Rename vendors to third parties

Renames the user-facing 'vendor' concept to 'third party' across the
entire codebase. The shared common_third_parties reference table is
unchanged.

Migration. Renames the vendor_category enum, the vendors and
vendor_<entity> tables (contacts, services, compliance_reports,
business_associate_agreements, data_privacy_agreements,
risk_assessments) and their vendor_id columns, the asset_vendors /
data_vendors / processing_activity_vendors junction tables,
generated_documents.vendors_document_id, the webhook_event_type
'vendor:<verb>' values, and the snapshots_type 'VENDORS' value.

Backend. Renames coredata models and SQL queries, probo services,
GraphQL / MCP API surface, console / trust / webhook resolvers and
types, the CLI (prb vendor* -> prb third-party*; pkg/cmd/vendormgmt
-> pkg/cmd/thirdpartymgmt), the document generator, vetting agent
prompts, and the common-third-parties-import command.

Frontend, packages, n8n, e2e. Renames apps/console pages, components,
hooks, routes, dialogs, and tabs; the shared @probo/vendors package
(now @probo/third-parties); the @probo/ui Vendors atoms (now
ThirdParties, VendorLogo -> ThirdPartyLogo); the n8n community node
actions/vendor folder (now actions/thirdParty); and the e2e Go test
suite (console and MCP). Filesystem and URL paths use kebab-case
(third-parties), GraphQL fields and TypeScript identifiers use
camelCase (thirdParty / thirdParties), Go types use PascalCase
(ThirdParty), and human-facing text uses 'third party' with a space.

Co-authored-by: Bryan Frimin <bryan@getprobo.com>
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
Sacha Al Himdani
2026-05-13 16:15:33 +02:00
parent 9eed0d71c8
commit eecbe4c46c
281 changed files with 8491 additions and 8425 deletions

View File

@@ -0,0 +1,24 @@
# Third parties
The [data.json](data.json) file and derived files contain data about various third parties and their security certifications. This data is licensed under the Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) license.
## License Requirements
When using this data, you must:
1. **Give appropriate credit** - Provide attribution to Probo Inc. and include a link to this license
2. **Indicate if changes were made** - If you modify the data, you must indicate that changes were made
3. **Share under the same license** - If you remix, transform, or build upon the material, you must distribute your contributions under the same license as the original
## Attribution Example
When using this data, please include the following attribution:
```
Data sourced from Probo Inc. (https://www.getprobo.com) under CC BY-SA 4.0 license
```
## More Information
For more information about the CC BY-SA 4.0 license, please visit:
https://creativecommons.org/licenses/by-sa/4.0/

View File

@@ -0,0 +1,37 @@
# ThirdParties library
A curated collection of software thirdParty information for use in thirdParty management and compliance activities.
## Overview
This package provides a structured dataset of software thirdParties and service providers with comprehensive metadata including:
- Basic thirdParty information (name, website, description)
- Legal documentation URLs (privacy policy, terms of service, etc.)
- Compliance certifications
- Security information
## Data Structure
Each thirdParty entry follows the structure defined in `data.d.ts`, including fields for:
- `name`: Display name of the thirdParty
- `legalName`: Legal business name
- `websiteUrl`: ThirdParty's website
- `privacyPolicyUrl`: URL to privacy policy
- `termsOfServiceUrl`: URL to terms of service
- And many more compliance-related URLs and metadata
See `data.d.ts` for the complete type definition.
### Building the Markdown Documentation
To generate the VENDORS.md documentation file from the data:
```bash
npm run build:md
```
## License
CC BY-SA 4.0 - See LICENSE.md for details.

