v3.0.2 is out — restored design-system guidance and corrected navigation. Read the notes
projectious·work
On this page

SBOM and dependencies

Supply-chain scope, licences, and maintenance obligations for the projectious.work design system.

Direct dependency inventory#

DependencyPurposeLicenceDelivery
brand-theme-hugo-vanilla v0.3.1Documentation rendererMITPinned Hugo module
Hugo extendedStatic-site buildApache-2.0Build-time tool
Plus Jakarta SansDisplay and headingsOFL-1.1Self-hosted by the theme
Source Sans 3Body and UI copyOFL-1.1Self-hosted by the theme
IBM Plex MonoCode, data, and terminalOFL-1.1Self-hosted by the theme
Tabler IconsInterface iconographyMITVersioned theme subset
FlexSearchClient-side searchApache-2.0Vendored theme runtime
PyYAMLToken and manifest generationMITEphemeral uv dependency
PlaywrightBrowser verificationApache-2.0Ephemeral uv dependency

Scope#

The SBOM covers code and assets shipped to a browser, build-time tools needed to reproduce the published site, generators used to create public downloads, and third-party material embedded in templates. It does not classify the reserved projectious.work marks as third-party dependencies.

Maintenance rules#

  • Pin released modules and vendored assets to a reviewable version.
  • Ship licence text beside self-hosted fonts and icon subsets.
  • Do not mix a second icon library into the Tabler set.
  • Record substitutions explicitly, including why the canonical delivery path was unsuitable.
  • Rebuild and review the SBOM whenever the module graph, fonts, icons, search runtime, or generation tools change.

The per-asset evidence remains in Provenance.

Updated Aug 17, 2026