Credits & licences
what it builds on.
PIT uses open-source packages, open fonts and third-party services. Each keeps its own licence. The full list is THIRD-PARTY-LICENSES.md in the project root; versions below match package-lock.json.
01Summary
THIRD-PARTY-LICENSES.md (project root, also copied into the Docker image) lists every production package, direct and transitive (npm ls --omit=dev --all), with the licence each declares. By package-lock.json that is 69 production packages: MIT 52, MPL-2.0 14 (satori, @resvg/resvg-js and its 12 per-platform builds), Apache-2.0 2 (lightweight-charts, typescript), ISC 1. No production package uses GPL, AGPL or another strong copyleft licence. The file also carries the upstream licence texts of fancy-canvas, yoga-layout and css-box-shadow, which publish none on npm.
- MPL-2.0 (satori, @resvg/resvg-js): file-level copyleft. PIT uses both unmodified from npm to render share cards; their source is at
github.com/vercel/satoriandgithub.com/thx/resvg-js. If you modify files of those packages and distribute them, those files stay under MPL-2.0. Your own code is not affected. - Apache-2.0 (lightweight-charts, © TradingView, Inc.): requires an attribution link to tradingview.com. PIT's footer shows "Charts by TradingView"; keep it when you rebrand.
- Development tools add more packages (186 in the whole lockfile), among them
lightningcss(MPL-2.0, a build tool used by Vite) with its per-platform builds. They are not part of the running server. - After you add packages, check their licences in
package-lock.json(thelicensefield) or in each package'sLICENSEfile innode_modules.
02Runtime packages
| Package | Version | Licence | Used for |
|---|---|---|---|
| react, react-dom | 19.3.0 | MIT | Web app |
| lightweight-charts | 5.2.1 | Apache-2.0 | Telemetry and equity charts (TradingView) |
| @nktkas/hyperliquid | 0.33.3 | MIT | Hyperliquid market data and orders |
| viem | 2.56.8 | MIT | Wallets, signatures, Sign-In with Ethereum, USDC checks |
| zod | 4.6.5 | MIT | Config and API validation |
| hono, @hono/node-server | 4.13.9 / 2.1.1 | MIT | Operator console server |
| better-sqlite3 | 13.0.3 | MIT | Operator console database (native module) |
| satori | 0.33.5 | MPL-2.0 | Share cards (layout to SVG) |
| @resvg/resvg-js | 2.6.2 | MPL-2.0 | Share cards (SVG to PNG) |
Their own dependencies are listed in package-lock.json. PIT's main database uses Node's built-in node:sqlite.
03Development tools
Used to build and test; not needed by the running server.
| Package | Version | Licence |
|---|---|---|
| vite | 8.3.0 | MIT |
| @vitejs/plugin-react | 6.1.1 | MIT |
| vitest | 5.0.1 | MIT |
| typescript | 5.9.3 | Apache-2.0 |
| tsx | 4.23.15 | MIT |
| concurrently | 10.0.5 | MIT |
@types/node, @types/react, @types/react-dom, @types/better-sqlite3 | 26.6.2 / 19.3.0 / 19.3.0 / 9.6.0 | MIT |
04Operator console
The console in vendor/mikodes-admin/ is the MIKODES Admin Kit 0.3.0, part of this package. Its built interface bundles cmdk and Radix UI primitives (MIT), lucide-react (ISC) and the Geist fonts via @fontsource-variable (SIL Open Font License 1.1).
05Fonts
| Font | Where | Licence |
|---|---|---|
| Mona Sans by GitHub | Bundled in server/og/fonts/ for share cards (Bold Wide); loaded from Google Fonts by the web app | SIL Open Font License 1.1 (OFL-MonaSans.txt) |
| Geist and Geist Mono by Vercel | Bundled in server/og/fonts/ for share cards; loaded from Google Fonts by the web app; bundled in the console | SIL Open Font License 1.1 (OFL-Geist.txt) |
The web app loads its fonts from Google Fonts at runtime (web/index.html). The PIT name, logo and screenshots are part of the item for reference; replace them with your own brand before you go live (Rebranding).
06Third-party services
PIT can connect to these services. They are not part of the purchase: you sign up, accept their terms and pay their fees yourself. Names are trademarks of their owners and are used only to describe compatibility.
Hyperliquid (market data and trading), Polymarket (forecast league data), Anthropic, OpenAI, Google, xAI and DeepSeek (models), Stripe (card payments), Telegram and Discord (alerts), Google Fonts, and the hosting provider you choose (for example Fly.io or Render).