This list is generated from our lockfile rather than written by hand, so it matches what we actually ship. It covers the packages that run in production; development-only tooling is not distributed to anyone and is not listed. Our build also produces a machine-readable software bill of materials for each release, which we can send on request.
We are grateful to everyone who wrote and maintains these. Each package remains under its own licence and the terms of that licence apply to it, not ours.
Where a licence reads Unknown, the package did not declare one in a form our tooling could read. We would rather show that than quietly leave it out.
MIT (226 packages)
@babel/runtime, @borewit/text-codec, @hono/node-server, @ioredis/commands, @lukeed/csprng, @mjackson/node-fetch-server, @modelcontextprotocol/sdk, @msgpackr-extract/msgpackr-extract-linux-x64, @nestjs/bull-shared, @nestjs/bullmq, @nestjs/common, @nestjs/core, @nestjs/platform-express, @nestjs/throttler, @noble/hashes, @otplib/core, @otplib/hotp, @otplib/plugin-base32-scure, @otplib/plugin-crypto-noble, @otplib/totp, @otplib/uri, @phc/format, @react-router/express, @react-router/node, @react-router/serve, @scure/base, @shopify/admin-api-client, @shopify/app-bridge-react, @shopify/graphql-client, @shopify/shopify-api, @shopify/shopify-app-react-router, @shopify/shopify-app-session-storage, @shopify/shopify-app-session-storage-postgresql, @shopify/storefront-api-client, @standard-schema/spec, @tokenizer/inflate, @tokenizer/token, @types/node, @types/react, @types/react-dom, @types/react-transition-group, @types/validator, accepts, ajv, ajv-formats, ansi-regex, ansi-styles, append-field, argon2, array-flatten, basic-auth, body-parser, bowser, buffer-from, bullmq, busboy, bytes, call-bind-apply-helpers, call-bound, camelcase, class-transformer, class-validator, color-convert, color-name, compare-versions, compressible, compression, concat-stream, content-disposition, content-type, cookie, cookie-signature, cors, cron-parser, cross-spawn, csstype, debug, decamelize, deepmerge, depd, destroy, dijkstrajs, dom-helpers, dunder-proto, ee-first, emoji-regex, encodeurl, es-define-property, es-errors, es-object-atoms, escape-html, etag, eventsource, eventsource-parser, express, express-rate-limit, fast-deep-equal, fast-safe-stringify, file-type, finalhandler, find-up, forwarded, fresh, function-bind, get-intrinsic, get-port, get-proto, gopd, has-symbols, hasown, hono, http-errors, iconv-lite, ioredis, ip-address, ipaddr.js, is-fullwidth-code-point, is-promise, jose, js-tokens, json-schema-traverse, libphonenumber-js, load-esm, locate-path, lodash.defaults, lodash.isarguments, loose-envify, lossless-json, luxon, math-intrinsics, maxmind, media-typer, merge-descriptors, methods, mime, mime-db, mime-types, mmdb-lib, morgan, ms, msgpackr, msgpackr-extract, multer, negotiator, node-abort-controller, node-addon-api, node-gyp-build, node-gyp-build-optional-packages, object-assign, object-inspect, on-finished, on-headers, otplib, p-limit, p-locate, p-try, parseurl, path-exists, path-key, path-to-regexp, pg, pg-cloudflare, pg-connection-string, pg-pool, pg-protocol, pg-types, pgpass, pkce-challenge, pngjs, postgres-array, postgres-bytea, postgres-date, postgres-interval, prop-types, proxy-addr, qrcode, range-parser, raw-body, react, react-dom, react-fast-compare, react-is, react-router, readable-stream, redis-errors, redis-parser, require-directory, require-from-string, router, safe-buffer, safer-buffer, scheduler, send, serve-static, set-cookie-parser, shebang-command, shebang-regex, side-channel, side-channel-list, side-channel-map, side-channel-weakmap, source-map-support, standard-as-callback, statuses, streamsearch, string_decoder, string-width, strip-ansi, stripe, strtok3, toidentifier, token-types, type-is, typedarray, uid, uint8array-extras, undici-types, unpipe, util-deprecate, utils-merge, validator, vary, wrap-ansi, xtend, yargs, zod
Apache-2.0 (44 packages)
@aws-crypto/crc32, @aws-crypto/crc32c, @aws-crypto/sha1-browser, @aws-crypto/sha256-browser, @aws-crypto/sha256-js, @aws-crypto/supports-web-crypto, @aws-crypto/util, @aws-sdk/checksums, @aws-sdk/client-s3, @aws-sdk/core, @aws-sdk/credential-provider-env, @aws-sdk/credential-provider-http, @aws-sdk/credential-provider-ini, @aws-sdk/credential-provider-login, @aws-sdk/credential-provider-node, @aws-sdk/credential-provider-process, @aws-sdk/credential-provider-sso, @aws-sdk/credential-provider-web-identity, @aws-sdk/middleware-flexible-checksums, @aws-sdk/middleware-sdk-s3, @aws-sdk/nested-clients, @aws-sdk/signature-v4-multi-region, @aws-sdk/token-providers, @aws-sdk/types, @aws-sdk/util-locate-window, @aws-sdk/xml-builder, @aws/lambda-invoke-store, @smithy/core, @smithy/credential-provider-imds, @smithy/fetch-http-handler, @smithy/is-array-buffer, @smithy/node-http-handler, @smithy/signature-v4, @smithy/types, @smithy/util-buffer-from, @smithy/util-utf8, cluster-key-slot, denque, detect-libc, playwright, playwright-core, reflect-metadata, rxjs, typescript
ISC (19 packages)
@shopify/app-bridge-types, cliui, get-caller-file, inherits, isexe, iterare, once, pg-int8, require-main-filename, semver, set-blocking, setprototypeof, split2, which, which-module, wrappy, y18n, yargs-parser, zod-to-json-schema
BSD-3-Clause (6 packages)
fast-uri, ieee754, qs, react-transition-group, source-map, tiny-lru
Unknown (3 packages)
@shopify/polaris, @shopify/polaris-icons, @shopify/polaris-tokens
0BSD (1 package)
tslib
BSD-2-Clause (1 package)
json-schema-typed
MIT-0 (1 package)
nodemailer
Unlicense (1 package)
isbot
Questions
Anything about licensing or attribution: legal@consentcook.com. Our security page covers how we manage dependencies, including the vulnerability scanning that runs on every build.