Files
felhom.eu/documentation/audits/licences-2026-10-02/read-1.md
T

7.5 KiB

Licence read, part 1 of 2 (R-787) — READ at each pinned tag, 2026-10-02 (subagent, verbatim in substance)

Apps: actualbudget adventurelog audiobookshelf bentopdf bookstack calcom calibre-web claper code-server crafty-controller dawarich docmost emby ghost gitea glance gokapi grafana gramps-web home-assistant homebox homepage immich jellyfin karakeep kimai komga mealie. Licences read from the upstream file at the pinned tag, except linuxserver packaging, PostGIS and immich base-images (read from master/main) and the MariaDB, Postgres, Chromium and Emby pages. Inferred is marked.

app image:tag licence (SPDX) OSI limiting clause (quoted) plain meaning evidence
actualbudget actualbudget/actual-server:26.9.0 MIT yes — — github.com/actualbudget/actual/blob/v26.9.0/LICENSE.txt
adventurelog adventurelog-backend/-frontend:v0.13.0 GPL-3.0 (version from the text; -only/-or-later inferred) yes — — github.com/seanmorley15/AdventureLog/blob/v0.13.0/LICENSE
adventurelog, dawarich postgis/postgis:16-3.5 / 17-3.5-alpine GPL-2.0-or-later + PostgreSQL yes — — postgis LICENSE.TXT
audiobookshelf ghcr.io/advplyr/audiobookshelf:2.37.1 GPL-3.0 yes — — github.com/advplyr/audiobookshelf/blob/v2.37.1/LICENSE
bentopdf ghcr.io/alam00000/bentopdf:v2.8.6 AGPL-3.0 (dual: a commercial licence optional) yes — AGPL; the README labels this image the "Commercial build" and points self-hosters to bentopdf-simple — a label, not a licence term github.com/alam00000/bentopdf/blob/v2.8.6/LICENSE + README "Licensing"
bookstack lscr.io/linuxserver/bookstack:26.09.1 MIT (+ GPL-3.0 packaging) yes — — github.com/BookStackApp/BookStack/blob/v26.09.1/LICENSE
bookstack, kimai mariadb:12.3 / 11.8 GPL-2.0-only yes — — mariadb.com/kb/en/mariadb-license/
calcom calcom/cal.com:v6.2.0 AGPL-3.0 AND Cal.com Commercial License (packages/features/ee, apps/api/v2/src/ee) partly EE: "may only be used in production, if you … have a valid Cal.com Enterprise Edition subscription … it is forbidden to copy, merge, publish, distribute, sublicense, and/or sell the Software." EE code is in the image, off without a key (inferred); free features stay AGPL; any EE feature in production needs a subscription github.com/calcom/cal.com/blob/v6.2.0/packages/features/ee/LICENSE
calcom, docmost postgres:18-alpine PostgreSQL yes — — —
calibre-web crocodilestick/calibre-web-automated:v4.0.8 GPL-3.0 yes — — github.com/crocodilestick/Calibre-Web-Automated/blob/v4.0.8/LICENSE
claper ghcr.io/claperco/claper:2.5 AGPL-3.0 (read at v2.5.0; tag mapping inferred) yes — — github.com/ClaperCo/Claper/blob/v2.5.0/LICENSE.txt
code-server lscr.io/linuxserver/code-server:4.129.0 MIT (+ GPL-3.0 packaging) yes — no Microsoft Marketplace (inferred) github.com/coder/code-server/blob/v4.129.0/LICENSE
crafty-controller crafty-4:4.11.0 GPL-3.0 yes — Minecraft jars it downloads fall under Mojang's EULA, separately gitlab.com/crafty-controller/crafty-4/-/blob/v4.11.0/LICENSE
dawarich freikin/dawarich:1.15.3 AGPL-3.0 yes — — github.com/Freika/dawarich/blob/1.15.3/LICENSE
dawarich, docmost, immich redis:7.4-alpine / 7-alpine (→ 7.4.11) RSALv2 OR SSPL-1.0 no RSALv2: "You may not make the functionality of the Software or a Modified version available to third parties as a service or distribute the Software … in a manner that makes the functionality of the Software available to third parties." a private cache only its app uses — inferred permitted; redis:7.2 / valkey (BSD-3) or Redis 8 (AGPL option) removes the question github.com/redis/redis/blob/7.4.0/LICENSE.txt
