Open source

Open-source licenses

ImOnFHIR is itself proprietary, and it is built on 139 open-source packages under 12 distinct licenses. This is all of them, generated from the lockfile rather than maintained by hand.

What this covers. Every package reachable from this project’s runtime dependencies, transitively — not just the ones named directly. Build and development tooling is excluded, because it is not part of anything served.

That exclusion is worth stating precisely: it drops the database CLI and its subtree, which an ordinary production listing includes only because the client library names the CLI as a peer dependency. Counting those would inflate this page to 273 packages and imply obligations for code that never ships.

Some entries are platform-specific binaries. Only the one matching the deployment platform is ever installed, so where a component ships no license file of its own, the notice below cites the upstream terms instead of quoting a file that is not there.

Requires attribution beyond a license name

These carry obligations we have to actively meet — reproducing a notice, or honouring a naming restriction. Each obligation is listed with the component.

  • @lhncbc/ucum-lhc7.1.9SEE LICENSE IN LICENSE.md
    • Reproduce the Owner Notice, the conditions and the disclaimer in binary redistributions — satisfied by this NOTICE file and the /licenses page.
    • Do not use the NLM, LHNCBC or NIH names to endorse or promote derived products.
    • Incorporates LOINC and UCUM content terms by reference (loinc.org/terms-of-use, ucum.org/license).
    • The authors request citation in publications that use the software.

Weak copyleft, dynamically linked and unmodified

Image-processing binaries reached through an optional dependency of Next.js. They run on the server during build and image serving, are never part of a browser bundle, and are not modified. Only the binary matching the deployment platform is installed; the rest are lockfile entries that never materialise.

  • @img/sharp-libvips-darwin-arm641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-darwin-x641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-arm1.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-arm641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-ppc641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-riscv641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-s390x1.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linux-x641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linuxmusl-arm641.3.2LGPL-3.0-or-later
  • @img/sharp-libvips-linuxmusl-x641.3.2LGPL-3.0-or-later
  • @img/sharp-wasm320.35.3Apache-2.0 AND LGPL-3.0-or-later AND MIT
  • @img/sharp-win32-arm640.35.3Apache-2.0 AND LGPL-3.0-or-later
  • @img/sharp-win32-ia320.35.3Apache-2.0 AND LGPL-3.0-or-later
  • @img/sharp-win32-x640.35.3Apache-2.0 AND LGPL-3.0-or-later

Fonts

Declared as a dependency and therefore attributed. The typography actually shipped is Inter and JetBrains Mono, self-hosted at build time.

  • geist1.7.2SIL OPEN FONT LICENSE

Data

A dataset rather than code, used at build time. Attribution required; none of its content is republished here.

  • caniuse-lite1.0.30001799CC-BY-4.0

Permissive

MIT, ISC, Apache-2.0 and the BSD family. Attribution is satisfied by naming the component and retaining its copyright line, which the repository NOTICE file does in full.

