Registry: docker-compose.yml now pulls argus-api/argus-ui/argus-proxy from git-cloud.weboria.eu/weboria (Gitea's built-in container registry) instead of ghcr.io. Built and pushed real production images from main (v3.73.0) before switching — verified anonymous `docker pull` works for all three with zero login required, matching the public installer's no-friction promise. install.sh's registry comment updated to match; no more "gap." Licensing: reworked per a full commercial-distribution review. Removed MaxMind/GeoLite2 entirely (confirmed geoip2-golang isn't even in go.mod — GeoIP is RIR-based, not MaxMind-based, and has been for a while). Clarified TimescaleDB's licensing story (embedded component distributed as part of the appliance, not a hosted DB service) rather than leaving it under a vague "reviewed before bundling" note. Added missing real dependencies grounded against the actual Dockerfiles (Alpine Linux, PostgreSQL, Go runtime, Node.js build-time-only, OpenSSL, curl, BusyBox). Renamed THIRD_PARTY_LICENSES -> THIRD_PARTY_LICENSES.md, added a "Weboria Proprietary Components" section. Removed the "pending legal review" section that was specifically about MaxMind/TimescaleDB, now resolved by the above -- LICENSE's own placeholder-pending-final-terms disclaimer stays, since drafting real commercial license text is separate legal work, not something to paper over. README: removed the internal "this repo contains no proprietary code" meta-description (customers don't need to see project scaffolding notes) and the "known gap" callout (both gaps closed above). Expanded the feature list with a dedicated ANIS Threat Intelligence section and richer detail on DNS Security, Bot/AI-crawler defense, and the Guided Security Policy Center. Stronger positioning copy up top.
159 lines
5.3 KiB
Markdown
159 lines
5.3 KiB
Markdown
# Third-Party Licenses
|
|
|
|
ARGUS uses the following third-party software.
|
|
|
|
## Core Components
|
|
|
|
### TimescaleDB
|
|
- **License**: Timescale License (TSL) / Apache 2.0 depending on component
|
|
- **Website**: https://www.timescale.com/
|
|
|
|
ARGUS uses TimescaleDB as an embedded time-series storage component for security events,
|
|
telemetry, and operational metrics.
|
|
|
|
TimescaleDB is distributed as part of the ARGUS Enterprise Appliance and is not offered as a
|
|
standalone database service. Customers receive ARGUS as a complete security appliance;
|
|
TimescaleDB remains subject to its original license terms.
|
|
|
|
### PostgreSQL
|
|
- **License**: PostgreSQL License (permissive, BSD/MIT-style)
|
|
- **Website**: https://www.postgresql.org/
|
|
|
|
TimescaleDB is distributed as a PostgreSQL extension; PostgreSQL itself is the underlying
|
|
database engine.
|
|
|
|
### Nginx
|
|
- **License**: BSD-2-Clause
|
|
- **Website**: https://nginx.org/
|
|
- **Copyright**: (C) 2002-2024 Igor Sysoev, (C) 2011-2024 Nginx, Inc.
|
|
|
|
### ModSecurity
|
|
- **License**: Apache License 2.0
|
|
- **Website**: https://github.com/owasp-modsecurity/ModSecurity
|
|
- **Copyright**: (C) 2002-2024 Trustwave Holdings, Inc.
|
|
|
|
### OWASP Core Rule Set (CRS)
|
|
- **License**: Apache License 2.0
|
|
- **Website**: https://coreruleset.org/
|
|
- **Copyright**: (C) 2006-2024 Trustwave Holdings, Inc., OWASP Core Rule Set contributors
|
|
|
|
### Valkey
|
|
- **License**: BSD-3-Clause
|
|
- **Website**: https://valkey.io/
|
|
|
|
### Alpine Linux
|
|
- **License**: Various (base OS, mostly MIT/BSD-style per-package licenses)
|
|
- **Website**: https://alpinelinux.org/
|
|
|
|
Alpine Linux is the base image for the ARGUS API, UI build, and proxy container images.
|
|
|
|
### BusyBox
|
|
- **License**: GPL-2.0
|
|
- **Website**: https://busybox.net/
|
|
|
|
Bundled as part of the Alpine Linux base images above.
|
|
|
|
### Go Runtime
|
|
- **License**: BSD-3-Clause
|
|
- **Website**: https://go.dev/
|
|
|
|
The ARGUS API is built with Go; the compiled binary statically includes the Go runtime.
