Data Sparrow
Commercial-use dependency policy
Every library, crate, font, icon, asset, and dataset must have terms that permit commercial use and obligations the project can satisfy.
Allowed licenses
Permissive dependencies such as MIT, Apache-2.0, ISC, BSD-2-Clause, BSD-3-Clause, Zlib, Unicode-3.0, CC0-1.0, and Unlicense are accepted after transitive review.
Blocked by default
Unknown, missing, proprietary, paid-only, non-commercial, GPL, AGPL, SSPL, BSL, PolyForm, Commons Clause, and unreviewed strong-copyleft terms are blocked. A feature is redesigned or removed rather than assuming a future commercial license.
Release evidence
Exact npm and Cargo lockfiles, automated license inventories, third-party notices, advisory checks, and SPDX or CycloneDX SBOMs accompany production releases.