# Third-party licences Python packages are installed by the user from `requirements.txt` (not shipped in this repo). Licences as published by each project, read 2026-09-29; update with any dependency change. | Package | Requirement | Licence | |---|---|---| | numpy | >=2.3 | BSD-3-Clause | | scipy | >=1.16 | BSD-3-Clause | | pillow | >=11 | MIT-CMU (HPND) | | h3 (h3-py) | >=4.5,<5 | Apache-2.0 | | numba (optional: compiled fast paths) | any | BSD-2-Clause | | llvmlite (with numba) | any | BSD-2-Clause; bundles LLVM: Apache-2.0 with LLVM exception | Vendored (shipped in this repo): | What | Where | Version | Licence | |---|---|---|---| | three.js | `viewer/vendor/` | three 0.186.1 (npm): build/three.module.js, build/three.core.js, examples/jsm/controls/OrbitControls.js | MIT, © Three.js Authors; notice: `viewer/vendor/LICENSE` | | "Hash without Sine" (Dave Hoskins), a few lines of GLSL | `viewer/js/tilelayer.js` (`grainHash`) | 2014 | MIT, © 2014 David Hoskins | Container image (`deploy/Containerfile`, built by the user, not shipped here): base `python:3.14-slim` (Python: PSF-2.0; Debian packages under their own licences) plus the pinned packages in `deploy/requirements.lock` (the six above).