/go-sysconf
golang.org/x/cryptov0.55.0Gohttps://golang.org/x/crypto
golang.org/x/expv0.0.0-20260218203240-3dfff04db8faGohttps://golang.org/x/exp
golang.org/x/modv0.38.0Gohttps://golang.org/x/mod
golang.org/x/netv0.58.0Gohttps://golang.org/x/net
golang.org/x/oauth2v0.36.0Gohttps://golang.org/x/oauth2
golang.org/x/syncv0.22.0Gohttps://golang.org/x/sync
golang.org/x/sysv0.47.0Gohttps://golang.org/x/sys
golang.org/x/termv0.45.0Gohttps://golang.org/x/term
golang.org/x/textv0.41.0Gohttps://golang.org/x/text
golang.org/x/timev0.15.0Gohttps://golang.org/x/time
golang.org/x/toolsv0.48.0Gohttps://golang.org/x/tools

ISC ​

ComponentVersionEcosystemSource
github.com/cnf/structhashv0.0.0-20250313080605-df4c6cc74a9aGohttps://github.com/cnf/structhash
github.com/tidwall/tinyqueuev0.1.1Gohttps://github.com/tidwall/tinyqueue
lucide-react0.468.0npmhttps://www.npmjs.com/package/lucide-react/v/0.468.0

