2.7 KiB
Optional sensitivity NER license inventory
This inventory covers the isolated /opt/sensitivity-ner Python environment built from
backend/python/sensitivity-ner-requirements.txt on 2 September 2026. It is a technical release
gate, not legal advice. Every dependency is version-locked; changing any version requires
regenerating this inventory and rerunning the offline CPU smoke test.
The optional runtime also dynamically links Debian's libseccomp2 (LGPL-2.1-only) solely to
install its kernel-enforced network syscall filter; no libseccomp source is incorporated into ThothII.
No dependency or selected model uses a non-commercial, research-only, source-available, GPL, or AGPL license. MPL-2.0, PSF-2.0, and the permissive composite licenses below allow free-of-charge and commercial use, but distributors must still preserve their applicable notices and license texts.
| License family | Locked packages |
|---|---|
| Apache-2.0 | accelerate==1.14.0, gliner2==2.0.0, hf-xet==1.6.0, huggingface-hub==0.36.2, peft==0.20.0, requests==2.34.2, safetensors==0.8.0, tokenizers==0.22.2, transformers==4.57.6 |
| MIT | annotated-types==0.8.0, charset-normalizer==3.5.1, filelock==3.32.5, pydantic==2.13.5, pydantic-core==2.46.5, PyYAML==6.0.3, typing-inspection==0.4.4, urllib3==2.7.0 |
| BSD-2/3-Clause | fsspec==2026.7.0, idna==3.19, Jinja2==3.1.6, MarkupSafe==3.0.3, mpmath==1.3.0, networkx==3.6.1, psutil==7.2.2, sympy==1.14.0 |
| MPL-2.0 or mixed MPL/MIT | certifi==2026.7.22, tqdm==4.70.0 |
| PSF-2.0 | typing-extensions==4.16.0 |
| Composite permissive | numpy==2.5.2 (BSD-3-Clause, 0BSD, MIT, Zlib, CC0), packaging==26.3 (Apache-2.0 or BSD-2-Clause), regex==2026.9.3 (Apache-2.0 and CNRI-Python), torch==2.14.0+cpu (Apache-2.0, LLVM exception, BSD, BSL-1.0, MIT) |
The selected fastino/gliner2-privacy-filter-PII-multi weights at revision
c153999da5f4c509df4322b0c6a1baf3d2c284d7 are marked Apache-2.0 in the
model card. Its published
microsoft/mdeberta-v3-base base model is MIT. The Fastino training corpus is described as
synthetic but is not published, so the training process is not independently reproducible.
Before distributing the optional image or model pack:
- retain the upstream license and notice files for all packaged wheels, system libraries, and weights;
- archive
THOTHII_MODEL_REVISIONand the verifiedMODEL_SHA256SUMSbeside the model; - verify that
pip checksucceeds in the isolated environment; - compare the installed distribution/version set with this inventory;
- repeat the licensing review if an upstream artifact or dependency changes.