Skip to the content.

Third-party provenance

The application code in cmd/ and internal/ is released into the public domain under the Unlicense. The exception is the explicitly vendored nlohmann/json header under internal/sdk/native, described below. Protocol conventions, endpoint names, and behavioral findings were researched against the sources in RESEARCH.md; they are not asserted to be newly invented algorithms.

Runtime-linked Go modules are pinned by go.mod / go.sum and copied by go mod vendor. Keep vendor/ license files with any source redistribution and include applicable notices with binary distributions. The Go standard library and toolchain retain their own licenses.

Module Pinned version Role License location
github.com/spf13/cobra v1.10.2 Commands, help, shell completion vendor/github.com/spf13/cobra/LICENSE.txt
github.com/spf13/pflag v1.0.9 Flag parsing (Cobra dependency) vendor/github.com/spf13/pflag/LICENSE
github.com/inconshreveable/mousetrap v1.1.0 Windows console behavior (Cobra dependency) vendor/github.com/inconshreveable/mousetrap/LICENSE
github.com/andygrunwald/vdf v1.1.0 Valve KeyValues/ACF parsing vendor/github.com/andygrunwald/vdf/LICENSE
github.com/rumblefrog/go-a2s v1.0.3 A2S server query protocol vendor/github.com/rumblefrog/go-a2s/LICENSE
github.com/jedib0t/go-pretty/v6 v6.8.3 Rendered tables and ANSI colour vendor/github.com/jedib0t/go-pretty/v6/LICENSE
github.com/mattn/go-runewidth v0.0.16 Display width for table layout (go-pretty dependency) vendor/github.com/mattn/go-runewidth/LICENSE
github.com/rivo/uniseg v0.4.7 Grapheme segmentation (go-runewidth dependency) vendor/github.com/rivo/uniseg/LICENSE.txt
golang.org/x/text v0.22.0 Text processing (go-pretty dependency) vendor/golang.org/x/text/LICENSE
github.com/gofrs/flock v0.13.1 Cross-process file locks vendor/github.com/gofrs/flock/LICENSE
golang.org/x/term v0.46.0 Terminal detection vendor/golang.org/x/term/LICENSE
golang.org/x/sys v0.48.0 OS calls for locks/terminals vendor/golang.org/x/sys/LICENSE
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e Terminal QR code generation vendor/github.com/skip2/go-qrcode/LICENSE
modernc.org/sqlite v1.59.0 Pure Go SQLite driver for Steam cookies vendor/modernc.org/sqlite/LICENSE
modernc.org/libc v1.75.7 C runtime translation library (modernc.org/sqlite dependency) vendor/modernc.org/libc/LICENSE
modernc.org/mathutil v1.7.1 Math utility library (modernc.org/sqlite dependency) vendor/modernc.org/mathutil/LICENSE
modernc.org/memory v1.12.1 Memory allocation library (modernc.org/sqlite dependency) vendor/modernc.org/memory/LICENSE
github.com/dustin/go-humanize v1.0.1 Formatting helpers (modernc.org/sqlite dependency) vendor/github.com/dustin/go-humanize/LICENSE
github.com/google/uuid v1.6.0 UUID generation (modernc.org/sqlite dependency) vendor/github.com/google/uuid/LICENSE
github.com/mattn/go-isatty v0.0.24 TTY detection (modernc.org/sqlite dependency) vendor/github.com/mattn/go-isatty/LICENSE
github.com/ncruces/go-strftime v1.0.0 strftime formatting (modernc.org/sqlite dependency) vendor/github.com/ncruces/go-strftime/LICENSE
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec FFT big integer arithmetic (modernc.org/sqlite dependency) vendor/github.com/remyoudompheng/bigfft/LICENSE

Embedded data

One third-party data file is compiled into the binary rather than merely vendored for the build:

File Origin License Role
internal/webapi/data/xpaw.json xPaw/SteamWebAPIDocumentation MIT, Copyright (c) 2019 Pavel Djundik; text in internal/webapi/data/LICENSE.xpaw Offline Steam Web API catalog backing web methods and verb/version discovery

It is embedded with go:embed, so every distributed artifact contains it and the MIT notice must accompany any redistribution. It is data, not source: no xPaw code is compiled in. --catalog live avoids it entirely and queries GetSupportedAPIList instead.

Reference-only repositories remain under ignored .references/, with exact revisions in references.json. Their complete licenses remain in those clones. They are not compiled into or bundled with the CLI. Reference libraries were assessed for suitability; no new API-client runtime dependency was added where the standard HTTP library already supplied the needed functionality.

SteamCMD is proprietary Valve software, fetched directly from Valve on demand. It is not redistributed as part of this source tree or the CLI artifacts. ASF is a separately operated service; its C# application is not embedded.

The Unlicense covers this project’s own code only. It does not and cannot relicense the vendored Go modules, the embedded xPaw catalog, Valve’s SteamCMD, or anything else listed above; those keep their own terms, and their notices must travel with any redistribution.

This project is not affiliated with, endorsed by, or sponsored by Valve Corporation. Steam, SteamCMD and the Steam logo are trademarks of Valve Corporation.

Native helper dependency

internal/sdk/native/json.hpp is the unmodified nlohmann/json v3.12.0 single header from nlohmann/json, MIT licensed; its notice is internal/sdk/native/LICENSE.json and is also included in DEPENDENCY_LICENSES.txt. SHA-256: aaf127c04cb31c406e5b04a63f1ae89369fccde6d8fa7cdda1ed4f32dfc5de63. It is embedded as build input in the Go binary and compiled only into a locally built native helper. Valve SDK headers, metadata and native libraries are supplied locally by the user and retain Valve’s terms; they are not redistributed here.