|
|
|
|
### Node.js (build-time only)
|
|
- **License**: MIT (Node.js core) plus per-package licenses of the npm dependencies below
|
|
- **Website**: https://nodejs.org/
|
|
|
|
Used to build the ARGUS web UI; not present in the running API/proxy containers.
|
|
|
|
### OpenSSL / TLS libraries
|
|
- **License**: Apache License 2.0 (OpenSSL 3.x) / various
|
|
- **Website**: https://www.openssl.org/
|
|
|
|
Used by the nginx proxy image for TLS termination.
|
|
|
|
### curl
|
|
- **License**: MIT/X derivate (curl license)
|
|
- **Website**: https://curl.se/
|
|
|
|
Used in container healthchecks and installer scripts.
|
|
|
|
## Backend (Go) Dependencies
|
|
|
|
| Package | License | Website |
|
|
|---------|---------|---------|
|
|
| github.com/labstack/echo/v4 | MIT | https://echo.labstack.com/ |
|
|
| github.com/go-acme/lego/v4 | MIT | https://go-acme.github.io/lego/ |
|
|
| github.com/lib/pq | MIT | https://github.com/lib/pq |
|
|
| github.com/google/uuid | BSD-3-Clause | https://github.com/google/uuid |
|
|
| github.com/redis/go-redis/v9 | BSD-2-Clause | https://github.com/redis/go-redis |
|
|
| github.com/cloudflare/cloudflare-go | BSD-3-Clause | https://github.com/cloudflare/cloudflare-go |
|
|
| golang.org/x/crypto | BSD-3-Clause | https://golang.org/x/crypto |
|
|
|
|
## Frontend (React) Dependencies
|
|
|
|
| Package | License | Website |
|
|
|---------|---------|---------|
|
|
| React | MIT | https://react.dev/ |
|
|
| @tanstack/react-query | MIT | https://tanstack.com/query |
|
|
| react-router-dom | MIT | https://reactrouter.com/ |
|
|
| recharts | MIT | https://recharts.org/ |
|
|
| i18next | MIT | https://www.i18next.com/ |
|
|
| Tailwind CSS | MIT | https://tailwindcss.com/ |
|
|
| Vite | MIT | https://vitejs.dev/ |
|
|
|
|
## Nginx Modules
|
|
|
|
| Module | License | Website |
|
|
|--------|---------|---------|
|
|
| ModSecurity-nginx | Apache 2.0 | https://github.com/owasp-modsecurity/ModSecurity-nginx |
|
|
| ngx_brotli | BSD-2-Clause | https://github.com/google/ngx_brotli |
|
|
| headers-more-nginx-module | BSD-2-Clause | https://github.com/openresty/headers-more-nginx-module |
|
|
| ngx_http_geoip2_module | BSD-2-Clause | https://github.com/leev/ngx_http_geoip2_module |
|
|
|
|
---
|
|
|
|
## Apache License 2.0 Notice
|
|
|
|
The following components are licensed under the Apache License 2.0:
|
|
|
|
- ModSecurity (Copyright 2002-2024 Trustwave Holdings, Inc.)
|
|
- OWASP Core Rule Set (Copyright 2006-2024 Trustwave Holdings, Inc.)
|
|
- ModSecurity-nginx (Copyright 2015-2024 Trustwave Holdings, Inc.)
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
you may not use these files except in compliance with the License.
|
|
You may obtain a copy of the License at:
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
See the License for the specific language governing permissions and
|
|
limitations under the License.
|
|
|
|
---
|
|
|
|
Third-party components have been reviewed for inclusion in ARGUS Enterprise deployments.
|
|
Each component remains subject to its original license terms.
|
|
|
|
---
|
|
|
|
# Weboria Proprietary Components
|
|
|
|
The following ARGUS components are proprietary software developed by Weboria:
|
|
|
|
- ARGUS Core Platform
|
|
- ARGUS Management Interface
|
|
- ARGUS Security Automation Engine
|
|
- ARGUS API Layer
|
|
- ARGUS Threat Analysis Components
|
|
- ARGUS Licensing System
|
|
- ARGUS Enterprise Features
|
|
- Weboria Integrations
|
|
|
|
These components are distributed under the ARGUS Commercial License.
|
|
|
|
Unauthorized copying, modification, redistribution, reverse engineering, or resale is
|
|
prohibited.
|