#Open Source Licenses
Last updated: 2026-07-10 — Corresponds to SKWADE package.json version 0.9.0.
#1. Introduction
SKWADE is built on top of a large ecosystem of open-source software. This document lists every open-source dependency that ships with the SKWADE application (Web, iOS and Android), together with its license, homepage and required attribution.
The information below is generated from the project manifest (package.json, bun.lock), the native bridge (capacitor.config.ts), the vendored source in vendor/ and the WebAssembly artifacts in public/wasm/. It reflects the exact set of libraries actually used by SKWADE — no template or placeholder entries.
#2. Why open source?
SKWADE relies on open-source software for three reasons:
- Security and auditability. Open source lets us — and independent
reviewers — audit the exact code that runs on divers' devices.
- Interoperability. Diving standards, dive-computer protocols and
marine biodiversity data are all documented and implemented in the open. Reusing that work is the only way to remain compatible with the wider ecosystem (libdivecomputer, GBIF, WoRMS, Wikimedia, etc.).
- Sustainability. Building on well-maintained libraries lets our
small team focus on the diving experience rather than reinventing infrastructure.
We are grateful to every author and maintainer whose work is listed below.
#3. General attribution
Unless otherwise noted, every library listed below is used unmodified and linked dynamically at build time via Vite / Bun. The full text of each SPDX license identifier is available at <https://spdx.org/licenses/>.
Where a library requires attribution (MIT, BSD, Apache-2.0, ISC), the copyright notice is reproduced in this document. Where a library is distributed under a copyleft license (LGPL-2.1-or-later — applies to libdivecomputer only), the full corresponding source and relink instructions are shipped in the repository under vendor/libdivecomputer/, docs/licenses/libdivecomputer-COPYING and docs/native/libdivecomputer.md. See also NOTICE.md at the repository root.
#4. Runtime dependencies (alphabetical)
| Package | Version | License | Homepage |
|---|---|---|---|
| @capacitor-community/bluetooth-le | 8.2.x | MIT | https://github.com/capacitor-community/bluetooth-le |
| @capacitor/app | 8.1.x | MIT | https://capacitorjs.com/docs/apis/app |
| @capacitor/core | 8.4.x | MIT | https://capacitorjs.com |
| @capacitor/device | 8.0.x | MIT | https://capacitorjs.com/docs/apis/device |
| @capacitor/haptics | 8.0.x | MIT | https://capacitorjs.com/docs/apis/haptics |
| @capacitor/keyboard | 8.0.x | MIT | https://capacitorjs.com/docs/apis/keyboard |
| @capacitor/network | 8.0.x | MIT | https://capacitorjs.com/docs/apis/network |
| @capacitor/preferences | 8.0.x | MIT | https://capacitorjs.com/docs/apis/preferences |
| @capacitor/splash-screen | 8.0.x | MIT | https://capacitorjs.com/docs/apis/splash-screen |
| @capacitor/status-bar | 8.0.x | MIT | https://capacitorjs.com/docs/apis/status-bar |
| @hookform/resolvers | 5.2.x | MIT | https://github.com/react-hook-form/resolvers |
| @lovable.dev/cloud-auth-js | 1.1.x | Proprietary (Lovable, redistributable client) | https://lovable.dev |
| @radix-ui/react-* (accordion, alert-dialog, aspect-ratio, avatar, checkbox, collapsible, context-menu, dialog, dropdown-menu, hover-card, label, menubar, navigation-menu, popover, progress, radio-group, scroll-area, select, separator, slider, slot, switch, tabs, toggle, toggle-group, tooltip) | 1.x / 2.x | MIT | https://www.radix-ui.com |
