Files
argus-installer/THIRD_PARTY_LICENSES.md
tech abab6775d6 feat: switch to Weboria's own registry, clean licensing docs, expand product copy
Registry: docker-compose.yml now pulls argus-api/argus-ui/argus-proxy from
git-cloud.weboria.eu/weboria (Gitea's built-in container registry) instead
of ghcr.io. Built and pushed real production images from main (v3.73.0)
before switching — verified anonymous `docker pull` works for all three
with zero login required, matching the public installer's no-friction
promise. install.sh's registry comment updated to match; no more "gap."

Licensing: reworked per a full commercial-distribution review. Removed
MaxMind/GeoLite2 entirely (confirmed geoip2-golang isn't even in go.mod —
GeoIP is RIR-based, not MaxMind-based, and has been for a while).
Clarified TimescaleDB's licensing story (embedded component distributed
as part of the appliance, not a hosted DB service) rather than leaving it
under a vague "reviewed before bundling" note. Added missing real
dependencies grounded against the actual Dockerfiles (Alpine Linux,
PostgreSQL, Go runtime, Node.js build-time-only, OpenSSL, curl, BusyBox).
Renamed THIRD_PARTY_LICENSES -> THIRD_PARTY_LICENSES.md, added a
"Weboria Proprietary Components" section. Removed the "pending legal
review" section that was specifically about MaxMind/TimescaleDB, now
resolved by the above -- LICENSE's own placeholder-pending-final-terms
disclaimer stays, since drafting real commercial license text is separate
legal work, not something to paper over.

README: removed the internal "this repo contains no proprietary code"
meta-description (customers don't need to see project scaffolding notes)
and the "known gap" callout (both gaps closed above). Expanded the
feature list with a dedicated ANIS Threat Intelligence section and richer
detail on DNS Security, Bot/AI-crawler defense, and the Guided Security
Policy Center. Stronger positioning copy up top.
2026-07-25 16:34:39 +00:00

5.3 KiB

Third-Party Licenses

ARGUS uses the following third-party software.

Core Components

TimescaleDB

ARGUS uses TimescaleDB as an embedded time-series storage component for security events, telemetry, and operational metrics.

TimescaleDB is distributed as part of the ARGUS Enterprise Appliance and is not offered as a standalone database service. Customers receive ARGUS as a complete security appliance; TimescaleDB remains subject to its original license terms.

PostgreSQL

TimescaleDB is distributed as a PostgreSQL extension; PostgreSQL itself is the underlying database engine.

Nginx

  • License: BSD-2-Clause
  • Website: https://nginx.org/
  • Copyright: (C) 2002-2024 Igor Sysoev, (C) 2011-2024 Nginx, Inc.

ModSecurity

OWASP Core Rule Set (CRS)

  • License: Apache License 2.0
  • Website: https://coreruleset.org/
  • Copyright: (C) 2006-2024 Trustwave Holdings, Inc., OWASP Core Rule Set contributors

Valkey

Alpine Linux

Alpine Linux is the base image for the ARGUS API, UI build, and proxy container images.

BusyBox

Bundled as part of the Alpine Linux base images above.

Go Runtime

The ARGUS API is built with Go; the compiled binary statically includes the Go runtime.

Node.js (build-time only)

  • License: MIT (Node.js core) plus per-package licenses of the npm dependencies below
  • Website: https://nodejs.org/

Used to build the ARGUS web UI; not present in the running API/proxy containers.

OpenSSL / TLS libraries

Used by the nginx proxy image for TLS termination.

curl

Used in container healthchecks and installer scripts.

Backend (Go) Dependencies

Package License Website
github.com/labstack/echo/v4 MIT https://echo.labstack.com/
github.com/go-acme/lego/v4 MIT https://go-acme.github.io/lego/
github.com/lib/pq MIT https://github.com/lib/pq
github.com/google/uuid BSD-3-Clause https://github.com/google/uuid
github.com/redis/go-redis/v9 BSD-2-Clause https://github.com/redis/go-redis
github.com/cloudflare/cloudflare-go BSD-3-Clause https://github.com/cloudflare/cloudflare-go
golang.org/x/crypto BSD-3-Clause https://golang.org/x/crypto

Frontend (React) Dependencies

Package License Website
React MIT https://react.dev/
@tanstack/react-query MIT https://tanstack.com/query
react-router-dom MIT https://reactrouter.com/
recharts MIT https://recharts.org/
i18next MIT https://www.i18next.com/
Tailwind CSS MIT https://tailwindcss.com/
Vite MIT https://vitejs.dev/

Nginx Modules

Module License Website
ModSecurity-nginx Apache 2.0 https://github.com/owasp-modsecurity/ModSecurity-nginx
ngx_brotli BSD-2-Clause https://github.com/google/ngx_brotli
headers-more-nginx-module BSD-2-Clause https://github.com/openresty/headers-more-nginx-module
ngx_http_geoip2_module BSD-2-Clause https://github.com/leev/ngx_http_geoip2_module

Apache License 2.0 Notice

The following components are licensed under the Apache License 2.0:

  • ModSecurity (Copyright 2002-2024 Trustwave Holdings, Inc.)
  • OWASP Core Rule Set (Copyright 2006-2024 Trustwave Holdings, Inc.)
  • ModSecurity-nginx (Copyright 2015-2024 Trustwave Holdings, Inc.)

Licensed under the Apache License, Version 2.0 (the "License"); you may not use these files except in compliance with the License. You may obtain a copy of the License at:

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.


Third-party components have been reviewed for inclusion in ARGUS Enterprise deployments. Each component remains subject to its original license terms.


Weboria Proprietary Components

The following ARGUS components are proprietary software developed by Weboria:

  • ARGUS Core Platform
  • ARGUS Management Interface
  • ARGUS Security Automation Engine
  • ARGUS API Layer
  • ARGUS Threat Analysis Components
  • ARGUS Licensing System
  • ARGUS Enterprise Features
  • Weboria Integrations

These components are distributed under the ARGUS Commercial License.

Unauthorized copying, modification, redistribution, reverse engineering, or resale is prohibited.