diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-05 08:59:06 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-05 09:20:38 +0200 |
| commit | cce8a911553597ada33e275bc9b29fd34121074d (patch) | |
| tree | 58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md | |
| parent | bacab81915a9ab640437b7d674bf9e29e701b1f1 (diff) | |
| download | meshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz | |
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so
any client may use it whatever its own licence: meshbay-common, and the files
marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js,
transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop;
Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is
AGPL-3.0-or-later, which the RPM specs and package.json already declared
without a licence file to back them.
Two AGPL section 7 permissions:
- group applications may be under any licence when they use the interface
only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt);
the reference application is 0BSD so that copying it brings no AGPL code;
- the Android application may be conveyed linked with Google Play services.
Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from
what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and
the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its
BSD licence does not mention — and the vendored browser libraries get their
licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata,
RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt.
test_licensing.py holds the line: the LGPL layer imports nothing under the
AGPL, the reference application nothing outside the application interface,
and every SPDX line is one of the known ones.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md | 22 |
1 files changed, 22 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md index 6935e91..53d4af3 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md +++ b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md @@ -34,3 +34,25 @@ The browser never requests it — `argon2.min.js` carries the same bytes inline a data URL. It is kept because the cross-language parity test drives the vendored library under node, where the emscripten loader takes its file path instead of the inline copy, and a test that cannot run is a test that stops being true. + +## htm-preact.js + +| | | +|---|---| +| Package | `htm` 3.1.1 (npm) — Apache-2.0 | +| Source | https://registry.npmjs.org/htm/-/htm-3.1.1.tgz | +| Tarball sha256 | `2425b9bee11409177bcabc7f32e319926fc6690c1701c0b257c88bdff2d5ba90` | +| Tarball sha1 (npm dist.shasum) | `49266582be0dc66ed2235d5ea892307cc0c24b78` | +| File taken | `package/preact/standalone.module.js` | +| File sha256 | `72284e8e9079c87817145df1110f74e8a2aa040b2fc384922e18dfcb46fc1fd7` | + +htm's "standalone" build: htm and Preact 10 (MIT) with its hooks, in one ES +module, so the SPA has a component model without a bundler or a second request. +The same bytes ship in htm 3.1.0; this entry was identified after the fact, by +matching the committed file against both releases. + +## Licences + +`LICENSES.txt`, beside these files, carries the licence text of each of them; +the MIT and Apache licences both ask for it to travel with every copy. A file +added here adds its licence there. |