MIT ​

ComponentVersionEcosystemSource
github.com/Azure/azure-sdk-for-go/sdk/azcorev1.20.0Gohttps://github.com/Azure/azure-sdk-for-go/sdk/azcore
github.com/Azure/azure-sdk-for-go/sdk/internalv1.11.2Gohttps://github.com/Azure/azure-sdk-for-go/sdk/internal
github.com/Azure/azure-sdk-for-go/sdk/storage/azblobv1.6.4Gohttps://github.com/Azure/azure-sdk-for-go/sdk/storage/azblob
github.com/Azure/go-ntlmsspv0.1.1Gohttps://github.com/Azure/go-ntlmssp
github.com/Mzack9999/gcachev0.0.0-20230410081825-519e28eab057Gohttps://github.com/Mzack9999/gcache
github.com/Mzack9999/jsluicev0.0.0-20260306161058-30114a312f98Gohttps://github.com/Mzack9999/jsluice
github.com/andybalholm/brotliv1.2.1Gohttps://github.com/andybalholm/brotli
github.com/asaskevich/govalidatorv0.0.0-20230301143203-a9d515a09cc2Gohttps://github.com/asaskevich/govalidator
github.com/aymerick/douceurv0.2.0Gohttps://github.com/aymerick/douceur
github.com/brianvoe/gofakeit/v7v7.2.1Gohttps://github.com/brianvoe/gofakeit/v7
github.com/ditashi/jsbeautifier-gov0.0.0-20141206144643-2520a8026a9cGohttps://github.com/ditashi/jsbeautifier-go
github.com/djherbis/timesv1.6.0Gohttps://github.com/djherbis/times
github.com/dlclark/regexp2v1.11.5Gohttps://github.com/dlclark/regexp2
github.com/gaissmai/bartv0.30.0Gohttps://github.com/gaissmai/bart
github.com/go-chi/chi/v5v5.1.0Gohttps://github.com/go-chi/chi/v5
github.com/go-ole/go-olev1.2.6Gohttps://github.com/go-ole/go-ole
github.com/go-rod/rodv0.116.2Gohttps://github.com/go-rod/rod
github.com/happyhackingspace/ditv0.0.25Gohttps://github.com/happyhackingspace/dit
github.com/iangcarroll/cookiemonsterv1.6.0Gohttps://github.com/iangcarroll/cookiemonster
github.com/jackc/pgpassfilev1.0.0Gohttps://github.com/jackc/pgpassfile
github.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761Gohttps://github.com/jackc/pgservicefile
github.com/jackc/pgx/v5v5.7.2Gohttps://github.com/jackc/pgx/v5
github.com/jackc/puddle/v2v2.2.2Gohttps://github.com/jackc/puddle/v2
github.com/json-iterator/gov1.1.12Gohttps://github.com/json-iterator/go
github.com/kataras/jwtv0.1.8Gohttps://github.com/kataras/jwt
github.com/lukasbob/srcsetv0.0.0-20190730101422-86b742e617f3Gohttps://github.com/lukasbob/srcset
github.com/mattn/go-isattyv0.0.20Gohttps://github.com/mattn/go-isatty
github.com/mitchellh/mapstructurev1.5.0Gohttps://github.com/mitchellh/mapstructure
github.com/odvcencio/gotreesitterv0.6.1-0.20260306002001-fbe5983c6f41Gohttps://github.com/odvcencio/gotreesitter
github.com/power-devops/perfstatv0.0.0-20240221224432-82ca36839d55Gohttps://github.com/power-devops/perfstat
github.com/projectdiscovery/blackrockv0.0.2Gohttps://github.com/projectdiscovery/blackrock
github.com/projectdiscovery/dslv0.8.21Gohttps://github.com/projectdiscovery/dsl
github.com/projectdiscovery/fastdialerv0.5.23Gohttps://github.com/projectdiscovery/fastdialer
github.com/projectdiscovery/goflagsv0.2.1Gohttps://github.com/projectdiscovery/goflags
github.com/projectdiscovery/gologgerv1.1.73Gohttps://github.com/projectdiscovery/gologger
github.com/projectdiscovery/gostructv0.0.2Gohttps://github.com/projectdiscovery/gostruct
github.com/projectdiscovery/govaluatev0.0.0-20260504230327-80320480bb6eGohttps://github.com/projectdiscovery/govaluate
github.com/projectdiscovery/hmapv0.0.102Gohttps://github.com/projectdiscovery/hmap
github.com/projectdiscovery/katanav1.8.0Gohttps://github.com/projectdiscovery/katana
github.com/projectdiscovery/mapcidrv1.1.97Gohttps://github.com/projectdiscovery/mapcidr
github.com/projectdiscovery/networkpolicyv0.1.53Gohttps://github.com/projectdiscovery/networkpolicy
github.com/projectdiscovery/ratelimitv0.0.92Gohttps://github.com/projectdiscovery/ratelimit
github.com/projectdiscovery/retryablednsv1.0.116Gohttps://github.com/projectdiscovery/retryabledns
github.com/projectdiscovery/utilsv0.11.6Gohttps://github.com/projectdiscovery/utils
github.com/projectdiscovery/wappalyzergov0.3.4Gohttps://github.com/projectdiscovery/wappalyzergo
github.com/quic-go/qpackv0.6.0Gohttps://github.com/quic-go/qpack
github.com/quic-go/quic-gov0.60.0Gohttps://github.com/quic-go/quic-go
github.com/remeh/sizedwaitgroupv1.0.0Gohttps://github.com/remeh/sizedwaitgroup
github.com/rs/xidv1.5.0Gohttps://github.com/rs/xid
github.com/saintfish/chardetv0.0.0-20230101081208-5e3ef4b5456dGohttps://github.com/saintfish/chardet
github.com/spf13/castv1.10.0Gohttps://github.com/spf13/cast
github.com/stoewer/go-strcasev1.3.0Gohttps://github.com/stoewer/go-strcase
github.com/tidwall/btreev1.6.0Gohttps://github.com/tidwall/btree
github.com/tidwall/buntdbv1.3.0Gohttps://github.com/tidwall/buntdb
github.com/tidwall/gjsonv1.18.0Gohttps://github.com/tidwall/gjson
github.com/tidwall/grectv0.1.4Gohttps://github.com/tidwall/grect
github.com/tidwall/matchv1.2.0Gohttps://github.com/tidwall/match
github.com/tidwall/prettyv1.2.1Gohttps://github.com/tidwall/pretty
github.com/tidwall/rtredv0.1.2Gohttps://github.com/tidwall/rtred
github.com/valyala/bytebufferpoolv1.0.0Gohttps://github.com/valyala/bytebufferpool
github.com/valyala/fasttemplatev1.2.2Gohttps://github.com/valyala/fasttemplate
github.com/weppos/publicsuffix-gov0.50.3-0.20260104170930-90713dec78f2Gohttps://github.com/weppos/publicsuffix-go
github.com/ysmood/fetchupv0.2.3Gohttps://github.com/ysmood/fetchup
github.com/ysmood/goobv0.4.0Gohttps://github.com/ysmood/goob
github.com/ysmood/gotv0.40.0Gohttps://github.com/ysmood/got
github.com/ysmood/gsonv0.7.3Gohttps://github.com/ysmood/gson
github.com/ysmood/leaklessv0.9.0Gohttps://github.com/ysmood/leakless
github.com/yusufpapurcu/wmiv1.2.4Gohttps://github.com/yusufpapurcu/wmi
go.etcd.io/bboltv1.3.7Gohttps://go.etcd.io/bbolt
go.uber.org/multierrv1.11.0Gohttps://go.uber.org/multierr
react19.2.7npmhttps://www.npmjs.com/package/react/v/19.2.7
react-dom19.2.7npmhttps://www.npmjs.com/package/react-dom/v/19.2.7
react-resizable-panels2.1.9npmhttps://www.npmjs.com/package/react-resizable-panels/v/2.1.9
scheduler0.27.0npmhttps://www.npmjs.com/package/scheduler/v/0.27.0

