Skip to main content
This index covers what make verify builds and runs. It is an evaluation-stage notice list, not a legal review, and it certifies nothing for production. dependency-inventory.json is written by python3 scripts/inventory.py <quivr-binary> <output>, and each make verify run writes one next to its report. When a licence cannot be identified from a licence file or a lock entry, the inventory says unclassified instead of guessing.

Unresolved

  • Model provenance. The E5 training data and the declared MIT licence are as published on the upstream model card. They are not independently verified, and the model repository has no standalone LICENSE file at the pinned revision.
  • Platforms. Only linux/amd64 is supported and tested. macOS and linux/arm64 have no pinned tokenizer wheel or TEI digest, and the harness’s process checks read /proc. No other platform is claimed.
  • Container images. Their licences are not inventoried; they are used as pinned upstream images.