Hesperan

(Hesperan Bots)

Source code and licences

Hesperan Bots and the bot computer it downloads contain programs by other people, each under its own licence. This page lists them, says where their source code is, and contains our written offer to provide the source code that the GNU General Public License (GPL) and Lesser General Public License (LGPL) ask for.

The app

Hesperan Bots itself is licensed under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). Its source code is not public. The app includes these programs under their own licences:

ComponentVersionLicenceSource
Electron, with Chromium and Node.jsthe app'sMIT; Chromium and Node.js under their own licences, including third-party componentsgithub.com/electron/electron
noVNC, for the live view of the bots' computersthe app'sMPL-2.0github.com/novnc/noVNC
ONNX Runtime, to search memory by meaningthe app'sMITgithub.com/microsoft/onnxruntime
Tokenizers.js, to search memory by meaningthe app'sApache-2.0github.com/huggingface/tokenizers.js

What runs a bot's computer

These parts come with the app (in Hesperan Bots.app/Contents/Resources/hb-box, with their licences in LICENSES.md next to them) and start every bot's computer in a lightweight virtual machine.

ComponentVersionLicenceSource
Linux kernel6.18.5, as built by Kata Containers 3.26.0 (kernel configuration 177)GPL-2.0-only, with the Linux syscall notekernel.orgKata's configuration, patches and build script
vminitd and vmexec (Apple Containerization), the computer's first program0.48.0Apache-2.0; statically linked with the Swift runtime and Foundation (Apache-2.0 with the Runtime Library Exception) and musl libc (MIT)github.com/apple/containerization
hb-box, the helper that runs the computersthe app'sAGPL-3.0-only (Hesperan), statically linked with Apple's Containerization 0.48.0 and Swift packages (Apache-2.0) and zstd (BSD-3-Clause)github.com/apple/containerization

The kernel's complete corresponding source is the Linux 6.18.5 source together with the configuration fragments, patches and build script Kata Containers 3.26.0 used for this binary (kernel configuration 177, the -177 in its name). We keep copies of both here:

Copy on hesperan.comSizeSHA-256
kata-containers-3.26.0.tar.gz22 MBa327e61fd7df1be9ca28c84dfef36607cd91b5df1e1f07b405b5933d59093429
linux-6.18.5.tar.xz154 MB189d1f409cef8d0d234210e04595172df392f8cb297e14b447ed95720e2fd940

The bot computer

The bot computer's system is a separate download that the app fetches from hesperan.com when you turn on a bot's computer, and again when a newer version is published. It is Debian GNU/Linux 13 with a desktop, a browser and developer tools: a collection of independent programs, each under its own licence. Inside the computer, every Debian package's copyright and licence text is in /usr/share/doc/<package>/copyright.

Each version lists its exact package versions. Their source packages are in Debian's snapshot archive as it was on the date the version was built:

VersionStatusBuilt from Debian as ofPackage list
1.202610061742offered now1 October 2026packages-1.202610061742.txt
ComponentVersionLicenceSource
Debian GNU/Linux 13 “trixie” base (glibc, coreutils, bash, apt, dpkg, util-linux)Debian snapshotGPL-2.0+, GPL-3.0+, LGPL-2.1+ (glibc) and other free licencesDebian
ChromiumDebian packageBSD-3-Clause and the licences of its third-party componentsDebianchromium.org
TigerVNC (the virtual display and VNC server)Debian packageGPL-2.0+Debiantigervnc.org
XFCE (window manager, panel, desktop, settings, Thunar, terminal, Mousepad)Debian packagesGPL-2.0+, LGPL-2.0+ (libraries)Debian
X.Org libraries and utilities, MesaDebian packagesMIT/X11Debian
GTK 3, GLib, Pango, CairoDebian packagesLGPL-2.1+ (GTK, GLib, Pango), LGPL-2.1 or MPL-1.1 (Cairo)Debian
noVNC1.7.0MPL-2.0; some files BSD-2-Clause, MIT, OFL-1.1 and CC-BY-SA-3.0github.com/novnc/noVNC
websockify0.13.0LGPL-3.0github.com/novnc/websockify
Node.js, npm and corepack24 LTSMIT; bundled dependencies under their own licencesnodejs.org
Python 3, pip, venvDebian packagesPSF-2.0, MIT (pip)Debian
GCC, binutils, make (build-essential)Debian packagesGPL-3.0+ (GCC with the runtime library exception)Debian
git, curl, wget, OpenSSH client, sudo, socat, nftables, iproute2Debian packagesGPL-2.0 (git, socat, nftables, iproute2), GPL-3.0+ (wget), MIT-style (curl), BSD (OpenSSH), ISC-style (sudo)Debian
jq, ripgrep, zip, unzip, xz-utils, tini, xdotool, maim, xclipDebian packagesMIT, Unlicense, Info-ZIP, 0BSD, BSD-3-Clause, GPL-3.0+ (maim), GPL-2.0+ (xclip)Debian
Fonts: DejaVu, Liberation, Noto Color Emoji, Noto Sans CJK; Adwaita iconsDebian packagesBitstream Vera, OFL-1.1, LGPL-3.0 or CC-BY-SA-3.0 (icons)Debian

Hesperan's own files in the bot computer (its start scripts and settings) are licensed like the app (AGPL-3.0-only).

Written offer

For at least three years after we last distribute a version of Hesperan Bots or of the bot computer, Hesperan will give anyone who asks a complete machine-readable copy of the corresponding source code of every component in it that is licensed under the GNU GPL or LGPL, such as the Linux kernel and the Debian packages of the bot computer, under the terms of those licences. We charge no more than our cost of physically performing this distribution; a download link is free. This offer is open to anyone who has received this information.

To ask, write to Hesperan, Eduard Röhrig, c/o POSTFLEX PFX-581-999, Emsdettener Straße 10, 48268 Greven, Germany, or email hello@hesperan.com. Please name the version of Hesperan Bots you have (Settings → About) and, for the bot computer, its version or when you downloaded it.

Questions about this page: hello@hesperan.com. See also the imprint and Hesperan Bots.