docmost docmost/docmost:0.96.0 AGPL-3.0 AND Docmost Enterprise License (packages/ee, apps/client/src/ee) partly EE: "may only be used in production, if you … have a valid Docmost Enterprise Edition subscription …" as Cal.com: EE off without a key (inferred) github.com/docmost/docmost/blob/v0.96.0/packages/ee/LICENSE
emby emby/embyserver:4.11.0.4 proprietary no "Emby grants you a personal, non-commercial … non-transferable, non-sublicensable … license … you may not … copy, modify, distribute, sell, or lease any part of the Software" the household's private use fits; a company selling its installation and care works in a context the licence does not cover; the box pulls the image from Emby, so no copies are distributed — a grey area (inferred) emby.media/terms.html
ghost ghost:6.67.0-alpine MIT yes — name is a trademark github.com/TryGhost/Ghost/blob/v6.67.0/LICENSE
gitea gitea/gitea:1.27.3 MIT yes — — github.com/go-gitea/gitea/blob/v1.27.3/LICENSE
glance glanceapp/glance:v0.8.5 AGPL-3.0 yes — — github.com/glanceapp/glance/blob/v0.8.5/LICENSE
gokapi f0rc3/gokapi:v1.9.6 AGPL-3.0 yes — — github.com/Forceu/Gokapi/blob/v1.9.6/LICENSE.md
grafana grafana/grafana:13.2.3 AGPL-3.0 (OSS image) yes — trademarks github.com/grafana/grafana/blob/v13.2.3/LICENSE
gramps-web ghcr.io/gramps-project/grampsweb:v25.6.0 AGPL-3.0 (Gramps core GPL-2.0-or-later) yes — — github.com/gramps-project/gramps-web/blob/v25.6.0/LICENSE
home-assistant home-assistant:2026.9.4 Apache-2.0 yes — trademark github.com/home-assistant/core/blob/2026.9.4/LICENSE.md
homebox ghcr.io/sysadminsmedia/homebox:0.26.2 AGPL-3.0 yes — — github.com/sysadminsmedia/homebox/blob/v0.26.2/LICENSE
homepage ghcr.io/gethomepage/homepage:v1.13.2 GPL-3.0 yes — — github.com/gethomepage/homepage/blob/v1.13.2/LICENSE
immich immich-server / -machine-learning:v3.2.4 AGPL-3.0 yes — ML model weights carry their own licences (not checked) github.com/immich-app/immich/blob/v3.2.4/LICENSE
immich ghcr.io/immich-app/postgres:16-vectorchord0.4.3-pgvectors0.2.0 PostgreSQL + (AGPL-3.0 OR Elastic-2.0) VectorChord + Apache-2.0 pgvecto.rs yes (AGPL chosen for VectorChord) ELv2 alternative only — github.com/tensorchord/VectorChord/blob/0.4.3/LICENSE
jellyfin jellyfin/jellyfin:10.11.11 GPL-2.0 (ffmpeg GPL-3.0) yes — — github.com/jellyfin/jellyfin/blob/v10.11.11/LICENSE
karakeep ghcr.io/karakeep-app/karakeep:0.33.2 AGPL-3.0 yes — — github.com/karakeep-app/karakeep/blob/v0.33.2/LICENSE
karakeep karakeep-chrome:151.0.7922.47-r1 BSD-3-Clause (Chromium headless-shell — inferred from Chromium) yes — — chromium LICENSE
karakeep getmeili/meilisearch:v1.41.0 MIT (Community image; BUSL EE code only in meilisearch-enterprise) yes — never switch to the -enterprise image github.com/meilisearch/meilisearch/blob/v1.41.0/LICENSE
kimai kimai/kimai2:2.67.0 AGPL-3.0 yes — paid plugins are separate github.com/kimai/kimai/blob/2.67.0/LICENSE
komga gotson/komga:1.28.0 MIT yes — — github.com/gotson/komga/blob/1.28.0/LICENSE
mealie ghcr.io/mealie-recipes/mealie:v3.28.0 AGPL-3.0 yes — — github.com/mealie-recipes/mealie/blob/v3.28.0/LICENSE

Not OSI-approved (part 1): emby (proprietary, personal non-commercial — the real business risk in this set); calcom and docmost (proprietary EE folders inside the AGPL image, off without a key); redis 7.4.11 in dawarich, docmost, immich (RSALv2/SSPL — internal cache).