Dependencies for Codebase-Memory-MCP: A Complete Guide to Zero-Runtime-Dependency Architecture

Codebase-Memory-MCP is a zero-dependency static executable that bundles every third-party library—including SQLite, Tree-sitter, and the Nomic embedding model—at build time, requiring only the system C library at runtime.

The DeusData/codebase-memory-mcp project delivers a self-contained MCP server for codebase intelligence. Unlike traditional tools that rely on dynamic linking or package managers, this binary embeds all dependencies directly into the executable, ensuring consistent behavior across Linux, macOS, and Windows without runtime installation requirements.

Core Dependency Philosophy

The project follows a zero-runtime-dependency model. Every third-party component is vendored into the repository and statically linked during the build process. This eliminates "dependency hell" and ensures the binary runs on any target system that provides a standard C library.

Vendored vs. Dynamic Linking

While most MCP servers require Node.js, Python, or shared libraries, Codebase-Memory-MCP compiles everything—including tree-sitter, SQLite3, and compression algorithms—into a single static binary. The only external dependency at execution time is the C standard library (glibc on Linux, libSystem on macOS, or the Windows CRT).

Complete Inventory of Vendored Libraries

The repository maintains all dependencies in dedicated vendored/ directories. According to the source code in THIRD_PARTY.md, the binary incorporates the following components:

Database and Memory Management

  • SQLite 3 – Embedded full-text search and graph storage. Located at vendored/sqlite3/, public domain.
  • mimalloc – High-performance memory allocator. Located at vendored/mimalloc/, MIT license.

Data Processing and Hashing

  • yyjson – High-performance JSON parser. Located at vendored/yyjson/, MIT license.
  • xxHash – Fast hashing algorithm for indexing. Located at vendored/xxhash/, BSD‑2‑Clause.
  • wyhash – Hash function for hash tables. Located at internal/cbm/vendored/wyhash/, Unlicense (public domain).
  • Verstable – Stable hashing implementation. Located at internal/cbm/vendored/verstable/, MIT license.

Parsing and Language Support

  • Tree-sitter runtime – Core AST parsing engine. Located at internal/cbm/vendored/ts_runtime/, MIT license.
  • Tree-sitter grammars – 158 pre-generated language parsers (e.g., tree-sitter-python, tree-sitter-cpp). Located at internal/cbm/vendored/grammars/<lang>/, mostly MIT.
  • simplecpp – C/C++ preprocessor. Located at internal/cbm/vendored/simplecpp/, 0BSD license.

Compression Algorithms

  • LZ4 – Fast compression for the indexing pipeline. Located at internal/cbm/vendored/lz4/, BSD‑2‑Clause.
  • Zstandard – Persistent compression for the graph database (graph.db.zst). Located at internal/cbm/vendored/zstd/, BSD‑3‑Clause.
  • TRE – POSIX-compatible regex engine. Located at vendored/tre/, BSD‑2‑Clause.
  • nomic-embed-code – Static embedding model for semantic search. Located at vendored/nomic/, Apache 2.0.

Optional Frontend Dependencies

When built with --with-ui, the project includes a React-based visualization layer. These dependencies are not required for core MCP server functionality.

Graph UI Stack

The optional UI components reside in graph-ui/package.json and include:

  1. React – UI framework
  2. three.js – 3D graph visualization
  3. @react-three/fiber – React renderer for three.js
  4. radix-ui – Headless UI components
  5. lucide-react – Icon library
  6. tailwindcss – Styling framework

All UI dependencies are permissively licensed (MIT/ISC/Apache-2.0/Zlib) and documented in the generated THIRD_PARTY_NOTICES.md file.

How Dependencies Power the Architecture

The vendored libraries integrate into a five-stage pipeline:

1. Parsing and AST Extraction The tree-sitter runtime (internal/cbm/vendored/ts_runtime/) processes source files using the 158 vendored grammars to generate language-specific syntax trees.

2. Hybrid LSP Type Resolution After parsing, the Hybrid LSP layer (pure C) traverses ASTs to resolve imports, generics, and inheritance. It uses SQLite as a fast lookup table for symbol resolution.

3. Indexing Pipeline Files are optionally compressed with LZ4 before storage in an in-memory SQLite database. The final database is compressed with Zstandard for persistence, producing graph.db.zst.

4. Search and Retrieval SQLite FTS5 (full-text search) works with custom tokenizers like cbm_camel_split to enable fast BM25 searches. Semantic search leverages the bundled nomic-embed-code vectors for similarity queries.

5. Memory and Performance mimalloc handles memory allocation, while xxHash and wyhash provide fast hashing for symbol tables and cache lookups.

Verifying Embedded Dependencies

You can inspect the bundled dependencies directly through the CLI, demonstrating that the binary carries all required components internally.

List Vendored Components


# Display the embedded license file containing all third-party notices

codebase-memory-mcp cli get_code_snippet '{"qualified_name":"THIRD_PARTY_NOTICES"}'

Query the Internal SQLite Schema


# Verify SQLite is embedded by querying the graph schema

codebase-memory-mcp cli get_graph_schema '{"project":"my_repo"}' | jq .

# Test the bundled nomic-embed-code model

codebase-memory-mcp cli semantic_query '{"query":"user authentication flow"}' | jq .

These commands confirm that the binary operates without external database clients, embedding models, or JSON parsers.

Key Files for Dependency Tracking

  • THIRD_PARTY.md – Complete catalog of all vendored libraries and their licenses.
  • vendored/sqlite3/ – SQLite amalgamation source.
  • internal/cbm/vendored/ – Tree-sitter runtime, grammars, and compression libraries.
  • graph-ui/package.json – NPM dependencies for the optional UI.
  • scripts/gen-ui-licenses.py – Generates UI license attribution files.

Summary

  • Codebase-Memory-MCP is a fully static binary with zero runtime dependencies beyond the host C library.
  • All third-party code—including SQLite, Tree-sitter, LZ4, Zstandard, and nomic-embed-code—is vendored in vendored/ and internal/cbm/vendored/ directories.
  • The optional UI (React/three.js) in graph-ui/ is the only component with Node.js dependencies, and it is not required for MCP server operation.
  • Complete license information is available in THIRD_PARTY.md and embedded within the binary as THIRD_PARTY_NOTICES.

Frequently Asked Questions

Does Codebase-Memory-MCP require any external databases?

No. The binary embeds SQLite 3 directly from vendored/sqlite3/ and uses it for all graph storage and full-text search. You do not need to install SQLite separately or maintain a database server.

The project uses nomic-embed-code, an Apache 2.0-licensed model for code embeddings. The model weights and token vectors are bundled in vendored/nomic/ and compiled into the binary, so no external ML runtime like PyTorch or TensorFlow is required.

Are the UI dependencies required for the MCP server to function?

No. The React, three.js, and other frontend dependencies listed in graph-ui/package.json are optional. They are only included when building with --with-ui for the graph visualization interface. The core MCP server functionality works without any Node.js or browser components.

Where can I find the complete license information for vendored libraries?

All third-party licenses are documented in THIRD_PARTY.md at the repository root. Additionally, the binary embeds a THIRD_PARTY_NOTICES file that you can extract using the CLI command codebase-memory-mcp cli get_code_snippet '{"qualified_name":"THIRD_PARTY_NOTICES"}'.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →