v0.3.6 is out — configurable branding and reusable composition APIs. Read the notes
projectious·work
You are reading the v0.3.6 documentation. Go to v0.4.0
On this page

Dependencies and SBOM

Understand build tools, browser runtimes, bundled assets, versions and licences.

The theme has no server runtime. Hugo produces static files. Dependencies fall into build-time tools, browser-loaded libraries and bundled assets.

Direct dependency inventory#

ComponentVersionDeliveryPurposeLicence
Hugo0.128.0 minimum; verified with 0.164.0Build toolStatic-site generation and asset pipelineApache-2.0
Go1.22 module declarationBuild toolHugo Module resolutionBSD-3-Clause
@tailwindcss/cli4.3.3 lockednpm development dependencyCompile utility CSS from Hugo build statisticsMIT
Playwright test1.62.1 lockednpm development dependencyBrowser behavior and visual regression testsApache-2.0
Tabler Icons3.31.0 lockednpm development dependency mounted into Hugo assetsComplete outline icon catalogueMIT
IBM Plex Mono font package5.3.0 lockednpm development source for bundled WOFF2 cutsCode and syntax typographySIL OFL 1.1
FlexSearch0.8.143Bundled browser assetLocal full-text searchApache-2.0
KaTeX0.18.4Pinned CDN or self-hostedMathematics renderingMIT
Mermaid11.16.1Pinned CDN or self-hostedDiagram renderingMIT
asciinema-player3.17.0Pinned CDN or self-hostedTerminal recording playbackApache-2.0
nbconvert7.16.6Optional pinned Python toolConvert Jupyter notebooks to MarkdownBSD-3-Clause
Bundled fallback icons38 theme glyphsBundled assetsOffline interface fallbackMIT

Exact browser-runtime URLs are maintained in src/data/cdn.yaml; exact npm transitives and integrity values are in package-lock.json; Python conversion pins are in scripts/requirements.txt.

Bundled fonts and icons#

Plus Jakarta Sans, Source Sans 3 and IBM Plex Mono are bundled as WOFF2 under the SIL Open Font License 1.1. IBM Plex Mono includes normal and italic cuts at 400, 500, 600 and 700 so syntax roles use real faces rather than browser-synthesized weight or oblique. Licence texts ship under src/static/fonts/licenses/. The theme’s fallback SVG set follows Tabler geometry. The exact Tabler dependency is mounted from node_modules during the example build; consuming sites may use the same mount or rely on the fallback set. See Icons and Tabler. FlexSearch’s licence ships under src/static/licenses/flexsearch/.

SBOM scope and maintenance#

This page is the human-readable software bill of materials for v0.3.x. Before each release, maintainers must compare it with package-lock.json, requirements.txt, data/cdn.yaml, bundled asset directories and Hugo/Go declarations. Generated CycloneDX or SPDX output may supplement this page, but must not replace checked-in licence files or the exact lockfiles.

Run npm audit --json for the Node graph. CDN and bundled assets require separate release-note and advisory review because npm audit cannot see them.

Edit this page Updated Aug 16, 2026