| @react-pdf-viewer/core, default-layout, full-screen, get-file, page-navigation, print, search, zoom | 3.12.x | Apache-2.0 | https://react-pdf-viewer.dev |
| @supabase/supabase-js | 2.108.x | MIT | https://github.com/supabase/supabase-js |
| @tailwindcss/vite | 4.2.x | MIT | https://tailwindcss.com |
| @tanstack/react-query | 5.83.x | MIT | https://tanstack.com/query |
| @tanstack/react-router | 1.168.x | MIT | https://tanstack.com/router |
| @tanstack/react-start | 1.167.x | MIT | https://tanstack.com/start |
| @tanstack/react-virtual | 3.14.x | MIT | https://tanstack.com/virtual |
| @tanstack/router-plugin | 1.167.x | MIT | https://tanstack.com/router |
| @tanstack/zod-adapter | 1.167.x | MIT | https://tanstack.com/router |
| @yudiel/react-qr-scanner | 2.6.x | MIT | https://github.com/yudielcurbelo/react-qr-scanner |
| browser-image-compression | 2.0.x | MIT | https://github.com/Donaldcwl/browser-image-compression |
| class-variance-authority | 0.7.x | Apache-2.0 | https://cva.style |
| clsx | 2.1.x | MIT | https://github.com/lukeed/clsx |
| cmdk | 1.1.x | MIT | https://cmdk.paco.me |
| date-fns | 4.1.x | MIT | https://date-fns.org |
| embla-carousel-react | 8.6.x | MIT | https://www.embla-carousel.com |
| fast-xml-parser | 5.9.x | MIT | https://github.com/NaturalIntelligence/fast-xml-parser |
| fflate | 0.8.x | MIT | https://github.com/101arrowz/fflate |
| fit-file-parser | 3.0.x | MIT | https://github.com/jimmyoneill/fit-file-parser |
| garmin-connect | 1.6.x | MIT | https://github.com/Pythe1337N/garmin-connect |
| heic2any | 0.0.4 | MIT | https://github.com/alexcorvi/heic2any |
| input-otp | 1.4.x | MIT | https://input-otp.rdsx.dev |
| leaflet | 1.9.x | BSD-2-Clause | https://leafletjs.com |
| leaflet.markercluster | 1.5.x | MIT | https://github.com/Leaflet/Leaflet.markercluster |
| lucide-react | 0.575.x | ISC | https://lucide.dev |
| passkit-generator | 3.5.x | MIT | https://github.com/alexandercerutti/passkit-generator |
| pdfjs-dist | 3.11.174 | Apache-2.0 | https://mozilla.github.io/pdf.js/ |
| qrcode | 1.5.x | MIT | https://github.com/soldair/node-qrcode |
| qrcode.react | 4.2.x | ISC | https://github.com/zpao/qrcode.react |
| react | 19.2.x | MIT | https://react.dev |
| react-day-picker | 9.14.x | MIT | https://react-day-picker.js.org |
| react-dom | 19.2.x | MIT | https://react.dev |
| react-easy-crop | 6.1.x | MIT | https://github.com/ValentinH/react-easy-crop |
| react-hook-form | 7.71.x | MIT | https://react-hook-form.com |
| react-leaflet | 5.0.x | Hippocratic-2.1 | https://react-leaflet.js.org |
| react-resizable-panels | 4.6.x | MIT | https://github.com/bvaughn/react-resizable-panels |
| recharts | 2.15.x | MIT | https://recharts.org |
| sonner | 2.0.x | MIT | https://sonner.emilkowal.ski |
| tailwind-merge | 3.5.x | MIT | https://github.com/dcastil/tailwind-merge |
| tailwindcss | 4.2.x | MIT | https://tailwindcss.com |
| tw-animate-css | 1.3.x | MIT | https://github.com/Wombosvideo/tw-animate-css |
| vaul | 1.1.x | MIT | https://vaul.emilkowal.ski |
| vite-tsconfig-paths | 6.0.x | MIT | https://github.com/aleclarson/vite-tsconfig-paths |
| xlsx | 0.18.x | Apache-2.0 | https://sheetjs.com |
| yet-another-react-lightbox | 3.32.x | MIT | https://yet-another-react-lightbox.com |
| zod | 3.24.x | MIT | https://zod.dev |
#5. Build / development dependencies
| Package | Version | License | Homepage |
|---|---|---|---|
| @capacitor/android | 8.4.x | MIT | https://capacitorjs.com |
| @capacitor/cli | 8.4.x | MIT | https://capacitorjs.com |
| @capacitor/ios | 8.4.x | MIT | https://capacitorjs.com |
