# What Are the Dependencies of the Pentagi Project? A Complete Stack Analysis

> Explore the Pentagi project dependencies. Discover its Go backend stack (Gin GORM OpenTelemetry) and React frontend stack (Apollo Client Radix UI XTerm.js) for a complete analysis.

- Repository: [VXControl/pentagi](https://github.com/vxcontrol/pentagi)
- Tags: how-to-guide
- Published: 2026-03-21

---

**Pentagi relies on a dual-stack dependency model: Go modules (including Gin, GORM, Docker SDK, OpenTelemetry, and multiple LLM adapters) for the backend, and npm packages (React, Apollo Client, Radix UI, and XTerm.js) for the React/TypeScript frontend.**

The `vxcontrol/pentagi` repository implements a full-stack AI-powered penetration testing platform, and understanding the dependencies of the Pentagi project is essential for developers contributing to or deploying the system. The codebase splits external libraries between a Go-based backend handling LLM integrations and containerized sandboxing, and a React/TypeScript frontend managing the terminal interface and GraphQL communications.

## Backend Dependencies: Go Modules

The Go backend defines its requirements in `backend/go.mod`, pulling modules that handle everything from HTTP routing to Docker container orchestration.

### Web Framework and HTTP Utilities

The server layer relies on **Gin** and its ecosystem for request handling. The `github.com/gin-gonic/gin` module provides the core HTTP router and middleware framework, while `github.com/gin-contrib/cors` handles cross-origin resource sharing, `github.com/gin-contrib/sessions` manages user session state, and `github.com/gin-contrib/static` serves built frontend assets. These are imported and configured in [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go) to initialize the web server.

### GraphQL Server Infrastructure

For API communications, Pentagi uses `github.com/99designs/gqlgen` as the GraphQL code generator and runtime server, paired with `github.com/vektah/gqlparser/v2` for schema parsing and validation. This combination enables type-safe GraphQL operations between the frontend and backend.

### Database and Vector Storage

Data persistence relies on PostgreSQL through several specialized drivers. The `github.com/jackc/pgx/v5` package provides the primary PostgreSQL driver, while `github.com/jinzhu/gorm` offers the ORM layer for model management. Vector embeddings are handled by `github.com/pgvector/pgvector-go`, and `github.com/lib/pq` serves as a fallback PostgreSQL driver for legacy compatibility.

### LLM Provider Integrations

The backend abstracts multiple AI providers through a unified adapter layer defined in [`backend/pkg/providers/provider.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/provider.go). Key dependencies include `github.com/aws/aws-sdk-go-v2` (specifically the `bedrockruntime` service), `github.com/ollama/ollama` for local model hosting, and custom VxControl libraries `github.com/vxcontrol/cloud` and `github.com/vxcontrol/langchaingo` that standardize interactions with OpenAI, Anthropic, Gemini, and other LLM services.

### Observability and Monitoring

Distributed tracing and metrics are implemented via the OpenTelemetry Go SDK. The `go.opentelemetry.io/otel/*` module family (including trace, metric, and log exporters) instruments the backend for performance monitoring and debugging across the containerized execution environment.

### Containerization and Sandboxing

Since Pentagi executes penetration testing tools in isolated environments, the backend imports `github.com/docker/docker` and `github.com/docker/go-connections`. These modules enable the Go application to create, start, and manage Docker containers programmatically, as implemented in the tools execution layer.

### Developer and Utility Libraries

Supporting functionality comes from specialized utility modules. The `github.com/charmbracelet/*` family (Bubbles, Bubbletea, Glamour, Lipgloss, Ultraviolet, and x/ansi) provides terminal UI components for any CLI interfaces. Logging uses `github.com/sirupsen/logrus`, while `github.com/creack/pty` handles pseudo-terminal allocation for interactive sessions. Additional utilities include `github.com/google/uuid` for identifier generation, `github.com/go-playground/validator/v10` for struct validation, `github.com/joho/godotenv` and `github.com/caarlos0/env/v10` for environment parsing, and `github.com/pressly/goose/v3` for database migrations.

## Frontend Dependencies: npm Packages

The React frontend declares its requirements in [`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json), organized between runtime dependencies shipped to the browser and development tools used for building and testing.

### Core React Framework and Routing

The UI foundation consists of `react` and `react-dom` for component rendering, with `react-router-dom` managing client-side navigation between the dashboard, terminal views, and reporting interfaces.

