This document outlines the dependency management policy for the visualization.matrix addon. It defines guidelines for:
- Approved dependencies
- Dependency updates
- Security requirements
- License compatibility
- Vulnerability management
| Dependency | Version | Purpose | License | Status |
|---|---|---|---|---|
| kissfft | Latest | Fast Fourier Transform | BSD-3-Clause | ✅ Approved |
| Kodi Addon Framework | Matrix/Nexus | Kodi addon infrastructure | GPL-2.0-or-later | ✅ Required |
| OpenGL/ES | System | Graphics rendering | Vendor-specific | ✅ System |
| GLM | Latest | OpenGL Mathematics | MIT | ✅ Approved |
-
Bundled Dependencies (included in
/lib/)- Must be header-only or statically linked
- Must have compatible licenses (see License Compatibility)
- Must be minimal and well-maintained
-
System Dependencies (linked at runtime)
- Must be widely available on target platforms (Linux, Windows, macOS, Android, iOS)
- Must have stable APIs
- Must be version-checked at runtime
-
Build Dependencies (used during compilation)
- Must be documented in
README.mdorCONTRIBUTING.md - Must be pinned to specific versions in CI/CD workflows
- Must be documented in
-
Automated Updates (Dependabot)
- Dependabot automatically opens PRs for dependency updates
- PRs are reviewed and tested before merging
- Security updates are prioritized (see Vulnerability Management)
-
Manual Updates
- Check for updates monthly
- Test updates in a separate branch before merging
- Document breaking changes in
CHANGELOG.md(if applicable)
-
Version Pinning
- Use specific versions (not
latestor*) - Pin versions in:
CMakeLists.txt(for bundled dependencies)- CI/CD workflows (for build dependencies)
- Documentation (for system dependencies)
- Use specific versions (not
| Criteria | Action |
|---|---|
| Security vulnerability | Update immediately (within 48 hours) |
| Critical bug fix | Update within 1 week |
| Minor bug fix | Update within 1 month |
| New feature | Evaluate for compatibility and need |
| Breaking change | Requires major version bump of the addon |
-
Scanning
- All dependencies are automatically scanned with:
- Trivy (on every push/PR)
- Dependabot (weekly)
- GitHub Security Advisories (continuous)
- All dependencies are automatically scanned with:
-
Response to Vulnerabilities
- Critical/High vulnerabilities: Must be fixed within 48 hours
- Medium vulnerabilities: Must be fixed within 1 week
- Low vulnerabilities: Must be fixed within 1 month
- If a fix is not available, apply mitigations (e.g., disable vulnerable features)
-
Vulnerability Disclosure
- Follow the responsible disclosure process in SECURITY.md
- Do not publicly disclose vulnerabilities before a fix is available
Before adding a new dependency, verify:
- The dependency is actively maintained (recent commits, releases)
- The dependency has no known vulnerabilities (check Snyk, OSV)
- The dependency has a clear security policy
- The dependency uses secure coding practices
The visualization.matrix addon is licensed under GPL-2.0-or-later. Compatible licenses for dependencies include:
| License | Compatibility | Notes |
|---|---|---|
| BSD-2-Clause | ✅ Compatible | Permissive, no restrictions |
| BSD-3-Clause | ✅ Compatible | Permissive, no restrictions |
| MIT | ✅ Compatible | Permissive, no restrictions |
| Apache-2.0 | ✅ Compatible | Permissive, patent grant |
| LGPL-2.1 | ✅ Compatible | Can be dynamically linked |
| LGPL-3.0 | ✅ Compatible | Can be dynamically linked |
| GPL-2.0 | ✅ Compatible | Must be statically linked or bundled |
| GPL-3.0 | Requires addon to be GPL-3.0 | |
| AGPL-3.0 | ❌ Incompatible | Requires network use restrictions |
| Proprietary | ❌ Incompatible | Closed-source licenses |
-
Check License Compatibility
- Use SPDX License List for reference
- Consult GPL Compatibility Matrix
-
Document License
- Add the dependency's license to
LICENSE-THIRD-PARTY.md(if applicable) - Include a copy of the license in
/lib/<dependency>/LICENSE
- Add the dependency's license to
-
Legal Review (if unsure)
- Contact the Kodi legal team or project maintainers for clarification
-
Evaluate Need
- Is the dependency necessary?
- Can the functionality be implemented internally?
- Is there an existing approved dependency that can be used?
-
Check Compatibility
- License: Must be compatible with GPL-2.0-or-later
- Platform: Must support all target platforms (Linux, Windows, macOS, Android, iOS)
- Architecture: Must support all target architectures (x86, x86_64, ARM, ARM64)
-
Security Review
- Check for known vulnerabilities
- Review the dependency's security practices
- Ensure the dependency is actively maintained
-
Technical Review
- Test the dependency in a separate branch
- Verify build compatibility with all target platforms
- Check for performance impact
-
Documentation
- Update
README.mdorCONTRIBUTING.mdwith:- Purpose of the dependency
- Version requirements
- Build instructions (if applicable)
- Update
DEPENDENCY_POLICY.mdwith the new dependency
- Update
-
Submit for Review
- Open a Pull Request with the dependency addition
- Include justification for the dependency
- Tag @MarcelRaschke for review
-
Evaluate Impact
- Is the dependency still needed?
- Can the functionality be replaced with another dependency or internal code?
-
Check for Dependencies
- Are there other dependencies that rely on this one?
- Are there features that will break without it?
-
Update Code
- Remove all references to the dependency
- Replace functionality with alternatives (if applicable)
-
Test
- Verify the addon builds and runs without the dependency
- Test on all target platforms
-
Documentation
- Update
README.md,CONTRIBUTING.md, andDEPENDENCY_POLICY.md - Remove the dependency from CI/CD workflows (if applicable)
- Update
-
Submit for Review
- Open a Pull Request with the dependency removal
- Include justification for the removal
- Tag @MarcelRaschke for review
| Metric | Value |
|---|---|
| Total Dependencies | 4 |
| Bundled Dependencies | 1 (kissfft) |
| System Dependencies | 2 (OpenGL/ES, Kodi Framework) |
| Build Dependencies | 1 (CMake) |
| Vulnerable Dependencies | 0 |
| Outdated Dependencies | 0 |
- kissfft: ✅ Healthy (actively maintained, no vulnerabilities)
- Kodi Framework: ✅ Healthy (actively maintained by Kodi team)
- OpenGL/ES: ✅ Healthy (vendor-maintained)
Dependabot is configured to:
- Check for updates weekly
- Open PRs for version updates
- Prioritize security updates
- Label PRs with
dependenciesandsecurity(if applicable)
Trivy is configured to:
- Scan for vulnerabilities on every push/PR
- Report findings in SARIF format to GitHub Security tab
- Fail builds if critical vulnerabilities are found
| Task | Frequency | Responsible |
|---|---|---|
| Dependency updates | Monthly | Maintainers |
| Vulnerability scanning | Continuous | Automated (Trivy, Dependabot) |
| Dependency review | Quarterly | Maintainers |
| License compliance check | Annually | Maintainers |
For questions about dependencies, contact:
- Maintainer: @MarcelRaschke
- Email:
security@marcelraschke.de - Kodi Forum: Kodi Addon Development
| Date | Change | Author |
|---|---|---|
| 2025-07-15 | Initial dependency policy created | Vibe Code |