File diff suppressed because it is too large Load Diff

115
packages/third-parties/data.d.ts vendored Normal file
View File

@@ -0,0 +1,115 @@
// Copyright (c) 2025-2026 Probo Inc <hello@getprobo.com>.
//
// Permission to use, copy, modify, and/or distribute this software for any
// purpose with or without fee is hereby granted, provided that the above
// copyright notice and this permission notice appear in all copies.
//
// THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH
// REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
// AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
// INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
// LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
// PERFORMANCE OF THIS SOFTWARE.
/**
* Type definitions for thirdParty data
*/
/**
* Category types for thirdParties
*/
export type ThirdPartyCategory =
| "ANALYTICS"
| "CLOUD_MONITORING"
| "CLOUD_PROVIDER"
| "COLLABORATION"
| "CUSTOMER_SUPPORT"
| "DATA_STORAGE_AND_PROCESSING"
| "DOCUMENT_MANAGEMENT"
| "EMPLOYEE_MANAGEMENT"
| "ENGINEERING"
| "FINANCE"
| "IDENTITY_PROVIDER"
| "IT"
| "MARKETING"
| "OFFICE_OPERATIONS"
| "OTHER"
| "PASSWORD_MANAGEMENT"
| "PRODUCT_AND_DESIGN"
| "PROFESSIONAL_SERVICES"
| "RECRUITING"
| "SALES"
| "SECURITY"
| "VERSION_CONTROL";
/**
* Represents a software thirdParty or service provider with associated metadata
*/
export interface ThirdParty {
/** Display name of the thirdParty */
name: string;
/** Legal business name of the thirdParty */
legalName?: string;
/** Physical headquarters address */
headquarterAddress?: string;
/** ThirdParty's website URL */
websiteUrl: string;
/** URL to thirdParty's privacy policy */
privacyPolicyUrl?: string;
/** URL to thirdParty's terms of service */
termsOfServiceUrl?: string;
/** URL to thirdParty's service level agreement */
serviceLevelAgreementUrl?: string;
/** URL to service software agreement */
serviceSoftwareAgreementUrl?: string;
/** URL to thirdParty's data processing agreement */
dataProcessingAgreementUrl?: string;
/** URL to thirdParty's list of subprocessors */
subprocessorsListUrl?: string;
/** URL to thirdParty's business associate agreement */
businessAssociateAgreementUrl?: string;
/** Short description of the thirdParty/service */
description?: string;
/** Primary category for the thirdParty */
category?: ThirdPartyCategory;
/** Security or compliance certifications held by the thirdParty */
certifications?: string[];
/** URL to thirdParty's security page */
securityPageUrl?: string;
/** URL to thirdParty's trust page */
trustPageUrl?: string;
/** URL to thirdParty's status page */
statusPageUrl?: string;
/** Countries where the thirdParty is located */
countries?: CountryCode[];
}
/**
* Array of thirdParty data
*/
export type ThirdParties = ThirdParty[];
/**
* Default export representing the entire thirdParty dataset
*/
declare const data: ThirdParties;
export default data;

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,21 @@
{
"name": "@probo/third-parties",
"version": "0.0.1",
"publishConfig": {
"access": "public"
},
"files": [
"data.json",
"LICENSE.md"
],
"scripts": {
"build:md": "node scripts/build-md.mjs"
},
"exports": {
".": {
"types": "./data.d.ts",
"default": "./data.json"
}
},
"license": "CC BY-SA 4.0"
}