### GraphQL Client and State Management

Data fetching uses **Apollo Client** (`@apollo/client`) for GraphQL operations over HTTP, combined with `graphql-ws` for WebSocket-based subscriptions that stream real-time terminal output from the backend. The `graphql` package provides the core query language utilities. This configuration is centralized in [`frontend/src/lib/apollo.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/lib/apollo.ts).

### Form Handling and Validation

User input management relies on `react-hook-form` for performant form state, `@hookform/resolvers` for validation integration, and `zod` for TypeScript-first schema validation. This trio ensures type-safe form submissions throughout the application.

### UI Components and Terminal Emulator

The component library builds on **Radix UI** primitives (`@radix-ui/react-*`) for accessible dropdowns, dialogs, and tabs, styled with `tailwindcss` and accompanied by `lucide-react` icons. Special-purpose components include `sonner` for notifications, `react-diff-viewer-continued` for comparing outputs, `react-markdown` with `remark-gfm` and `rehype-raw` for rendering AI-generated reports, and `@react-pdf/renderer` for PDF export functionality.

The in-browser terminal implementation in [`frontend/src/components/term/Terminal.tsx`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/components/term/Terminal.tsx) depends on `@xterm/xterm` and its addon packages (`@xterm/addon-fit`, `@xterm/addon-web-links`) to emulate a full terminal environment for interacting with backend sandboxed tools.

### Utility and Styling Libraries

Supporting utilities include `axios` for HTTP requests, `clsx` for conditional CSS classes, `date-fns` for date formatting, `lru-cache` for client-side caching, and `marked` for markdown processing. The styling pipeline relies on `tailwindcss`, `postcss`, and `autoprefixer`.

### Development Tooling

The build system uses `vite` for fast development and production bundling, with `vitest` for unit testing. Code quality is enforced by `eslint` and `prettier`, while `@graphql-codegen/*` generates TypeScript types from the GraphQL schema. `typescript` provides the core type system.

## Key Dependency Files in the Repository

Understanding where these libraries are declared helps navigate the codebase:

- **`backend/go.mod`** – Lists all Go module requirements and their semantic versions.
- **`backend/go.sum`** – Contains cryptographic checksums ensuring reproducible Go builds.
- **[`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json)** – Declares npm dependencies and development scripts.
- **[`frontend/package-lock.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package-lock.json)** – Locks exact versions of the npm dependency tree.
- **[`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go)** – Entry point that wires together Gin, database drivers, and LLM providers.
- **[`frontend/src/lib/apollo.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/lib/apollo.ts)** – Configures the Apollo Client using the GraphQL dependencies.
- **[`backend/pkg/providers/provider.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/provider.go)** – Registers LLM provider adapters (OpenAI, Anthropic, Bedrock, Ollama).
- **[`frontend/src/components/term/Terminal.tsx`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/components/term/Terminal.tsx)** – Implements the terminal using `@xterm/xterm`.

## How Dependencies Are Used in the Code

### Initializing the Gin HTTP Server

The backend entry point in [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go) demonstrates how Gin and CORS middleware are instantiated:

```go
package main

import (
	"github.com/gin-gonic/gin"
	"github.com/gin-contrib/cors"
	"github.com/vxcontrol/pentagi/pkg/server"
)

func main() {
	r := gin.Default()
	r.Use(cors.Default())

	// Register routes from the internal server package
	server.RegisterRoutes(r)

	// Listen on the configured port
	_ = r.Run(":8080")
}

```

This snippet uses `github.com/gin-gonic/gin` and `github.com/gin-contrib/cors` declared in `backend/go.mod`.

### Configuring the Apollo GraphQL Client

The frontend establishes real-time communication with the backend using Apollo Client and WebSocket links, as defined in [`frontend/src/lib/apollo.ts`](https://github.com/vxcontrol/pentagi/blob/main/frontend/src/lib/apollo.ts):

```tsx
import { ApolloClient, InMemoryCache, split, HttpLink } from '@apollo/client';
import { GraphQLWsLink } from '@apollo/client/link/subscriptions';
import { createClient } from 'graphql-ws';

// HTTP link for queries & mutations
const httpLink = new HttpLink({ uri: '/api/graphql' });

// WebSocket link for subscriptions
const wsLink = new GraphQLWsLink(
  createClient({ url: `${window.location.protocol === 'https:' ? 'wss' : 'ws'}://localhost:8443/graphql` })
);

// Split traffic based on operation type
const link = split(
  ({ query }) => {
    const definition = getMainDefinition(query);
    return definition.kind === 'OperationDefinition' && definition.operation === 'subscription';
  },
  wsLink,
  httpLink
);

export const client = new ApolloClient({
  link,
  cache: new InMemoryCache(),
});

```

This configuration consumes `@apollo/client` and `graphql-ws` from [`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json).

