aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-05 08:59:06 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-05 09:20:38 +0200
commitcce8a911553597ada33e275bc9b29fd34121074d (patch)
tree58e2eddfe4f0535e5d177959d8d6ea6da15cc552 /packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md
parentbacab81915a9ab640437b7d674bf9e29e701b1f1 (diff)
downloadmeshbay-cce8a911553597ada33e275bc9b29fd34121074d.tar.gz
chore: license MeshBay — LGPL protocol layer, AGPL for the rest
The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md22
1 files changed, 22 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md
index 6935e91..53d4af3 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md
+++ b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md
@@ -34,3 +34,25 @@ The browser never requests it — `argon2.min.js` carries the same bytes inline
a data URL. It is kept because the cross-language parity test drives the vendored
library under node, where the emscripten loader takes its file path instead of the
inline copy, and a test that cannot run is a test that stops being true.
+
+## htm-preact.js
+
+| | |
+|---|---|
+| Package | `htm` 3.1.1 (npm) — Apache-2.0 |
+| Source | https://registry.npmjs.org/htm/-/htm-3.1.1.tgz |
+| Tarball sha256 | `2425b9bee11409177bcabc7f32e319926fc6690c1701c0b257c88bdff2d5ba90` |
+| Tarball sha1 (npm dist.shasum) | `49266582be0dc66ed2235d5ea892307cc0c24b78` |
+| File taken | `package/preact/standalone.module.js` |
+| File sha256 | `72284e8e9079c87817145df1110f74e8a2aa040b2fc384922e18dfcb46fc1fd7` |
+
+htm's "standalone" build: htm and Preact 10 (MIT) with its hooks, in one ES
+module, so the SPA has a component model without a bundler or a second request.
+The same bytes ship in htm 3.1.0; this entry was identified after the fact, by
+matching the committed file against both releases.
+
+## Licences
+
+`LICENSES.txt`, beside these files, carries the licence text of each of them;
+the MIT and Apache licences both ask for it to travel with every copy. A file
+added here adds its licence there.