MPL-2.0 ​

ComponentVersionEcosystemSource
github.com/gosimple/slugv1.15.0Gohttps://github.com/gosimple/slug
github.com/hashicorp/go-versionv1.9.0Gohttps://github.com/hashicorp/go-version
github.com/hashicorp/golang-lru/v2v2.0.7Gohttps://github.com/hashicorp/golang-lru/v2
github.com/projectdiscovery/retryablehttp-gov1.3.29Gohttps://github.com/projectdiscovery/retryablehttp-go

OFL-1.1 ​

ComponentVersionEcosystemSource
@fontsource/inter5.3.0npmhttps://www.npmjs.com/package/@fontsource/inter/v/5.3.0
@fontsource/jetbrains-mono5.3.0npmhttps://www.npmjs.com/package/@fontsource/jetbrains-mono/v/5.3.0
@fontsource/rajdhani5.3.0npmhttps://www.npmjs.com/package/@fontsource/rajdhani/v/5.3.0

Unlicense ​

ComponentVersionEcosystemSource
github.com/logrusorgru/aurorav2.0.3+incompatibleGohttps://github.com/logrusorgru/aurora
github.com/logrusorgru/aurora/v4v4.0.0Gohttps://github.com/logrusorgru/aurora/v4

Undetermined ​

The license of the following components could not be determined automatically from the files bundled in this build. They are listed here rather than omitted; contact Hack LLC for their license terms.

ComponentVersionEcosystemSource
github.com/sullo/nikto-dsl-golang
no license file vendored
v0.2.0Gohttps://github.com/sullo/nikto-dsl-golang

Attribution notices (Apache-2.0 section 4(d)) ​

The following components ship a NOTICE file. Apache License 2.0 section 4(d) requires that the attribution notices they contain be reproduced with any distribution that includes those components. They are reproduced below exactly as published upstream.

github.com/aws/aws-sdk-go-v2 ​

text
AWS SDK for Go
Copyright 2015 Amazon.com, Inc. or its affiliates. All Rights Reserved.
Copyright 2014-2015 Stripe, Inc.

github.com/aws/smithy-go ​

text
Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.

github.com/glaslos/tlsh ​

text
=========================================================================
==  NOTICE file for use with the Apache License, Version 2.0,          ==
==  in this case for the Trend Locality Sensitive Hash distribution.   ==
=========================================================================

Trend Locality Sensitive Hash (TLSH)
Copyright 2010-2014 Trend Micro
Copyright 2017 Lukas Rist

This product is derived from software developed at
Trend Micro (http://www.trendmicro.com/)

Refer to the following publications for more information:

  Jonathan Oliver, Chun Cheng and Yanggui Chen,
  "TLSH - A Locality Sensitive Hash"
  4th Cybercrime and Trustworthy Computing Workshop, Sydney, November 2013
  https://github.com/trendmicro/tlsh/blob/master/TLSH_CTC_final.pdf

  Jonathan Oliver, Scott Forman and Chun Cheng,
  "Using Randomization to Attack Similarity Digests"
  Applications and Techniques in Information Security. Springer Berlin Heidelberg, 2014. 199-210.
  https://github.com/trendmicro/tlsh/blob/master/Attacking_LSH_and_Sim_Dig.pdf

  Jonathan Oliver and Jayson Pryde
  http://blog.trendmicro.com/trendlabs-security-intelligence/smart-whitelisting-using-locality-sensitive-hashing/


SHA1(LICENSE)= f0b513a735cc88cc1f37c5ee0caec2a9e154bd86

github.com/praetorian-inc/titus ​

text
Titus
Copyright 2026 Praetorian Security, Inc.

This product includes software developed at Praetorian Security, Inc.
(https://www.praetorian.com/).

================================================================================

Detection rules in pkg/rule/rules/ are derived from NoseyParker
(https://github.com/praetorian-inc/noseyparker), which is licensed under the
Apache License, Version 2.0.

NoseyParker
Copyright 2023-2026 Praetorian Security, Inc.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

================================================================================

Additional detection rules in pkg/rule/rules/ (prefixed with "kingfisher.") are
derived from Kingfisher (https://github.com/mongodb/kingfisher), which is
licensed under the Apache License, Version 2.0.

Kingfisher
Copyright MongoDB, Inc.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

github.com/zmap/zcrypto/cryptobyte ​

text
Forked from golang.org/x/crypto/cryptobyte in order to support 
permissive asn1 parsing.

gopkg.in/yaml.v2 ​

text
Copyright 2011-2016 Canonical Ltd.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

gopkg.in/yaml.v3 ​

text
Copyright 2011-2016 Canonical Ltd.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

Proprietary software. Licensed for use under the End User License Agreement.