### Executing Docker Containers

The backend sandboxing functionality uses the Docker SDK to run security tools in isolated containers:

```go
package tools

import (
	"context"
	"github.com/docker/docker/client"
	"github.com/docker/docker/api/types/container"
)

func RunNmap(ctx context.Context, target string) (string, error) {
	cli, _ := client.NewClientWithOpts(client.FromEnv)
	resp, err := cli.ContainerCreate(ctx,
		&container.Config{
			Image: "instrumentisto/nmap",
			Cmd:   []string{"-sV", target},
		},
		nil, nil, nil, "")
	if err != nil {
		return "", err
	}
	cli.ContainerStart(ctx, resp.ID, types.ContainerStartOptions{})
	// …collect logs, remove container, etc.
}

```

This implementation relies on `github.com/docker/docker` from `backend/go.mod`.

### Rendering Markdown Reports

The frontend renders AI-generated penetration testing reports using React Markdown:

```tsx
import React from 'react';
import ReactMarkdown from 'react-markdown';
import remarkGfm from 'remark-gfm';
import rehypeRaw from 'rehype-raw';

export const Report = ({ markdown }: { markdown: string }) => (
  <ReactMarkdown remarkPlugins={[remarkGfm]} rehypePlugins={[rehypeRaw]}>
    {markdown}
  </ReactMarkdown>
);

```

This component uses `react-markdown`, `remark-gfm`, and `rehype-raw` declared in [`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json).

## Summary

- **Pentagi uses a dual-stack architecture**: Go modules power the backend AI and sandboxing engine, while npm packages drive the React frontend terminal interface.
- **Key backend libraries include**: Gin for HTTP routing, GORM and pgx for PostgreSQL, Docker SDK for containerization, OpenTelemetry for observability, and multiple LLM adapters (AWS Bedrock, Ollama, LangChainGo).
- **Key frontend libraries include**: React with Apollo Client for GraphQL, Radix UI for components, XTerm.js for the terminal emulator, and React Markdown for report rendering.
- **Dependency declarations live in**: `backend/go.mod` and [`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json), with lockfiles ensuring reproducible builds across environments.

## Frequently Asked Questions

### Does Pentagi require Docker to be installed separately?

Yes. While the backend includes `github.com/docker/docker` to communicate with the Docker daemon programmatically, the Docker Engine must be installed and running on the host system. The Go client library depends on the Docker socket or environment variables to manage containers for sandboxed tool execution.

### Can I use a different database instead of PostgreSQL?

The current implementation in `backend/go.mod` specifically imports PostgreSQL drivers (`github.com/jackc/pgx/v5`, `github.com/lib/pq`, `github.com/pgvector/pgvector-go`) and GORM configurations optimized for PostgreSQL. Switching to another database would require replacing these dependencies and updating the connection logic in [`backend/cmd/pentagi/main.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/cmd/pentagi/main.go).

### Which LLM providers are supported out of the box?

According to the source code in [`backend/pkg/providers/provider.go`](https://github.com/vxcontrol/pentagi/blob/main/backend/pkg/providers/provider.go), the project supports OpenAI, Anthropic Claude, Google Gemini, AWS Bedrock, and local Ollama instances. These integrations rely on `github.com/aws/aws-sdk-go-v2`, `github.com/ollama/ollama`, and `github.com/vxcontrol/langchaingo` to standardize API interactions across different model providers.

### Are the frontend dependencies suitable for production deployment?

Yes. The [`frontend/package.json`](https://github.com/vxcontrol/pentagi/blob/main/frontend/package.json) separates `dependencies` (shipped to browsers, including React, Apollo Client, and XTerm.js) from `devDependencies` (build tools like Vite, TypeScript, and ESLint). The build process, configured in Vite, tree-shakes unused code and bundles only the required runtime libraries for the production bundle.