libyears

Terms of service

Draft, not yet reviewed by a lawyer. This document describes what the product actually does and is accurate on the facts, but it has not been checked for enforceability or for whether it covers what it needs to. Do not rely on it, and do not treat it as a contract offer.

Written to be read. Where a term is unusual or in our favour, it says so rather than being buried in a clause designed not to be noticed.

What Libyears does

Libyears reads the dependency manifests and lockfiles in repositories you connect, compares what you have installed against what has been published, and reports how far behind you are and what is known to be dangerous.

It is read-only. It never writes to your repositories, never opens a pull request, and never changes your code. That is a deliberate limit on the product, not an omission.

What it is not

It is not a security audit, a penetration test, or a compliance certification, and it does not find vulnerabilities in your own code. It reports what public advisory databases say about third-party packages you depend on.

A clean report means no public advisory matched the versions you have installed. It does not mean your dependencies are safe, and it never will: a vulnerability nobody has published cannot be reported by anyone. Decisions about upgrading, and their consequences, remain yours.

Effort estimates are bands derived from how far behind a package is and how widely it is used. They do not account for what changed between two releases. They are an input to a quote, not a quote.

Your account

You need an account and a connected repository host. You are responsible for who you invite and what they can see: a viewer seat is safe to hand to a client because a viewer can read everything and change nothing, but an admin can change thresholds and remove repositories.

One free organisation per person. Creating several free organisations to avoid the repository limit is the one form of abuse worth naming, and we will consolidate them rather than terminate an account over it.

Paying

Plans and prices are on the settings screen. Payment is handled by Lemon Squeezy as merchant of record: they are the seller, they collect the money, and they issue the invoice. Card details never reach this application, which is why there is no payment form in it.

Subscriptions renew until cancelled. Cancelling stops the next charge and drops you to the free plan at the end of the period you have paid for. We do not prorate refunds for a period already begun, but if you cancel because the product did not work, write to us and we will refund it.

Over your plan’s repository limit, scanning pauses. Nothing is deleted. Every repository, every past scan and every report stays exactly as it was; the numbers simply stop updating, and the interface says so. Raising the plan brings them straight back. That is a commitment, not a current behaviour: downgrading has to be safe or trying a paid plan is not.

Your data

Your repository data is yours. We process it to provide the service and for nothing else: not to train models, not to sell, not to compile into a dataset about you. Aggregate statistics we publish — median libyears across public repositories, for instance — are derived from public repositories only and never identify a customer.

You can export any repository as CSV or CycloneDX at any time, and delete your organisation yourself without contacting us. The privacy policy says what we hold and for how long.

Availability

There is no uptime commitment on the free, Pro, Team or Agency plans, and we would rather say that than offer one we have not measured. Enterprise agreements can include one.

Scans depend on GitHub, the npm registry and public advisory databases. When one of them is unavailable the affected data goes stale rather than disappearing, and the interface says which repository stopped updating and why.

When it goes wrong

The service is provided as-is. We do not warrant that it is error-free or that it will identify every outdated or vulnerable dependency.

Our total liability is limited to what you paid us in the twelve months before the claim. For a free account that is nothing, which is the honest consequence of a free account. Nothing here limits liability for fraud, or for anything that cannot be limited by law.

We are not liable for a security incident in your dependencies. We report what the public record says; acting on it is yours.

Ending it

Cancel any time from settings. Delete your organisation any time from settings. Neither requires talking to us, and there is no retention offer in the way.

We may suspend an account for non-payment after notice, or for use that endangers the service or other customers. If we discontinue the product we will give at least 90 days’ notice and keep exports working throughout.

The rest

These terms are governed by the laws of India, where the company is registered. The MIT components — the parsers, metrics, registry client and CLI — are licensed under MIT and nothing here restricts that.

Questions: hello@libyears.com.