Data Sparrow
Commercial-use dependency policy
Every library, font, icon, image, and reference file must allow commercial use under terms the project can meet.
Allowed licenses
Permissive dependencies such as MIT, Apache-2.0, ISC, BSD-2-Clause, BSD-3-Clause, Zlib, Unicode-3.0, CC0-1.0, and Unlicense are accepted after transitive review.
Blocked by default
Unknown, missing, proprietary, paid-only, non-commercial, GPL, AGPL, SSPL, BSL, PolyForm, Commons Clause, and unreviewed strong-copyleft terms are blocked. A feature is redesigned or removed rather than assuming a future commercial license.
Release evidence
Exact npm and Cargo lockfiles, automated license inventories, third-party notices, advisory checks, and SPDX or CycloneDX SBOMs accompany production releases.