Commercial-use inventory
Licenses and attribution
Date Sparrow ships only code and data reviewed as free for commercial use. Exact versions are pinned in the lockfile and verified by the repository license gate.
Runtime packages
| Package | Version | License | Purpose |
|---|---|---|---|
| Svelte / SvelteKit | 5.56.8 / 2.70.2 | MIT | Application UI and routing |
| @js-temporal/polyfill | 0.5.1 | ISC | Temporal date/time semantics |
| @lucide/svelte | 1.28.0 | ISC | Interface icons |
| date-holidays | 3.34.1 | ISC AND CC-BY-3.0 | Optional local public-holiday rules/data |
| @bluesparrow/fleet | 0.3.0 | MIT OR Apache-2.0 | Shared BlueSparrow shell |
| qrcode | 1.5.4 | MIT | Local share-link QR images |
| svelte-sonner | 1.1.1 | MIT | Local interface notices |
Holiday data attribution
The optional holiday feature uses date-holidays 3.34.1, licensed under ISC and Creative Commons Attribution 3.0. Its data is bundled and processed locally. BlueSparrow has not modified the upstream package data. Review date: 2026-08-02.
Pinned package integrity: sha512-C5CR3/Rx7exJrtq2yPlCU0+rO06AeoKvUHCBCu3s37SUFi/xoVkE6DiErPlZ2tPGoorb85FLX3uuDlADT3h5fg==
Creative Commons Attribution 3.0: license summary and terms.
Complete notices
The repository THIRD_PARTY_NOTICES.md, production lockfile and generated CycloneDX SBOM are the authoritative release artifacts. Registry metadata is an engineering check, not legal advice.