Peep collector: source and licenses

This is the complete corresponding source of the Peep collector server you are talking to, offered to everyone who uses it.

Download collector.tar.gz

What you get

One archive, built from the same files as the running server. It holds the collector source, the workspace manifests and bun.lock, the container build recipe, every dependency exactly as published, and the full upstream source of the AGPL-licensed libraries at the commit they were published from. SOURCE-README.md inside the archive explains the layout and how to rebuild.

Files

collector.tar.gz
The source archive.
SHA256SUMS.txt
SHA-256 of the archive, in sha256sum format.
manifest.json
Archive digests, pinned upstream commits and the dependency list with integrity hashes.
LICENSE.txt
Licensing scope of the collector and the full GNU AGPL version 3 text.
THIRD_PARTY_NOTICES.txt
Every bundled dependency with its complete license text.

Verify the download

curl -fsSLO <this site>/source/collector.tar.gz
curl -fsSLO <this site>/source/SHA256SUMS.txt
sha256sum -c SHA256SUMS.txt

Licensing

Peep's own collector code is MIT-licensed. The collector bundles four libraries from Peculiar Ventures' acme-ts project (@peculiar/acme-client, acme-core, acme-protocol and jose, version 1.8.2) that are licensed under the GNU Affero General Public License, version 3. The collector as built and run is therefore provided under the AGPL-3.0, and this page is the source offer that license requires.

The Peep command-line client, TypeScript SDK and protocol package are separate programs that only talk to the collector over the network. They contain none of this AGPL code and remain MIT-licensed. LICENSE.txt has the exact statement.