# Dependencies for Codebase-Memory-MCP: A Complete Guide to Zero-Runtime-Dependency Architecture

> Explore the zero-runtime-dependency architecture of Codebase-Memory-MCP. Discover how it bundles all libraries like SQLite and Tree-sitter at build time for a lean, efficient runtime.

- Repository: [Martin Vogel/codebase-memory-mcp](https://github.com/DeusData/codebase-memory-mcp)
- Tags: how-to-guide
- Published: 2026-07-04

---

**Codebase-Memory-MCP is a zero-dependency static executable that bundles every third-party library—including SQLite, Tree-sitter, and the Nomic embedding model—at build time, requiring only the system C library at runtime.**

The DeusData/codebase-memory-mcp project delivers a self-contained MCP server for codebase intelligence. Unlike traditional tools that rely on dynamic linking or package managers, this binary embeds all dependencies directly into the executable, ensuring consistent behavior across Linux, macOS, and Windows without runtime installation requirements.

## Core Dependency Philosophy

The project follows a **zero-runtime-dependency** model. Every third-party component is vendored into the repository and statically linked during the build process. This eliminates "dependency hell" and ensures the binary runs on any target system that provides a standard C library.

### Vendored vs. Dynamic Linking

While most MCP servers require Node.js, Python, or shared libraries, Codebase-Memory-MCP compiles everything—including `tree-sitter`, `SQLite3`, and compression algorithms—into a single static binary. The only external dependency at execution time is the **C standard library** (glibc on Linux, libSystem on macOS, or the Windows CRT).

## Complete Inventory of Vendored Libraries

The repository maintains all dependencies in dedicated `vendored/` directories. According to the source code in [`THIRD_PARTY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/THIRD_PARTY.md), the binary incorporates the following components:

### Database and Memory Management

- **SQLite 3** – Embedded full-text search and graph storage. Located at `vendored/sqlite3/`, public domain.
- **mimalloc** – High-performance memory allocator. Located at `vendored/mimalloc/`, MIT license.

### Data Processing and Hashing

- **yyjson** – High-performance JSON parser. Located at `vendored/yyjson/`, MIT license.
- **xxHash** – Fast hashing algorithm for indexing. Located at `vendored/xxhash/`, BSD‑2‑Clause.
- **wyhash** – Hash function for hash tables. Located at `internal/cbm/vendored/wyhash/`, Unlicense (public domain).
- **Verstable** – Stable hashing implementation. Located at `internal/cbm/vendored/verstable/`, MIT license.

### Parsing and Language Support

- **Tree-sitter runtime** – Core AST parsing engine. Located at `internal/cbm/vendored/ts_runtime/`, MIT license.
- **Tree-sitter grammars** – 158 pre-generated language parsers (e.g., `tree-sitter-python`, `tree-sitter-cpp`). Located at `internal/cbm/vendored/grammars/<lang>/`, mostly MIT.
- **simplecpp** – C/C++ preprocessor. Located at `internal/cbm/vendored/simplecpp/`, 0BSD license.

### Compression Algorithms

- **LZ4** – Fast compression for the indexing pipeline. Located at `internal/cbm/vendored/lz4/`, BSD‑2‑Clause.
- **Zstandard** – Persistent compression for the graph database (`graph.db.zst`). Located at `internal/cbm/vendored/zstd/`, BSD‑3‑Clause.

### Text Processing and Search

- **TRE** – POSIX-compatible regex engine. Located at `vendored/tre/`, BSD‑2‑Clause.
- **nomic-embed-code** – Static embedding model for semantic search. Located at `vendored/nomic/`, Apache 2.0.

## Optional Frontend Dependencies

When built with `--with-ui`, the project includes a React-based visualization layer. These dependencies are **not required** for core MCP server functionality.

### Graph UI Stack

The optional UI components reside in [`graph-ui/package.json`](https://github.com/DeusData/codebase-memory-mcp/blob/main/graph-ui/package.json) and include:

1. **React** – UI framework
2. **three.js** – 3D graph visualization
3. **@react-three/fiber** – React renderer for three.js
4. **radix-ui** – Headless UI components
5. **lucide-react** – Icon library
6. **tailwindcss** – Styling framework

All UI dependencies are permissively licensed (MIT/ISC/Apache-2.0/Zlib) and documented in the generated [`THIRD_PARTY_NOTICES.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/THIRD_PARTY_NOTICES.md) file.

