Licences
superwitness is released under the MIT licence.
What ships
Section titled “What ships”A release tarball holds:
- the
superwitnessbinary, with the run page built into it; LICENSEandNOTICE;deploy/superwitness.serviceanddeploy/env.example.
The binary links Go modules and embeds a web page built with React. Each keeps its own licence,
and the NOTICE file in
every release credits them. In summary:
| Component | Licence |
|---|---|
| chi, pgx and its jackc helpers, goose and mfridman/interpolate, golang-jwt, google/jsonschema-go, segmentio/encoding, cespare/xxhash, felixge/httpsnoop, go.uber.org/multierr, cenkalti/backoff | MIT |
| the MCP Go SDK | MIT for existing code, Apache-2.0 for new contributions |
| segmentio/asm | MIT-0 (MIT No Attribution) |
| sethvargo/go-retry, go-logr/logr and stdr, the OpenTelemetry Go API, SDK, exporters, otelhttp instrumentation and OTLP protobufs, gRPC and genproto | Apache-2.0 |
| portions of the OpenTelemetry Go modules and otelhttp, from the Go Authors | BSD-3-Clause |
| yosida95/uritemplate, google/uuid, grpc-gateway, Go protobuf, and golang.org/x sync, net, oauth2, sys, text and time | BSD-3-Clause |
| react, react-dom and scheduler, in the embedded run page | MIT |
The list covers what the binary links, not test-only modules. Build tools are not bundled: the web page’s development dependencies, including caniuse-lite (CC-BY-4.0, used by the browser-list tooling), stay out of the release. The same goes for the npm packages that build superwitness.dev and this documentation site: they are not part of any release.
The allowlist
Section titled “The allowlist”superwitness’s CI checks the licence of every Go module it builds with, using go-licenses,
against an allowlist of permissive licences:
- MIT
- Apache-2.0
- BSD-2-Clause
- BSD-3-Clause
- ISC
go-licenses does not classify segmentio/asm, which the MCP SDK pulls in. Its licence, MIT-0,
was reviewed by hand: it is permissive, and the allowlist is unchanged.
No AGPL code is linked or shipped, so Grafana, Loki, Tempo and Mimir are not used, and neither is anything under a source-available licence such as ELv2, BSL, FSL or SSPL.
What runs beside it
Section titled “What runs beside it”The telemetry engines are not part of superwitness. They are separate upstream programs that you install and run as released, and superwitness only calls their published APIs over HTTP. This release queries VictoriaTraces and VictoriaLogs, fed by the OpenTelemetry Collector. Each is under its own licence:
| Project | Licence |
|---|---|
| VictoriaTraces | Apache-2.0 |
| VictoriaLogs | Apache-2.0 |
| OpenTelemetry Collector | Apache-2.0 |
superwitness is designed to sit beside VictoriaMetrics and Perses (both Apache-2.0) the same way, but this release does not use them.