Skip to main content
This page is the compliance companion to Data Sources. Where that page explains what World Monitor covers and which providers power each domain, this one is the raw, machine-audited ledger: every upstream host observed in the source tree, what kind of surface it is (structured API, feed, or operational-status endpoint), the license posture we track for it, and the attribution it requires. The inventory is generated, not hand-written: scripts/source-attribution.mjs scans URL literals in scripts/, server/, api/, and src/, and joins them against the committed manifest (shared/source-attribution-manifest.json). A host that appears in code but not in the manifest fails CI, so this disclosure cannot silently drift from what the code actually fetches. Status meanings:

Observed Upstream Inventory

This generated inventory covers 531 active upstream hosts (291 structured/API, 268 feed, and 30 operational-status hosts). It is derived from URL literals in scripts/, server/, api/, and src/; the manifest records a license posture and the credit required for every observed host. 517 entries remain marked terms-review and should be confirmed before a redistribution or commercial-use claim.