Third-party provenance
The application code in cmd/ and internal/ is released into the public domain under the Unlicense. The exception is the explicitly vendored nlohmann/json header under internal/sdk/native, described below. Protocol conventions, endpoint names, and behavioral findings were researched against the sources in RESEARCH.md; they are not asserted to be newly invented algorithms.
Runtime-linked Go modules are pinned by go.mod / go.sum and copied by go mod vendor. Keep vendor/ license files with any source redistribution and include applicable notices with binary distributions. The Go standard library and toolchain retain their own licenses.
| Module | Pinned version | Role | License location |
|---|---|---|---|
| github.com/spf13/cobra | v1.10.2 | Commands, help, shell completion | vendor/github.com/spf13/cobra/LICENSE.txt |
| github.com/spf13/pflag | v1.0.9 | Flag parsing (Cobra dependency) | vendor/github.com/spf13/pflag/LICENSE |
| github.com/inconshreveable/mousetrap | v1.1.0 | Windows console behavior (Cobra dependency) | vendor/github.com/inconshreveable/mousetrap/LICENSE |
| github.com/andygrunwald/vdf | v1.1.0 | Valve KeyValues/ACF parsing | vendor/github.com/andygrunwald/vdf/LICENSE |
| github.com/rumblefrog/go-a2s | v1.0.3 | A2S server query protocol | vendor/github.com/rumblefrog/go-a2s/LICENSE |
| github.com/jedib0t/go-pretty/v6 | v6.8.3 | Rendered tables and ANSI colour | vendor/github.com/jedib0t/go-pretty/v6/LICENSE |
| github.com/mattn/go-runewidth | v0.0.16 | Display width for table layout (go-pretty dependency) | vendor/github.com/mattn/go-runewidth/LICENSE |
| github.com/rivo/uniseg | v0.4.7 | Grapheme segmentation (go-runewidth dependency) | vendor/github.com/rivo/uniseg/LICENSE.txt |
| golang.org/x/text | v0.22.0 | Text processing (go-pretty dependency) | vendor/golang.org/x/text/LICENSE |
| github.com/gofrs/flock | v0.13.1 | Cross-process file locks | vendor/github.com/gofrs/flock/LICENSE |
| golang.org/x/term | v0.46.0 | Terminal detection | vendor/golang.org/x/term/LICENSE |
| golang.org/x/sys | v0.48.0 | OS calls for locks/terminals | vendor/golang.org/x/sys/LICENSE |
| github.com/skip2/go-qrcode | v0.0.0-20200617195104-da1b6568686e | Terminal QR code generation | vendor/github.com/skip2/go-qrcode/LICENSE |
| modernc.org/sqlite | v1.59.0 | Pure Go SQLite driver for Steam cookies | vendor/modernc.org/sqlite/LICENSE |
| modernc.org/libc | v1.75.7 | C runtime translation library (modernc.org/sqlite dependency) | vendor/modernc.org/libc/LICENSE |
| modernc.org/mathutil | v1.7.1 | Math utility library (modernc.org/sqlite dependency) | vendor/modernc.org/mathutil/LICENSE |
| modernc.org/memory | v1.12.1 | Memory allocation library (modernc.org/sqlite dependency) | vendor/modernc.org/memory/LICENSE |
| github.com/dustin/go-humanize | v1.0.1 | Formatting helpers (modernc.org/sqlite dependency) | vendor/github.com/dustin/go-humanize/LICENSE |
| github.com/google/uuid | v1.6.0 | UUID generation (modernc.org/sqlite dependency) | vendor/github.com/google/uuid/LICENSE |
| github.com/mattn/go-isatty | v0.0.24 | TTY detection (modernc.org/sqlite dependency) | vendor/github.com/mattn/go-isatty/LICENSE |
| github.com/ncruces/go-strftime | v1.0.0 | strftime formatting (modernc.org/sqlite dependency) | vendor/github.com/ncruces/go-strftime/LICENSE |
| github.com/remyoudompheng/bigfft | v0.0.0-20230129092748-24d4a6f8daec | FFT big integer arithmetic (modernc.org/sqlite dependency) | vendor/github.com/remyoudompheng/bigfft/LICENSE |
Embedded data
One third-party data file is compiled into the binary rather than merely vendored for the build:
| File | Origin | License | Role |
|---|---|---|---|
internal/webapi/data/xpaw.json |
xPaw/SteamWebAPIDocumentation | MIT, Copyright (c) 2019 Pavel Djundik; text in internal/webapi/data/LICENSE.xpaw |
Offline Steam Web API catalog backing web methods and verb/version discovery |
It is embedded with go:embed, so every distributed artifact contains it and the MIT notice must accompany any redistribution. It is data, not source: no xPaw code is compiled in. --catalog live avoids it entirely and queries GetSupportedAPIList instead.
Reference-only repositories remain under ignored .references/, with exact revisions in references.json. Their complete licenses remain in those clones. They are not compiled into or bundled with the CLI. Reference libraries were assessed for suitability; no new API-client runtime dependency was added where the standard HTTP library already supplied the needed functionality.
SteamCMD is proprietary Valve software, fetched directly from Valve on demand. It is not redistributed as part of this source tree or the CLI artifacts. ASF is a separately operated service; its C# application is not embedded.
The Unlicense covers this project’s own code only. It does not and cannot relicense the vendored Go modules, the embedded xPaw catalog, Valve’s SteamCMD, or anything else listed above; those keep their own terms, and their notices must travel with any redistribution.
This project is not affiliated with, endorsed by, or sponsored by Valve Corporation. Steam, SteamCMD and the Steam logo are trademarks of Valve Corporation.
Native helper dependency
internal/sdk/native/json.hpp is the unmodified nlohmann/json v3.12.0 single
header from nlohmann/json, MIT
licensed; its notice is internal/sdk/native/LICENSE.json and is also included in
DEPENDENCY_LICENSES.txt. SHA-256:
aaf127c04cb31c406e5b04a63f1ae89369fccde6d8fa7cdda1ed4f32dfc5de63.
It is embedded as build input in the Go binary and compiled only into a locally
built native helper. Valve SDK headers, metadata and native libraries are supplied
locally by the user and retain Valve’s terms; they are not redistributed here.