# bkywksj/knowledge-base ships a dual-licence Tauri notes app whose manifest outruns its newest tag

> A local-first desktop knowledge base built on Tauri 2.x, React 19 and SQLite, with FTS5 search, a knowledge graph and WebDAV or S3 sync. The 222-word README is mostly a licence notice, and the file that would tell you how to install it, INSTALL.md, is never linked.

**bkywksj/knowledge-base** — 本地优先的知识库桌面应用。Markdown 编辑器 + 全文搜索（FTS5） + 双向链接 / 知识图谱；多端同步（WebDAV / S3 / 同步盘，单笔记粒度增量 + 自动双向调度，含整库 ZIP 备份）；AI 问答与智能规划（OpenAI 兼容 / Ollama / 自定义 provider，工具调用框架）；支持导入 .md / .txt / .pdf / .docx（自动嗅探编码）；笔记加密 Vault + 隐藏笔记 PIN；自定义数据目录；跨平台 Win/macOS/Linux + 应用内自动更新。Tauri 2.x + React 19 + Rust + SQLite，零云端依赖。

- Repository: https://github.com/bkywksj/knowledge-base
- Website: https://kb.ruoyi.plus
- Stars: 328 · Forks: 62
- Language: TypeScript
- License: NOASSERTION
- Published: 2026-09-15 · Updated: 2026-09-15 · Language: en
- Canonical page: https://hysenlabs.com/projects/bkywksj-knowledge-base

## The README is a licence notice, not a product document

Every heading in the README falls into one of seven buckets: development, build, licence, commercial licensing enquiry, contributing, community and donations. None of them describe what the program does. There is no feature list, no screenshot, no configuration reference and no changelog pointer anywhere in the file, and at 222 words it is too short to hold one. The product story lives in the repository description instead, where the feature set is unusually specific: a Markdown editor over FTS5 full-text search, bidirectional links feeding a knowledge graph, multi-device sync over WebDAV, S3 or a synchronised folder with per-note incremental transfers scheduled in both directions plus a whole-library ZIP backup, AI question answering and planning against OpenAI-compatible endpoints, Ollama or a custom provider through a tool-calling framework, import of .md, .txt, .pdf and .docx with automatic encoding sniffing, an encrypted note vault plus a PIN for hidden notes, a configurable data directory, and in-app automatic update on Windows, macOS and Linux. The single pointer back to prose documentation is one table row calling kb.ruoyi.plus the application documentation site. So the order a reader meets is licensing posture and support channels first, product second.

## package.json declares 1.64.0 and the newest tag is v1.62.0

The declared version and the published tags have drifted apart. package.json names the package knowledge_base, sets private to true, records the licence as AGPL-3.0-or-later and pins version 1.64.0. The three most recent releases are mobile-v0.2.0 on 2026-09-16, v1.62.0 on 2026-09-01 and v1.52.0 on 2026-08-05. The newest desktop tag is therefore two patch generations behind the manifest, and neither v1.63.0 nor v1.64.0 appears in the release list at all. A second numbering line runs beside it: the mobile client ships as mobile-v0.2.0 from the same repository, two weeks after the desktop tag and on a 0.x scheme while the desktop line sits on 1.x. Because installers are keyed to tags, anyone taking a released desktop build gets 1.62.0 behaviour while the source tree already reads 1.64.0. The default branch is master rather than main, and its last push is dated 2026-10-01, four days after v1.62.0 shipped, which puts the gap days old rather than months old.

## Three rows of the licence table need payment and three do not

The licence section is the longest part of the README and it runs on a dual model: GNU AGPL-3.0 as the default, a commercial licence sold alongside it. A six-row table splits usage in half. Free, on condition of AGPL-3.0 compliance: personal study, research and non-commercial use; second development of open source projects, where derived work must also be published under AGPL-3.0; and internal enterprise tools that are not distributed. Paid: closed-source commercial use and packaging for sale; SaaS or network service deployment where source is not published to users; and integration into proprietary software that is then redistributed, which the table marks as a violation of AGPL-3.0 copyleft. The README compresses this to one line, that using it yourself or in open source is free while closed-source sales and non-published SaaS mean buying a licence from the author. Contact runs through QQ or WeChat 770492966, and the detailed terms sit in COMMERCIAL-LICENSE.md rather than in LICENSE. package.json records only AGPL-3.0-or-later and says nothing about the commercial path, while the repository licence field resolves to NOASSERTION instead of a single SPDX identifier, so tooling that reads metadata sees only the free half of a two-part scheme.

## The only runnable block in the README is a developer workflow

```bash
pnpm install
pnpm tauri dev
```

That block, followed by a second one ending in pnpm tauri build, assumes you already hold a clone. There is no install command for the packaged application anywhere in the file and no download link. An INSTALL.md sits at the repository root next to LICENSE, CONTRIBUTING.md and COMMERCIAL-LICENSE.md, and no line in the README points at it, so the file a newcomer would look for exists but is unlinked. package.json fills in what the file leaves out. dev runs vite alone; dev:clean runs kill-port 1421 && vite; build runs tsc && vite build; preview serves the built output. Port 1421 is hard-coded into dev:clean, so the escape hatch for a wedged development server is a fixed number rather than whatever vite chose. The tauri passthrough is also spelled three ways: tauri forwards straight through, while tauri:dev and tauri:build wrap the same two subcommands. The documented form is the passthrough one, so neither named alias appears anywhere. Tests run through vitest run with test:watch for the loop, and vitest.config.ts at the root holds that configuration.