View File

@@ -0,0 +1,143 @@
import { readFile } from "node:fs/promises";
import { createWriteStream } from "node:fs";
import path from "node:path";
const data = await readFile(path.join(import.meta.dirname, '../data.json'), 'utf8');
const thirdParties = JSON.parse(data);
const output = path.join(import.meta.dirname, '../VENDORS.md');
const file = createWriteStream(output);
const formatAsList = (array) => {
if (!array || array.length === 0) return '';
if (typeof array === 'string') {
return array.split(',').map(item => `- ${item.trim()}`).join('\n');
}
return array.map(item => `- ${item}`).join('\n');
};
file.write('# ThirdParties\n\n');
file.write('## Table of Contents by Category\n\n');
const categoriesMap = new Map();
for (const thirdParty of thirdParties) {
const category = (thirdParty.category || thirdParty.categories || 'Uncategorized');
if (!categoriesMap.has(category)) {
categoriesMap.set(category, []);
}
categoriesMap.get(category).push(thirdParty.name);
}
const sortedCategories = [...categoriesMap.keys()].sort();
for (const category of sortedCategories) {
file.write(`### ${category}\n\n`);
const thirdPartiesInCategory = categoriesMap.get(category).sort();
for (const thirdPartyName of thirdPartiesInCategory) {
// Create proper anchor by:
// 1. Converting to lowercase
// 2. Replacing spaces with hyphens
// 3. Removing parentheses, dots, and other special characters
const anchor = thirdPartyName.toLowerCase()
.replace(/\s+/g, '-')
.replace(/[\(\)\.]/g, '')
.replace(/[^a-z0-9\-]/g, '');
file.write(`- [${thirdPartyName}](#${anchor})\n`);
}
file.write('\n');
}
file.write('---\n\n');
for (const thirdParty of thirdParties) {
file.write(`## ${thirdParty.name}\n\n`);
if (thirdParty.description) {
file.write(`${thirdParty.description}\n\n`);
}
if (thirdParty.legalName) {
file.write(`**Legal Name:** ${thirdParty.legalName}\n\n`);
}
if (thirdParty.headquarterAddress) {
file.write(`**Headquarters:** ${thirdParty.headquarterAddress}\n\n`);
}
file.write('### Links\n\n');
file.write('| Resource | Link |\n');
file.write('|----------|------|\n');
if (thirdParty.websiteUrl) {
file.write(`| Website | [Link](${thirdParty.websiteUrl}) |\n`);
}
if (thirdParty.privacyPolicyUrl) {
file.write(`| Privacy Policy | [Link](${thirdParty.privacyPolicyUrl}) |\n`);
}
if (thirdParty.termsOfServiceUrl && thirdParty.termsOfServiceUrl !== 'undefined') {
file.write(`| Terms of Service | [Link](${thirdParty.termsOfServiceUrl}) |\n`);
}
if (thirdParty.serviceLevelAgreementUrl && thirdParty.serviceLevelAgreementUrl !== 'undefined') {
file.write(`| Service Level Agreement | [Link](${thirdParty.serviceLevelAgreementUrl}) |\n`);
}
if (thirdParty.securityPageUrl && thirdParty.securityPageUrl !== 'undefined') {
file.write(`| Security Page | [Link](${thirdParty.securityPageUrl}) |\n`);
}
if (thirdParty.trustPageUrl && thirdParty.trustPageUrl !== 'undefined') {
file.write(`| Trust Page | [Link](${thirdParty.trustPageUrl}) |\n`);
}
if (thirdParty.statusPageUrl && thirdParty.statusPageUrl !== 'undefined') {
file.write(`| Status Page | [Link](${thirdParty.statusPageUrl}) |\n`);
}
if (thirdParty.dataProcessingAgreementUrl && thirdParty.dataProcessingAgreementUrl !== 'undefined') {
file.write(`| Data Processing Agreement | [Link](${thirdParty.dataProcessingAgreementUrl}) |\n`);
}
if (thirdParty.businessAssociateAgreementUrl && thirdParty.businessAssociateAgreementUrl !== 'undefined') {
file.write(`| Business Associate Agreement | [Link](${thirdParty.businessAssociateAgreementUrl}) |\n`);
}
if (thirdParty.serviceSoftwareAgreementUrl && thirdParty.serviceSoftwareAgreementUrl !== 'undefined') {
file.write(`| Service Software Agreement | [Link](${thirdParty.serviceSoftwareAgreementUrl}) |\n`);
}
if (thirdParty.subprocessorsListUrl && thirdParty.subprocessorsListUrl !== 'undefined') {
file.write(`| Subprocessors List | [Link](${thirdParty.subprocessorsListUrl}) |\n`);
}
file.write('\n');
if (thirdParty.categories && thirdParty.categories !== 'undefined') {
file.write(`**Categories:** ${thirdParty.categories}\n\n`);
} else if (thirdParty.category && thirdParty.category !== 'undefined') {
file.write(`**Category:** ${thirdParty.category}\n\n`);
}
if (thirdParty.certifications && thirdParty.certifications !== 'undefined') {
file.write('### Certifications\n\n');
file.write(formatAsList(thirdParty.certifications));
file.write('\n\n');
}
if (thirdParty.subprocessors && thirdParty.subprocessors !== 'undefined') {
file.write('### Subprocessors\n\n');
file.write(formatAsList(thirdParty.subprocessors));
file.write('\n\n');
}
file.write('---\n\n');
}
file.end();