PawFlow Docker images bundle third-party operating system packages, language runtimes, package-manager dependencies, and developer tools. This file summarizes the redistribution posture for the public images built by .github/workflows/docker-publish.yml.
This notice is not a substitute for dependency review. The release workflow does not publish BuildKit SBOM/provenance attestations because GHCR exposes those attestation manifests as extra untagged package versions.
PawFlow publishes these redistributable images:
ghcr.io/allcolor/pawflowghcr.io/allcolor/pawflow-relay-minimalghcr.io/allcolor/pawflow-relay-dev
The full relay image intentionally uses Playwright-managed Chromium instead of Google Chrome and does not install Microsoft Visual Studio Code desktop. code-server is used for browser-based editor support.
PawFlow does not publish pawflow-claude-code:latest. That image is built locally because it installs Claude Code and Antigravity binaries whose redistribution terms are not suitable for a public PawFlow image.
The public images may include software under, among others:
- MIT
- Apache-2.0
- BSD-style licenses
- Python Software Foundation License
- LGPL-family licenses for selected libraries
- GPL-family licenses for selected Ubuntu/Debian packages and command-line tools
- Ubuntu/Debian package copyright and trademark notices
The project source code is licensed separately under the repository license. Third-party packages retain their own licenses and notices.
tasks/io/chat_ui/vendor/livekit-client.umd.min.js— livekit-client 2.20.1, Apache-2.0. Served to browsers at/api/realtime/livekit/sdk.jsfor realtime LiveKit sessions. Update by downloading the pinned UMD build from npm/jsdelivr and recording the new version here.tasks/io/chat_ui/three.module.min.js— three.js r170 (npmthree@0.170.0), MIT. Served to browsers at/chat/js/three.module.min.jsand lazily imported by the webchat Openspace 3D view (openspace.js). Stored flat (not undervendor/) because the/chat/js/{path}route matches a single path segment. Update by downloading the pinned ESM build from jsdelivr and recording the new version here.
docker-buildx— Docker Buildx 0.36.1, Apache-2.0. The PawFlow server image copies the pinned, architecture-matched CLI plugin from the officialdocker/buildx-binimage so installer-driven local builds use BuildKit.search— paperfoot/search-cli 0.9.0, MIT. The PawFlow server image builds the Linux binary from pinned commit3ebd955e51035c53c7f8bf3c5b62be652ff441ffwith Cargo's locked dependency graph and without the unsupported Linux stealth feature.
pawflow_relay/physical-seccomp.jsonderives from the default profile in moby/profiles, pinned at61eaf32614c7c71b60bd8927d3e6a4ffc8ff1f31, Apache-2.0. PawFlow adds only apivot_rootallow rule conditional onCAP_SYS_ADMIN. The upstream license is included aspawflow_relay/physical-seccomp.LICENSE.
Before making a Docker release public:
- Confirm the workflow builds only the three public images listed above.
- Confirm no public image installs Google Chrome, Microsoft Visual Studio Code desktop, Claude Code, or Antigravity.
- Review image dependency changes for unexpected proprietary packages.
- Keep this notice and the repository license reachable from the package source URL.
- If a new binary installer or package repository is added, verify its redistribution terms before publishing the image.