## build:mcp compiles an artifact the README never mentions

build:mcp runs node scripts/build-mcp.mjs and build:mcp:debug runs the same script with --debug. Those are the only two entries in package.json that point inside scripts/, and neither the script nor its output appears in the README. The top-level tree shows how much more sits outside the documented path: cc.bat, status.json, .docs-meta.json, prototypes/, templates/, docs/, and both AGENTS.md and CLAUDE.md next to a .claude/ directory and a .codex/ directory. Two agent instruction files and two agent config directories at the root of a Tauri application is a deliberate arrangement, and its effect is that part of the workflow is written down in files the README never sends you to. status.json is the strangest of the set: no script in package.json reads or writes it and no README line explains it. Whether these are build inputs, developer scratch state or shipping data is not decidable from the file listing, which is the point. The documented surface produces a binary from pnpm tauri build. Everything else in the tree is unlabeled.

## Tiptap is pinned two different ways inside one manifest

The editor dependencies are pinned inconsistently. @tiptap/core sits at the exact version 3.20.4 with no range operator, and @tiptap/extension-code is pinned the same way. Everything else in that family uses a caret: extension-code-block-lowlight, extension-color, extension-heading, extension-highlight, extension-image and extension-link all read ^3.20.4. The outlier is @tiptap/extension-mathematics at ^3.22.4, a range whose floor is a minor version two ahead of the core it extends. The effect is that the caret entries float up to any 3.x release while the editor runtime and the code extension hold still. The Tauri side is looser still: @tauri-apps/api and @tauri-apps/plugin-opener are ^2 with no minor floor at all, while the other plugins carry explicit floors such as ^2.10.0 for updater, ^2.5.1 for autostart and ^2.3.2 for clipboard-manager. Outside Tauri, the knowledge graph comes from @antv/g6 at ^5.0.51, the whiteboard from @excalidraw/excalidraw at ^0.18.1, and long lists are virtualised through @tanstack/react-virtual at ^3.13.23. Only two packages in the visible block are held exactly.

## Issue links are written for a subdirectory view of the README

The contribution table links three actions through relative paths that begin two levels up: ../../issues/new?template=bug_report.md for bugs, ../../issues/new?template=feature_request.md for feature requests and ../../compare for pull requests. From the repository root those paths resolve outside the repository. They only make sense when the file is rendered from a subdirectory, which is why every other link in the same table is an absolute URL, including the star links for GitHub and the Gitee mirror. The two template names in those query strings, bug_report.md and feature_request.md, have to exist under .github/ for the links to land on a form, and a .github/ directory is indeed present. Behind the links sits a hard gate. The README states that the project runs AGPL-3.0 plus commercial licensing as a dual scheme, that every external pull request must agree to a CLA, and that a PR without the CLA box ticked will not be reviewed. CONTRIBUTING.md is named as mandatory reading before submission.

## The donation image slot is empty and a paid community sits beside the free claim

The donations section says the project is fully open source and free, with no membership or subscription of any kind, then asks readers to scan a WeChat payment code. The code is not there. The block is a bare p element with align set to center and nothing inside it, so the rendered page shows an empty centred line where the image should be. Four alternative ways to help follow, three of them GitHub or Bilibili actions, including stars on both the GitHub repository and the Gitee mirror at gitee.com/bkywksj/knowledge-base. The community table then mixes free channels with a paid one: a QQ group numbered 1090770702 for bug reports, use questions and feature discussion, a Bilibili author page at space.bilibili.com/520725002 carrying tutorial videos and feature demos, and a paid membership community numbered 91839984 for the author AI-from-backend series. The free statement in one section and the paid membership in another describe different things, but the README puts them four headings apart with nothing distinguishing them.

## Conclusion

bkywksj/knowledge-base fits a solo note taker who wants a Tauri desktop client with FTS5 search, bidirectional links and sync they control end to end, and who can live with dual AGPL and commercial licence terms. It does not fit a team that needs an installed build today, because the README documents only developer commands and the newest tag trails the manifest. Before committing, confirm which version you are really running, whether your intended use falls into the paid column of the licence table, and where the unlinked INSTALL.md and the undocumented build:mcp step belong in your own workflow.

## FAQ

### Does bkywksj/knowledge-base need a paid licence for workplace use?

Not if the tool stays internal and undistributed. The usage table puts personal study, research, non-commercial use and internal enterprise tools in the free column provided AGPL-3.0 compliance is kept. Closed-source commercial packaging, SaaS without published source and redistribution inside proprietary software all move to the paid column.

### Which version of bkywksj/knowledge-base does a release actually give me?

The newest published tag is v1.62.0 from 2026-09-01, listed next to mobile-v0.2.0 from 2026-09-16 and v1.52.0 from 2026-08-05. The manifest in the tree already reads 1.64.0, so the source and the last release do not carry the same version number.

### How do I build bkywksj/knowledge-base from source?

The documented path is pnpm install followed by pnpm tauri dev for a development window, and pnpm tauri build to produce a binary. An INSTALL.md file exists at the repository root but the README never links to it, so there is no end-user installation command in that file.

### Which sync backends does bkywksj/knowledge-base support?

WebDAV, S3 and a synchronised folder, with per-note incremental transfers scheduled in both directions and a whole-library ZIP backup. There is also an encrypted note vault with a PIN for hidden notes and a configurable data directory.

### Can I open a pull request against bkywksj/knowledge-base?

External pull requests must agree to the contributor licence agreement, and the README states that a PR without the CLA box ticked will not be reviewed. CONTRIBUTING.md is named as required reading before anything is submitted.

## Sources

- [bkywksj/knowledge-base on GitHub](https://github.com/bkywksj/knowledge-base)
- [Issues](https://github.com/bkywksj/knowledge-base/issues)
- [Project website](https://kb.ruoyi.plus)
- [README](https://github.com/bkywksj/knowledge-base/blob/master/README.md)
- [Releases](https://github.com/bkywksj/knowledge-base/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bkywksj-knowledge-base
