Files
ThothII/docs/reports/2026-09-02-sensitivity-ner-license-inventory.md

2.7 KiB

Optional sensitivity NER license inventory

This inventory covers the isolated /opt/sensitivity-ner Python environment built from backend/python/sensitivity-ner-requirements.txt on 2 September 2026. It is a technical release gate, not legal advice. Every dependency is version-locked; changing any version requires regenerating this inventory and rerunning the offline CPU smoke test.

The optional runtime also dynamically links Debian's libseccomp2 (LGPL-2.1-only) solely to install its kernel-enforced network syscall filter; no libseccomp source is incorporated into ThothII.

No dependency or selected model uses a non-commercial, research-only, source-available, GPL, or AGPL license. MPL-2.0, PSF-2.0, and the permissive composite licenses below allow free-of-charge and commercial use, but distributors must still preserve their applicable notices and license texts.

License family Locked packages
Apache-2.0 accelerate==1.14.0, gliner2==2.0.0, hf-xet==1.6.0, huggingface-hub==0.36.2, peft==0.20.0, requests==2.34.2, safetensors==0.8.0, tokenizers==0.22.2, transformers==4.57.6
MIT annotated-types==0.8.0, charset-normalizer==3.5.1, filelock==3.32.5, pydantic==2.13.5, pydantic-core==2.46.5, PyYAML==6.0.3, typing-inspection==0.4.4, urllib3==2.7.0
BSD-2/3-Clause fsspec==2026.7.0, idna==3.19, Jinja2==3.1.6, MarkupSafe==3.0.3, mpmath==1.3.0, networkx==3.6.1, psutil==7.2.2, sympy==1.14.0
MPL-2.0 or mixed MPL/MIT certifi==2026.7.22, tqdm==4.70.0
PSF-2.0 typing-extensions==4.16.0
Composite permissive numpy==2.5.2 (BSD-3-Clause, 0BSD, MIT, Zlib, CC0), packaging==26.3 (Apache-2.0 or BSD-2-Clause), regex==2026.9.3 (Apache-2.0 and CNRI-Python), torch==2.14.0+cpu (Apache-2.0, LLVM exception, BSD, BSL-1.0, MIT)

The selected fastino/gliner2-privacy-filter-PII-multi weights at revision c153999da5f4c509df4322b0c6a1baf3d2c284d7 are marked Apache-2.0 in the model card. Its published microsoft/mdeberta-v3-base base model is MIT. The Fastino training corpus is described as synthetic but is not published, so the training process is not independently reproducible.

Before distributing the optional image or model pack:

  1. retain the upstream license and notice files for all packaged wheels, system libraries, and weights;
  2. archive THOTHII_MODEL_REVISION and the verified MODEL_SHA256SUMS beside the model;
  3. verify that pip check succeeds in the isolated environment;
  4. compare the installed distribution/version set with this inventory;
  5. repeat the licensing review if an upstream artifact or dependency changes.