snailmail is MIT licensed. It links the modules below, all under permissive licences compatible with redistribution: no dependency is copyleft, and none imposes a condition beyond attribution.
Recorded here so an adopter does not have to repeat the audit. Regenerate with:
go list -deps -f '{{with .Module}}{{.Path}} {{.Dir}}{{end}}' ./...and read the licence file at each module root.
The AWS SDK for Go v2 and its supporting modules, used only by the S3 blob store
and host adapters — both compiled out by the nos3 build tag.
github.com/aws/aws-sdk-go-v2and itsconfig,credentials,feature/ec2/imds,service/s3,service/sso,service/ssooidc,service/stsand internal modulesgithub.com/aws/smithy-go
github.com/ProtonMail/go-crypto— OpenPGP signing and verificationgithub.com/cloudflare/circl— cryptographic primitives used by the abovegithub.com/klauspost/compress— deterministic gzip and zstdgithub.com/ulikunitz/xz— xz, for Debian control archivesgolang.org/x/crypto,golang.org/x/net,golang.org/x/sys
github.com/Masterminds/semver/v3— Helm chart version orderinggithub.com/pelletier/go-toml/v2— manifest and lock encodinggopkg.in/yaml.v3— Helm index encoding
github.com/goreleaser/nfpm/v2 builds the deb, rpm and apk packages during
make packages. It is run with go run at release time and is not linked into
the binary, so it is not a dependency of the distributed artifact.