// LEGAL_03 · OSS_LICENSES · SINGLE_PLATFORM · ToS §2

Open Source Licenses

オープンソースソフトウェア 帰属・ライセンス

Last updated | 最終更新日:

// Scope · 対象範囲: This attribution page covers ALL bundled open-source libraries shipped as part of the QKay SaaS platform 「全3コンポーネント共通」: the three platform components defined in Terms §2 (Component Scope) and Privacy Policy §2. A single, centralized attribution index applies uniformly across qkay.jp, kanri.qkay.jp, and the your-store.**qkay.jp tenant-storefront cluster.本帰属ページは、the QKay SaaS platform 「全3コンポーネント共通」 に同梱・配送される全ての OSS ライブラリを対象とします。プラットフォームを構成する 3 つのコンポーネント(利用規約第2条・プライバシーポリシー第2条の「コンポーネント構成」表参照)を横断して、本書面が唯一かつ統一的な帰属インデックスとして適用されます。

// Anti-reconnaissance notice · リコン防止告知 (Terms §6)

Public-registry package identifiers 「npm, pnpm」 and exact version numbers are intentionally NOT published on this page, in accordance with Terms of Service §6 (Prohibited Acts) (automated vulnerability mapping, reconnaissance scanning, and CPE-driven CVE reconnaissance are prohibited acts).

利用規約第6条(禁止行為)(自動脆弱性スキャン、偵察行為、CPE 文字列を使用した CVE リコン等は禁止)に基づき、npm 等の公開レジストリ上のパッケージ識別子およびバージョン番号は、意図的に本ページに記載しておりません。

Complete, per-package SPDX attribution including exact revision identifiers may be obtained in writing on a need-to-know basis by mailing support@qkay.jp for bona-fide open-source license compliance audits only.

正確なリビジョン識別子を含む完全なパッケージ別 SPDX 帰属情報は、誠実な OSS ライセンスコンプライアンス監査目的に限定し、必要な範囲で書面にて support@qkay.jp までお問い合わせください。

Tier 1 · User-visible / DOM-fingerprintable componentsTier 1 · 利用者視認可能 / DOM フィンガープリント可能コンポーネント

The components below may be identified through ordinary browser DevTools or SSR response headers. Naming them explicitly here provides no additional reconnaissance information to an attacker.以下のコンポーネントは、一般的なブラウザ DevTools や SSR レスポンスヘッダで判別可能なため、ここに明示的に記載することで追加の偵察情報を提供するものではありません。

Astro SSR framework + adapters + sitemap plugin

Tier 1 · SPDX: MIT

Astro SSR フレームワーク + 各種アダプタ・サイトマッププラグイン

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © The Astro Core Contributors and respective adapter/plugin maintainers.

Upstream | 上流リポジトリ:https://github.com/withastro/astro

Tailwind CSS styling system + Vite integration plugin

Tier 1 · SPDX: MIT

Tailwind CSS スタイルシステム + Vite 統合プラグイン

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © Tailwind Labs, Inc.

Upstream | 上流リポジトリ:https://github.com/tailwindlabs/tailwindcss

TypeScript compiled output (server + client)

Tier 1 · SPDX: Apache-2.0

TypeScript コンパイル成果物(サーバー・クライアント共通)

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © Microsoft Corporation.

Upstream | 上流リポジトリ:https://github.com/microsoft/TypeScript

Applies to all compiled TypeScript artifacts shipped to the browser or server runtime across the three platform components.プラットフォーム 3 コンポーネントを横断してブラウザおよびサーバーランタイムに配送される、コンパイル済みの全成果物に適用されます。

Zod schema validation (Astro content collections + runtime guards)

Tier 1 · SPDX: MIT

Zod スキーマ・バリデーション(Astro コンテンツコレクション + ランタイムガード)

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © Zod Contributors.

Upstream | 上流リポジトリ:https://github.com/colinhacks/zod

Used for Astro content-collection schema validation and server runtime guardrails.Astro コンテンツコレクションのスキーマ検証、およびサーバーランタイムのガード処理として使用されます。

Clerk authentication UI widgets + platform SDK (client + server)

Tier 1 · SPDX: MIT

Clerk 認証 UI ウィジェット + プラットフォーム SDK(クライアント・サーバー)

Present in · 導入箇所: qkay.jp · kanri.qkay.jp

Copyright © Clerk, Inc.

Upstream | 上流リポジトリ:https://github.com/clerk/javascript

Client-side widgets render on login flows for the Management Dashboard; server-side SDK is used for authentication across the platform.クライアントサイドのウィジェットは管理画面ログインフローで描画されます。サーバーサイド SDK はプラットフォーム全体の認証処理で使用されます。

Fuse.js client-side fuzzy search

Tier 1 · SPDX: Apache-2.0

Fuse.js クライアントサイドあいまい検索

Present in · 導入箇所: tenant storefronts

Copyright © Fuse.js Contributors.