  • @babel/runtime7.29.7MIT
  • @codemirror/autocomplete6.20.3MIT
  • @codemirror/commands6.10.4MIT
  • @codemirror/lang-json6.0.2MIT
  • @codemirror/language6.12.4MIT
  • @codemirror/lint6.9.7MIT
  • @codemirror/search6.7.1MIT
  • @codemirror/state6.7.1MIT
  • @codemirror/theme-one-dark6.1.3MIT
  • @codemirror/view6.43.6MIT
  • @emnapi/runtime1.11.1MIT
  • @img/colour1.1.0MIT
  • @img/sharp-darwin-arm640.35.3Apache-2.0
  • @img/sharp-darwin-x640.35.3Apache-2.0
  • @img/sharp-freebsd-wasm320.35.3Apache-2.0
  • @img/sharp-linux-arm0.35.3Apache-2.0
  • @img/sharp-linux-arm640.35.3Apache-2.0
  • @img/sharp-linux-ppc640.35.3Apache-2.0
  • @img/sharp-linux-riscv640.35.3Apache-2.0
  • @img/sharp-linux-s390x0.35.3Apache-2.0
  • @img/sharp-linux-x640.35.3Apache-2.0
  • @img/sharp-linuxmusl-arm640.35.3Apache-2.0
  • @img/sharp-linuxmusl-x640.35.3Apache-2.0
  • @img/sharp-webcontainers-wasm320.35.3Apache-2.0
  • @lezer/common1.5.2MIT
  • @lezer/highlight1.2.3MIT
  • @lezer/json1.0.3MIT
  • @lezer/lr1.4.10MIT
  • @marijn/find-cluster-break1.0.3MIT
  • @next/env15.5.21MIT
  • @next/swc-darwin-arm6415.5.21MIT
  • @next/swc-darwin-x6415.5.21MIT
  • @next/swc-linux-arm64-gnu15.5.21MIT
  • @next/swc-linux-arm64-musl15.5.21MIT
  • @next/swc-linux-x64-gnu15.5.21MIT
  • @next/swc-linux-x64-musl15.5.21MIT
  • @next/swc-win32-arm64-msvc15.5.21MIT
  • @next/swc-win32-x64-msvc15.5.21MIT
  • @prisma/adapter-pg7.9.0Apache-2.0
  • @prisma/client7.9.0Apache-2.0
  • @prisma/client-runtime-utils7.9.0Apache-2.0
  • @prisma/debug7.9.0Apache-2.0
  • @prisma/driver-adapter-utils7.9.0Apache-2.0
  • @swc/helpers0.5.15Apache-2.0
  • @types/node26.1.1MIT
  • @types/pg8.20.0MIT
  • @uiw/codemirror-extensions-basic-setup4.25.11MIT
  • @uiw/react-codemirror4.25.11MIT
  • @vercel/analytics2.0.1MIT
  • argparse1.0.10MIT
  • client-only0.0.1MIT
  • codemirror6.0.2MIT
  • coffeescript2.7.0MIT
  • core-util-is1.0.3MIT
  • cql-exec-fhir2.1.6Apache-2.0
  • cql-execution3.3.2Apache-2.0
  • crelt1.0.7MIT
  • csv-parse4.16.3MIT
  • csv-stringify1.1.2BSD-3-Clause
  • detect-libc2.1.2Apache-2.0
  • escape-html1.0.3MIT
  • esprima4.0.1BSD-2-Clause
  • extend-shallow2.0.1MIT
  • graceful-fs4.2.11ISC
  • gray-matter4.0.3MIT
  • immutable5.1.9MIT
  • inherits2.0.4ISC
  • is-extendable0.1.1MIT
  • is-finite1.1.0MIT
  • is-integer1.0.7WTFPL OR ISC
  • isarray1.0.0MIT
  • js-yaml3.15.0MIT
  • jsonfile2.4.0MIT
  • kind-of6.0.3MIT
  • lodash.get4.4.2MIT
  • luxon3.7.2MIT
  • marked18.0.6MIT
  • nanoid3.3.15MIT
  • next15.5.21MIT
  • pg8.22.0MIT
  • pg-cloudflare1.4.0MIT
  • pg-connection-string2.14.0MIT
  • pg-int81.0.1ISC
  • pg-pool3.14.0MIT
  • pg-protocol1.15.0MIT
  • pg-types2.2.0MIT
  • pgpass1.0.5MIT
  • picocolors1.1.1ISC
  • postcss8.5.19MIT
  • postgres-array2.0.0MIT
  • postgres-array3.0.4MIT
  • postgres-bytea1.0.1MIT
  • postgres-date1.0.7MIT
  • postgres-interval1.2.0MIT
  • process-nextick-args2.0.1MIT
  • react19.2.8MIT
  • react-dom19.2.8MIT
  • readable-stream2.3.8MIT
  • safe-buffer5.1.2MIT
  • sax1.1.6ISC
  • sax1.6.1BlueOak-1.0.0
  • scheduler0.27.0MIT
  • section-matter1.0.0MIT
  • semver7.8.5ISC
  • sharp0.35.3Apache-2.0
  • source-map-js1.2.1BSD-3-Clause
  • split24.2.0ISC
  • sprintf-js1.0.3BSD-3-Clause
  • stream-transform0.1.2BSD-3-Clause
  • string_decoder1.1.1MIT
  • string-to-stream1.1.1MIT
  • strip-bom-string1.0.0MIT
  • style-mod4.1.3MIT
  • styled-jsx5.1.6MIT
  • tslib2.8.10BSD
  • undici-types8.3.0MIT
  • util-deprecate1.0.2MIT
  • w3c-keyname2.2.8MIT
  • xml2js0.6.2MIT
  • xmlbuilder11.0.1MIT
  • xmldoc0.4.0MIT
  • xtend4.0.2MIT

Services and tools we run

Not linked into any bundle — these run as separate services or build-time tools, and none of them sees anything you paste into the browser-only tools.

  • HL7 FHIR Validator (Inferno community image)Apache-2.0

    The validation sidecar — the same engine behind the official validator, so our standards verdicts match what implementers already trust.

  • HAPI FHIRApache-2.0

    The FHIR server class our hosted sandbox and adapter integrate against — the reference implementation most real systems run.

  • SyntheaApache-2.0

    Generates the synthetic patients behind our fixtures; generated data carries no upstream license restriction.

  • Vercel · Cloudflare · DigitalOcean · Neoncommercial services

    Hosting, tunnel/access control, the sidecar host, and the database. The full subprocessor list with data-handling detail lives on /security.

Where this is canonical

The full notices, including every copyright line, live in the NOTICE file at the root of the repository. Both it and this page are generated by one script from package-lock.json, and a check in CI fails the build if either drifts from the lockfile, if a component arrives under a license class that has not been reviewed, or if a component whose license text we quote changes that text.