v0.4.0 is out — data-driven components and integrated graphics. Read the notes
projectious·theme
On this page

Dependencies and SBOM

Understand build tools, browser runtimes, bundled assets, versions and licences.

The theme has no server runtime. Hugo produces static files. Dependencies fall into build-time tools, browser-loaded libraries and bundled assets.

Direct dependency inventory#

ComponentVersionDeliveryPurposeLicence
Hugo0.128.0 minimum; verified with 0.165.0Build toolStatic-site generation and asset pipelineApache-2.0
Go1.22 module declarationBuild toolHugo Module resolutionBSD-3-Clause
@tailwindcss/cli4.3.3 lockednpm development dependencyCompile utility CSS from Hugo build statisticsMIT
Playwright test1.62.1 lockednpm development dependencyBrowser behavior and visual regression testsApache-2.0
Tabler Icons3.31.0 lockednpm development dependency mounted into Hugo assetsComplete outline icon catalogueMIT
IBM Plex Mono font package5.3.0 lockednpm development source for bundled WOFF2 cutsCode and syntax typographySIL OFL 1.1
FlexSearch0.8.143Bundled browser assetLocal full-text searchApache-2.0
KaTeX0.18.4Pinned CDN or self-hostedMathematics renderingMIT
Mermaid11.16.1Pinned CDN or self-hostedDiagram renderingMIT
D37.9.0Pinned CDN or self-hostedPlot data parsing and scalesISC
Observable Plot0.6.17Pinned CDN or self-hostedHigh-level interactive chartsISC
JSXGraph1.13.2Pinned CDN or self-hostedInteractive mathematical constructionsMIT or LGPL-3.0-or-later
WaveDrom3.6.2Pinned CDN or self-hostedDigital timing diagramsMIT
SMILES Drawer2.4.1Pinned CDN or self-hostedLightweight chemical structuresMIT
pseudocode.js2.4.1Pinned CDN or self-hostedAlgorithms as semantic HTMLMIT
asciinema-player3.17.0Pinned CDN or self-hostedTerminal recording playbackApache-2.0
nbconvert7.16.6Optional pinned Python toolConvert Jupyter notebooks to MarkdownBSD-3-Clause
Bundled fallback icons38 theme glyphsBundled assetsOffline interface fallbackMIT

D2, Graphviz and Typst are optional build tools. The graphics pre-renderer calls only a backend used by uncached content, so a consuming project installs the subset it needs. Their versions should be pinned in that project’s build image; they are not mandatory theme dependencies.

See Installation for the required core toolchain, optional renderer commands and offline/self-hosted setup.

Exact browser-runtime URLs are maintained in src/data/cdn.yaml; exact npm transitives and integrity values are in package-lock.json; Python conversion pins are in scripts/requirements.txt.

Bundled fonts and icons#

Plus Jakarta Sans, Source Sans 3 and IBM Plex Mono are bundled as WOFF2 under the SIL Open Font License 1.1. IBM Plex Mono includes normal and italic cuts at 400, 500, 600 and 700 so syntax roles use real faces rather than browser-synthesized weight or oblique. Licence texts ship under src/static/fonts/licenses/. The theme’s fallback SVG set follows Tabler geometry. The exact Tabler dependency is mounted from node_modules during the example build; consuming sites may use the same mount or rely on the fallback set. See Icons and Tabler. FlexSearch’s licence ships under src/static/licenses/flexsearch/.

SBOM scope and maintenance#

This page is the human-readable software bill of materials for v0.3.x. Before each release, maintainers must compare it with package-lock.json, requirements.txt, data/cdn.yaml, bundled asset directories and Hugo/Go declarations. Generated CycloneDX or SPDX output may supplement this page, but must not replace checked-in licence files or the exact lockfiles.

Run npm audit --json for the Node graph. CDN and bundled assets require separate release-note and advisory review because npm audit cannot see them.

Edit this page Updated Aug 26, 2026