# Third-party notices AZET Shield is assembled from open-source parts. Our own code is the installer, the reporter, the control plane (Cloudflare Workers + D1), the dashboard and the scan-runner glue. Detection, blocking and scanning are done by the parts below, used unmodified. Licenses were re-read from each project's repository on 2026-10-05. ## Installed on the customer's server by `install.sh` (downloaded from the vendor's own package repository) | Part | Version seen in the e2e run | License | How it is used | |---|---|---|---| | [CrowdSec Security Engine](https://github.com/crowdsecurity/crowdsec) | 1.8.1 | MIT | Unmodified Debian package from CrowdSec's repository. Reads logs, detects attacks, decides bans. | | [cs-firewall-bouncer](https://github.com/crowdsecurity/cs-firewall-bouncer) (`crowdsec-firewall-bouncer-nftables`) | 0.0.36 | MIT | Unmodified package. Applies CrowdSec's decisions to nftables. | | [CrowdSec hub](https://github.com/crowdsecurity/hub) collections `crowdsecurity/linux`, `sshd`, `nginx`, `wordpress` | hub head | MIT | Detection rules, installed with `cscli collections install`. | | jq, curl (Debian/Ubuntu packages) | distro | MIT, curl license | Called as separate programs by the reporter script. | We do not redistribute these; the installer asks the server's package manager to fetch them. The installer answers "no" to the CrowdSec package's Central API question (debconf `crowdsec/capi`), so the engine is not registered with CrowdSec's Central API (CAPI): it sends no signals to CrowdSec and does not pull CrowdSec's community blocklist. The server owner can opt in with `SHIELD_CROWDSEC_SHARE=1` at install time or `cscli capi register` later; a CrowdSec that was already installed is left as configured. AZET Shield neither collects nor redistributes CrowdSec's blocklist. The reporter forwards only alerts whose decisions originate from the local engine. ## Inside the scan runner image (`runner/Dockerfile`) | Part | Version | License | How it is used | |---|---|---|---| | [subfinder](https://github.com/projectdiscovery/subfinder) | 2.16.0 | MIT | Release binary, run as a subprocess. Passive subdomain discovery. | | [httpx](https://github.com/projectdiscovery/httpx) | 1.12.0 | MIT | Release binary, subprocess. Web service probe. | | [naabu](https://github.com/projectdiscovery/naabu) | 2.6.1 | MIT | Release binary, subprocess. TCP connect scan of the top 100 ports. | | [nuclei](https://github.com/projectdiscovery/nuclei) | 3.11.1 | MIT | Release binary, subprocess. Template-based checks. | | [nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) | v10.4.9 | MIT | Rule data for nuclei. | | [dnstwist](https://github.com/elceef/dnstwist) | 20250130 | Apache-2.0 | PyPI package, run as a subprocess. Lookalike-domain discovery. | | [dnspython](https://github.com/rthalley/dnspython) | 2.8.0 | ISC | Dependency used by dnstwist for DNS lookups. | | Debian bookworm base image, OpenSSL, libpcap, Python 3, jq, curl, git, unzip | distro | various (Debian main) | Operating-system packages, separate programs. | Not used, on purpose: Nmap (NPSL), WPScan (WPScan Public Source License), any AGPL/SSPL/BUSL tool. ## In the dashboard | Part | License | How it is used | |---|---|---| | [Lucide](https://github.com/lucide-icons/lucide) icons | ISC | A few icon paths inlined as SVG in `web/public/app.js`. | ## Related AZET service AZET Gate (form bot check, linked from the dashboard) derives from [LocalCan/invisible-captcha](https://github.com/LocalCan/invisible-captcha) (MIT); see the notice in the azet-gate repository. --- Fonts in the dashboard (web/public/fonts/, unmodified latin subsets from Fontsource 5.3.0): Instrument Sans, Copyright 2022 The Instrument Sans Project Authors (https://github.com/Instrument/instrument-sans); Space Mono, Copyright 2016 The Space Mono Project Authors (https://github.com/googlefonts/spacemono). Both under the SIL Open Font License 1.1; the full text is next to the files (OFL-instrument-sans.txt, OFL-space-mono.txt). --- MIT License (CrowdSec, cs-firewall-bouncer, CrowdSec hub, ProjectDiscovery tools and templates): Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. Copyright notices: Copyright (c) Crowdsec; Copyright (c) ProjectDiscovery, Inc.; dnstwist Copyright (c) Marcin Ulikowski (Apache License 2.0, https://www.apache.org/licenses/LICENSE-2.0); Lucide Copyright (c) Lucide Icons and Contributors (ISC). The full license text of each part ships inside its own package or repository.