Open Source & Third-Party Software

Transparency, compliance, and our commitment to the communities that power our work. This document outlines the open-source and third-party components used across That Is A Q's product ecosystem.

Our Open Source Philosophy

That Is A Q recognizes that modern software development stands on the shoulders of a vast, collaborative community. We actively use, test, and contribute to open-source projects. Our commitment includes:

Core Principles We prioritize permissive and community-friendly licenses, maintain strict attribution records, audit dependencies regularly, and give back through bug fixes, documentation improvements, and financial sponsorships where applicable.

We maintain a centralized software bill of materials (SBOM) for all client deliveries and internal tools to ensure full traceability and licensing compliance.

Dependency Registry

Below is a curated list of core open-source and third-party libraries integrated into our standard development stack. For the complete machine-readable SBOM, contact our engineering team.

Package / Tool Category License Usage Context
ReactFrontend FrameworkMITUI components, SPA architecture
Next.jsFull-Stack FrameworkMITServer-side rendering, routing, API routes
Node.jsRuntime EnvironmentBSL 1.1Backend services, build tooling
PostgreSQLDatabasePostgreSQLPrimary relational data store
Tailwind CSSUtility CSS FrameworkMITResponsive styling system
Stripe.jsThird-Party SDKCommercialSecure payment processing
DockerContainerizationApache 2.0Development & deployment environments
PlaywrightTesting FrameworkApache 2.0E2E testing automation
ESLintLinting / Code QualityMITStatic analysis & formatting
AWS SDKCloud ServicesApache 2.0Storage, compute, and networking APIs

Compliance & Attribution Policy

All open-source components used in That Is A Q projects are tracked against the OSI Open Source Definition. We enforce the following compliance standards:

  • Automated license scanning via CI/CD pipelines on every commit
  • Mandatory attribution files (NOTICE, CREDITS.md) bundled with client deliveries
  • Strict prohibition of non-permissive or copyleft licenses unless explicitly approved by legal & client
  • Quarterly SBOM audits and dependency vulnerability assessments
  • Transparent disclosure of all third-party services integrated into client products

If you are a maintainer of an open-source project used by us and believe attribution is missing or incorrect, please open a ticket via our compliance portal.

Security & Vulnerability Management

Security is treated as a first-class citizen in our dependency management workflow. We utilize automated tools and manual review processes to mitigate risks:

Vulnerability Response SLA Critical (CVSS ≥ 9.0): Patches within 24–48 hours
High (CVSS 7.0–8.9): Patches within 5 business days
Medium/Low: Addressed in standard release cycles

We participate in coordinated vulnerability disclosure (CVD) programs and encourage responsible reporting. If you discover a security issue in any of our published open-source tools, please email security@thatisaq.com.

Contribution Guidelines

We welcome contributions to the open-source projects we maintain and use. Whether it's a bug fix, feature request, documentation improvement, or translation, all contributions must adhere to:

  • Our Contributor License Agreement (CLA) for external maintainers
  • Consistent code style enforced via pre-commit hooks and CI checks
  • Clear, concise commit messages following Conventional Commits spec
  • Respectful collaboration aligned with our Code of Conduct

To get started, review our GitHub organization templates, fork the repository, and submit a pull request. Our engineering team will triage and merge approved changes within one sprint cycle.

Need Licensing or Compliance Documentation?

For official SBOM exports, license verification reports, or enterprise compliance agreements, please reach out to our legal & operations team:

Email: compliance@thatisaq.com
Portal: oss.thatisaq.com/registry