Upstream | 上流リポジトリ:https://github.com/krisk/Fuse

Runs on the browser for storefront catalog search.テナントストアフロントのカタログ検索を目的として、ブラウザ上で実行されます。

Tier 2 · Server-side internal libraries 「OPSEC-classified」Tier 2 · サーバーサイド内部ライブラリ(OPSEC 管理対象)

Components in this tier are required to be disclosed for copyright attribution because their code is bundled and distributed by the platform runtime. However, they are never delivered to the browser runtime. Public-registry identifiers and exact version numbers are intentionally withheld to protect platform integrity. Legal minimum attribution 「copyright holder + SPDX identifier + functional description」 is satisfied by each entry below.本段のコンポーネントは、コードがプラットフォームランタイムに同梱・配送されるため、著作権上の帰属開示が必要となりますが、ブラウザランタイムに配送されることは一切ありません。プラットフォーム保全のため公開レジストリ識別子・バージョンは非公開とし、著作権者・SPDX 識別子・機能記載からなる法定最低限の帰属を各記載で充足します。

Registration onboarding payment SDK 「server-side · qkay.jp only」

Tier 2 · SPDX: MIT

新規登録決済向け SDK(サーバーサイド・qkay.jp 限定)

Present in · 導入箇所: qkay.jp

Copyright © the payment processor SDK contributors.

Server-side library used exclusively for the one-time new-merchant registration checkout on qkay.jp. Production tenant storefront payment processing uses a separate platform-side payment SDK listed below.qkay.jp 上の新規テナント登録時ワンタイム決済処理専用のサーバーサイドライブラリ。本番テナントストアフロントの決済基盤は下段に記載の別 SDK を使用します。

Tenant-storefront payment-gateway SDK 「server-side · tenant storefronts only」

Tier 2 · SPDX: MIT

テナントストアフロント向け決済ゲートウェイ SDK(サーバーサイド・ストアフロント限定)

Present in · 導入箇所: tenant storefronts

Copyright © the tenant payment-gateway SDK contributors.

Server-side Node SDK used for tenant-storefront capture, refund and order state workflows.テナントストアフロントにおける売上確定・返金・注文ステータス連携等のためのサーバーサイド Node SDK。

Headless CMS content SDK 「server-side · tenant storefronts only」

Tier 2 · SPDX: MIT

ヘッドレス CMS コンテンツ SDK(サーバーサイド・ストアフロント限定)

Present in · 導入箇所: tenant storefronts

Copyright © the CMS platform SDK contributors.

Typed server SDK used to pull tenant content and catalog data from the headless CMS platform.ヘッドレス CMS 基盤からテナントコンテンツ・カタログデータを取得するための型付きサーバー SDK。

Managed relational database client drivers 「server-side」

Tier 2 · SPDX: MIT

管理対象リレーショナル DB クライアントドライバ(サーバーサイド)

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © the respective managed-RDBMS driver maintainers and the database community contributors.

Server-side driver set used across the platform for tenant-row-scoped database operations. Exact registry package identifiers and version numbers are intentionally not published here per Terms §6.プラットフォーム全体でテナント行単位の DB 操作に使用されるサーバーサイドのドライバセット。利用規約第6条に基づき、公開レジストリ上のパッケージ識別子・バージョン番号は意図的に非公開とします。

Password & secret hashing libraries 「server-side · qkay.jp only」

Tier 2 · SPDX: MIT

パスワード・機密情報ハッシュ化ライブラリ(サーバーサイド・qkay.jp 限定)

Present in · 導入箇所: qkay.jp

Copyright © the respective hashing-algorithm contributors.

Performs credential stretching on the marketing-site registration flow. Library details are not published to reduce automated hashcat/cracking reconnaissance surface.マーケティングサイト登録フローのクレデンシャルストレッチング用途。自動 hashcat 等によるハッシュ解析リコンを軽減するため、ライブラリ詳細は非公開。

Transactional email delivery transport libraries 「server-side」

Tier 2 · SPDX: MIT

トランザクションメール配送トランスポートライブラリ(サーバーサイド)

Present in · 導入箇所: qkay.jp · tenant storefronts

Copyright © the respective email transport / SMTP library contributors.

Internal SMTP pipeline. Used for onboarding welcome flows and storefront transactional notifications.内部 SMTP パイプライン専用。新規登録ウェルカムメールおよびストアフロントの決済通知等に使用されます。

Hosting runtime adapters 「deployment」

Tier 2 · SPDX: MIT

ホスティング・ランタイムアダプタ(デプロイメント)

Present in · 導入箇所: qkay.jp · kanri.qkay.jp · tenant storefronts

Copyright © the hosting vendor adapter maintainers.

SSR deployment binding used across the platform. Hosting provider identifier is not published to reduce automated hosting-takeover reconnaissance surface.プラットフォーム全体の SSR デプロイ結合コンポーネント。ホスティング事業者を標的とした自動アカウント乗っ取りリコンを軽減するため、事業者識別名は非公開。