Skip to content

Storage

Kubo (IPFS)

An IPFS implementation. The licence is dual, with a carve-out for older contributions.

Amber — conditions, and a legal review before you copy it in

SPDX or status
MIT OR Apache-2.0, with a pre-2019 caveat
Confidence
medium
Maintainer
IPFS / Protocol Labs ecosystem
Runtime
Content-addressed storage
Repository
ipfs/kubo

GitHub returned NOASSERTION. The LICENSE file read on 2026-10-01 says the project is moving from MIT-only to dual MIT/Apache-2.0, and that code contributed before 2019-05-06 may be MIT-only unless the contributor signed off. Blockchain Lab has not audited this repository. A licence check is not a vulnerability scan, a dependency review, or a security audit.

Read the LICENSE before copying a file. Public IPFS is not access control.

Reuse status

Research available. Review required.

Copyleft, mixed terms, a dated dual licence, or a repository whose maintainer record is not settled. Legal review would be required before any copy. The scan gates are also unmet.

Source class
S3 conditional
Commit
Not pinned
Source-derived demo
Held

Available

  • E0: Metadata
  • E1: Research report
  • E2: Citation bundle
  • E3: Pattern blueprint
  • E4: Test plan
  • E5: Original scaffold

Not available

  • E6: Source-derived demo pack — held
  • E7: Full source bundle — held
  • E8: Dataset export — held
  • E9: Model-training pack — held
  • E10: Production candidate pack — held

Kubo (IPFS) is conditional. Copyleft, mixed terms, or a maintainer caveat still needs a legal reading, and the scan gates are unmet. Non-commercial or demo use does not remove the licence duty. When in doubt, link — do not copy.

View the repository/Export policy

Use

  • Content addressing of files you have the right to distribute

Do not use for

  • A privacy vault
  • Assuming every historical line is Apache-licensed

Risks

  • Public content addressing publishes the bytes to anyone who has the identifier.
  • Personal data does not belong there.

Reviews required

  • Data-protection review before any personal or customer file is addressed

No source code is reproduced on this page. No commit SHA is published, because this release did not pin one.