## How Dependencies Power the Architecture

The vendored libraries integrate into a five-stage pipeline:

**1. Parsing and AST Extraction**
The `tree-sitter` runtime (`internal/cbm/vendored/ts_runtime/`) processes source files using the 158 vendored grammars to generate language-specific syntax trees.

**2. Hybrid LSP Type Resolution**
After parsing, the Hybrid LSP layer (pure C) traverses ASTs to resolve imports, generics, and inheritance. It uses **SQLite** as a fast lookup table for symbol resolution.

**3. Indexing Pipeline**
Files are optionally compressed with **LZ4** before storage in an in-memory SQLite database. The final database is compressed with **Zstandard** for persistence, producing `graph.db.zst`.

**4. Search and Retrieval**
SQLite FTS5 (full-text search) works with custom tokenizers like `cbm_camel_split` to enable fast BM25 searches. **Semantic search** leverages the bundled `nomic-embed-code` vectors for similarity queries.

**5. Memory and Performance**
**mimalloc** handles memory allocation, while **xxHash** and **wyhash** provide fast hashing for symbol tables and cache lookups.

## Verifying Embedded Dependencies

You can inspect the bundled dependencies directly through the CLI, demonstrating that the binary carries all required components internally.

### List Vendored Components

```bash

# Display the embedded license file containing all third-party notices

codebase-memory-mcp cli get_code_snippet '{"qualified_name":"THIRD_PARTY_NOTICES"}'

```

### Query the Internal SQLite Schema

```bash

# Verify SQLite is embedded by querying the graph schema

codebase-memory-mcp cli get_graph_schema '{"project":"my_repo"}' | jq .

```

### Perform Semantic Search

```bash

# Test the bundled nomic-embed-code model

codebase-memory-mcp cli semantic_query '{"query":"user authentication flow"}' | jq .

```

These commands confirm that the binary operates without external database clients, embedding models, or JSON parsers.

## Key Files for Dependency Tracking

- [`THIRD_PARTY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/THIRD_PARTY.md) – Complete catalog of all vendored libraries and their licenses.
- `vendored/sqlite3/` – SQLite amalgamation source.
- `internal/cbm/vendored/` – Tree-sitter runtime, grammars, and compression libraries.
- [`graph-ui/package.json`](https://github.com/DeusData/codebase-memory-mcp/blob/main/graph-ui/package.json) – NPM dependencies for the optional UI.
- [`scripts/gen-ui-licenses.py`](https://github.com/DeusData/codebase-memory-mcp/blob/main/scripts/gen-ui-licenses.py) – Generates UI license attribution files.

## Summary

- **Codebase-Memory-MCP** is a fully static binary with zero runtime dependencies beyond the host C library.
- All third-party code—including **SQLite**, **Tree-sitter**, **LZ4**, **Zstandard**, and **nomic-embed-code**—is vendored in `vendored/` and `internal/cbm/vendored/` directories.
- The **optional UI** (React/three.js) in `graph-ui/` is the only component with Node.js dependencies, and it is not required for MCP server operation.
- Complete license information is available in [`THIRD_PARTY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/THIRD_PARTY.md) and embedded within the binary as `THIRD_PARTY_NOTICES`.

## Frequently Asked Questions

### Does Codebase-Memory-MCP require any external databases?

No. The binary embeds **SQLite 3** directly from `vendored/sqlite3/` and uses it for all graph storage and full-text search. You do not need to install SQLite separately or maintain a database server.

### What embedding model does Codebase-Memory-MCP use for semantic search?

The project uses **nomic-embed-code**, an Apache 2.0-licensed model for code embeddings. The model weights and token vectors are bundled in `vendored/nomic/` and compiled into the binary, so no external ML runtime like PyTorch or TensorFlow is required.

### Are the UI dependencies required for the MCP server to function?

No. The React, three.js, and other frontend dependencies listed in [`graph-ui/package.json`](https://github.com/DeusData/codebase-memory-mcp/blob/main/graph-ui/package.json) are **optional**. They are only included when building with `--with-ui` for the graph visualization interface. The core MCP server functionality works without any Node.js or browser components.

### Where can I find the complete license information for vendored libraries?

All third-party licenses are documented in [`THIRD_PARTY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/THIRD_PARTY.md) at the repository root. Additionally, the binary embeds a `THIRD_PARTY_NOTICES` file that you can extract using the CLI command `codebase-memory-mcp cli get_code_snippet '{"qualified_name":"THIRD_PARTY_NOTICES"}'`.