THIRD-PARTY NOTICES for foam-otel

This package REDISTRIBUTES NO THIRD-PARTY CODE. It is a plain Python package of
Foam's own source; its dependencies are installed by the customer's package
manager (pip / uv / poetry), and each dependency arrives from PyPI carrying its
own LICENSE file in the customer's environment. This file is the static
attribution list for those direct runtime dependencies (BASE_PACKAGE_SPEC
rule 35: attribution matches what the artifact actually redistributes — and none
is redistributed here, so there is no full-text reproduction and no generator).

Foam thanks the OpenTelemetry authors and community
(https://opentelemetry.io) — this package is built on their work. All
OpenTelemetry Python packages are licensed under Apache-2.0.

Direct runtime dependencies (name [declared floor; resolves to] — license — source):

  opentelemetry-api [>=1.44; 1.44.0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python (https://pypi.org/project/opentelemetry-api/)
  opentelemetry-sdk [>=1.44; 1.44.0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python (https://pypi.org/project/opentelemetry-sdk/)
  opentelemetry-exporter-otlp-proto-http [>=1.44; 1.44.0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python (https://pypi.org/project/opentelemetry-exporter-otlp-proto-http/)
  opentelemetry-instrumentation [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation/)
  wrapt [>=1.0; 2.2.2] — BSD-2-Clause — https://github.com/GrahamDumpleton/wrapt (https://pypi.org/project/wrapt/)

The bundled universal floor (2026-07-26 coverage ruling; direct runtime dependencies too):

  opentelemetry-instrumentation-fastapi [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-fastapi/)
  opentelemetry-instrumentation-django [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-django/)
  opentelemetry-instrumentation-flask [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-flask/)
  opentelemetry-instrumentation-requests [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-requests/)
  opentelemetry-instrumentation-urllib3 [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-urllib3/)
  opentelemetry-instrumentation-httpx [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-httpx/)
  opentelemetry-instrumentation-psycopg [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-psycopg/)
  opentelemetry-instrumentation-asyncpg [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-asyncpg/)
  opentelemetry-instrumentation-mysql [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-mysql/)
  opentelemetry-instrumentation-pymysql [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-pymysql/)
  opentelemetry-instrumentation-redis [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-redis/)
  opentelemetry-instrumentation-pymongo [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-pymongo/)
  opentelemetry-instrumentation-celery [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-celery/)
  opentelemetry-instrumentation-system-metrics [>=0.65b0; 0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-system-metrics/)
  opentelemetry-instrumentation-openai-v2 [>=2.0b0; 2.0b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (https://pypi.org/project/opentelemetry-instrumentation-openai-v2/)
  opentelemetry-instrumentation-anthropic [>=0.62.1; 0.62.1] — Apache-2.0 — https://github.com/traceloop/openllmetry (https://pypi.org/project/opentelemetry-instrumentation-anthropic/)
  opentelemetry-instrumentation-google-genai [>=1.0b1; 1.0b1] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-genai (https://pypi.org/project/opentelemetry-instrumentation-google-genai/)

Optional dependencies (compatibility extras — each a subset of the bundled floor above, same licenses/sources):

  opentelemetry-instrumentation-fastapi   [>=0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (extra: foam-otel[fastapi])
  opentelemetry-instrumentation-httpx     [>=0.65b0] — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (extra: foam-otel[httpx])
  opentelemetry-instrumentation-openai-v2 [>=2.0b0]  — Apache-2.0 — https://github.com/open-telemetry/opentelemetry-python-contrib (extra: foam-otel[llm])

These direct dependencies pull further packages transitively
(opentelemetry-semantic-conventions, opentelemetry-proto,
opentelemetry-exporter-otlp-proto-common, opentelemetry-util-http, the
-asgi/-wsgi/-dbapi instrumentation bases, and the OTLP/instrumentation support
packages — all Apache-2.0, from the same OpenTelemetry repositories above;
plus asgiref (BSD-3-Clause, Django project), psutil (BSD-3-Clause,
https://github.com/giampaolo/psutil, via -system-metrics),
opentelemetry-semantic-conventions-ai (Apache-2.0, Traceloop, via the
Anthropic instrumentor) and opentelemetry-util-genai (Apache-2.0, from the
same opentelemetry-python-genai repository, via the google-genai
instrumentor). None is redistributed by foam; each is
installed by the customer's package manager under its own license.

Value-pattern secret ruleset attribution (2026-07-27 value-pattern secret
layer, design docs/decisions/security-fixes-design.md). foam REDISTRIBUTES NO
CODE from these projects. The frozen credential-shape patterns in
src/foam_otel/_constants.py (SECRET_VALUE_RULES / the H1/H2 heuristics /
placeholders / stopwords / key-context allowlist) are DERIVED from the
permissively-licensed detector rulesets below — regex facts about public token
formats are not copyrightable, and the patterns are re-authored ReDoS-bounded,
but attribution is recorded per the design's vendoring obligations (§V.1). The
AGPL-3.0 trufflehog project was used ONLY as a provider-coverage checklist; NO
pattern is transcribed from its source.

  gitleaks         — MIT       — https://github.com/gitleaks/gitleaks (commit b58d3f1)
  detect-secrets   — Apache-2.0 (+ NOTICE) — https://github.com/Yelp/detect-secrets (commit 5e14193)
  secretlint       — MIT       — https://github.com/secretlint/secretlint (commit 7da613e)
