The tool has two production dependencies, the model runtime library and tesseract.js (the OCR engine, Apache-2.0), and two development dependencies. The lockfile lists 90 packages, each with its content hash. Of those, 64 install on a given machine, and the rest are per‑platform variants. A generator classifies their licenses, so no one sorts them by hand: 63 permissive, 1 with obligations, 0 blocking, 0 undetermined, re‑checked on each test run. A CycloneDX software bill of materials ships with the tool.
The repository itself has no install‑time script, a script that runs when a package is installed, beyond wiring its own git hooks. Two transitive production packages do carry install scripts. On macOS and Windows they touch nothing beyond the npm registry. On one platform, linux/x64, one of them fetches optional GPU providers from a second registry at install time. npm ci --ignore-scripts disables both scripts, and running on CPU, as documented, loses nothing.
Check the countsThe license table and the test count are both generated. Each has a checker that fails the suite when the document drifts from the sources.
run it yourself
node src/licences.ts --checkfails when the license table driftsnode src/readme.ts --checkfails when the test count drifts