Files
app-catalog-felhom.eu/audits
admin b38aa92317
gates / gates (push) Successful in 7s
audits: PikaPods read against the catalog (read-only; no template touched)
NOTHING IN THE CATALOG CHANGED. No template, no .felhom.yml, no
templates.json, no image pin. Output is audits/pikapods-scan-2026-10-10/.

THE GREEN HEART, in PikaPods' own words. Hovering it shows the tooltip
"Project has a revenue sharing agreement." (verified by hovering the heart
beside Actual, A1-heart-tooltip.jpg). Their FAQ: "Open source developers have
the option to enter into a revenue sharing agreement to receive 20% of
revenues their app generates." The mark is NOT permission for Felhom -- it is
an agreement with PikaPods, on terms we have not seen. It only shows the
author is open to such an arrangement at all.

Finding the mark took reading the DOM: the hearts are not text and not a
title attribute. Each card carries three Vuetify icons, all three present on
every card, and the green one (rgb(76,175,80)) is display:none where there is
no agreement. Counting "hearts in the page text" would have returned zero on
all 126.

NUMBERS. 126 apps on PikaPods, 39 marked. 58 template dirs here (56 offered +
plant-it abandoned + wger hidden -- which reconciles with the website's 56 +
FileBrowser built-in). 25 on both, 33 of ours not there, 101 of theirs not
ours, 11 of the 25 shared carry the mark.

LICENCE COMFORT: one row moved, and I will not dress it up as more.
sparkyfitness is there WITH the mark, consistent with what its author already
told us (R-784) -- so he demonstrably does commercial-hosting agreements.
tandoor, emby, plex, outline, calcom and wanderer are NOT on PikaPods at all,
so the scan says nothing about them. n8n and docmost ARE hosted there WITHOUT
a mark: a fact about PikaPods' risk appetite, not a permission we can borrow.

TEN CANDIDATES, none added, each licence read at its own repo and cited:
Grocy (MIT), Firefly III (AGPL-3.0), Monica (AGPL-3.0), LubeLogger (MIT),
Storyteller (MIT), PdfDing (AGPL-3.0), Memos (MIT), Wealthfolio (AGPL-3.0),
Kavita (GPL-3.0), PhotoPrism (AGPL-3.0). Developer and company tools were
excluded wholesale. Each would still go through NEW-APP-CHECKLIST.md.

JOPLIN WAS SHORTLISTED AND DROPPED ON ITS LICENCE, which is the most useful
thing in this scan. Its repo root says AGPL-3.0-or-later "unless a directory
contains a LICENSE or LICENSE.md file" -- and packages/server, the part we
would host, carries the Joplin Server Personal Use License: "the Software may
be used for personal non-commercial purposes only", and the licensee may not
"grant others the right to use the Software for a fee". Same shape as
SparkyFitness: open client, restricted server. GitHub's repo-level licence
field says AGPL-3.0 and would have hidden it.

Two other reads worth keeping: PdfDing's GitHub mirror has NO licence file at
all (the project lives on Codeberg, where it is AGPL-3.0) -- trusting the
mirror would have called it unlicensed; and photoprism/joplin both report
NOASSERTION to the API, so both needed the file read rather than the badge.

Register: 0 opened, 0 closed. The brief expected a row only for a licence
problem in an app we already ship; none turned up. No contact with PikaPods or
any author.
2026-10-10 09:47:39 +02:00
..