| @eslint/js | 9.32.x | MIT | https://eslint.org |
| @lovable.dev/vite-tanstack-config | 2.7.x | Proprietary (Lovable) | https://lovable.dev |
| @types/leaflet | 1.9.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/leaflet.markercluster | 1.5.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/node | 22.16.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/qrcode | 1.5.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/react | 19.2.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @types/react-dom | 19.2.x | MIT | https://github.com/DefinitelyTyped/DefinitelyTyped |
| @vitejs/plugin-react | 5.2.x | MIT | https://github.com/vitejs/vite-plugin-react |
| eslint | 9.32.x | MIT | https://eslint.org |
| eslint-config-prettier | 10.1.x | MIT | https://github.com/prettier/eslint-config-prettier |
| eslint-plugin-prettier | 5.2.x | MIT | https://github.com/prettier/eslint-plugin-prettier |
| eslint-plugin-react-hooks | 5.2.x | MIT | https://react.dev |
| eslint-plugin-react-refresh | 0.4.x | MIT | https://github.com/ArnaudBarre/eslint-plugin-react-refresh |
| globals | 15.15.x | MIT | https://github.com/sindresorhus/globals |
| nitro | 3.0.x-beta | MIT | https://nitro.build |
| prettier | 3.7.x | MIT | https://prettier.io |
| typescript | 5.8.x | Apache-2.0 | https://www.typescriptlang.org |
| typescript-eslint | 8.56.x | MIT / BSD-2-Clause | https://typescript-eslint.io |
| vite | 8.0.x | MIT | https://vitejs.dev |
| vitest | 4.1.x | MIT | https://vitest.dev |
#6. Vendored / native components
#libdivecomputer
- Version pinned: upstream commit
35df71c0fa55fc2559b6a70ca791eddbbe3d1a6b(2026-07-03). - License: GNU Lesser General Public License, version 2.1 or later
(LGPL-2.1-or-later).
- Copyright: © Jef Driesen and contributors.
- Location in repository:
vendor/libdivecomputer/(full upstream source,
minus .git) plus vendor/libdivecomputer-shim.c (SKWADE-authored build-time shim, LGPL-compatible).
- Full license text:
docs/licenses/libdivecomputer-COPYING. - Build reproduction, ABI documentation and relink instructions:
docs/native/libdivecomputer.md.
- Runtime artifacts:
public/wasm/libdivecomputer.wasmand
public/wasm/libdivecomputer.mjs — end users may substitute their own build against the same shim ABI, as required by LGPL-2.1 §6(a).
SKWADE is not affiliated with the libdivecomputer project and does not speak on its behalf.
#7. Standard reproduced notices
The following notice covers every MIT / BSD / ISC / Apache-2.0 dependency listed above. Copyright is held by the respective authors of each package as listed in that package's source repository.
Permission is hereby granted, free of charge, to any person obtaining a copy of the software and associated documentation files (the "Software"), to deal in the Software without restriction (…). THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED (…).
The full, per-package license text is available in each package's LICENSE file, distributed inside node_modules/<package>/ after bun install, and mirrored in each project's public repository (see "Homepage" column above).
#8. Maintenance statement
This document is regenerated whenever package.json, bun.lock or the vendored vendor/ tree changes. The canonical source of truth for dependency versions is package.json; this file exists to make the license position explicit for legal, regulatory and store-review purposes (App Store, Google Play, procurement audits).
If you believe a library used by SKWADE is missing from this list or listed with an incorrect license, contact <legal@skwade.app>.