From cce8a911553597ada33e275bc9b29fd34121074d Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 5 Oct 2026 08:59:06 +0200 Subject: chore: license MeshBay — LGPL protocol layer, AGPL for the rest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The protocol layer is LGPL-3.0-or-later in every language it exists in, so any client may use it whatever its own licence: meshbay-common, and the files marked with an SPDX line — keyderive.js, crypto.js, playlist-crypto.js, transport*.js; keyring.js, transcripts.js and argon2-wasm.js on the desktop; Kdf.kt, Keyring.kt and Transcripts.kt on Android. Everything else is AGPL-3.0-or-later, which the RPM specs and package.json already declared without a licence file to back them. Two AGPL section 7 permissions: - group applications may be under any licence when they use the interface only through a named surface (static/licenses/APPLICATION-EXCEPTION.txt); the reference application is 0BSD so that copying it brings no AGPL code; - the Android application may be conveyed linked with Google Play services. Third-party code is accounted for: THIRD-PARTY-NOTICES.txt is generated from what a build ships (packaging/third_party_notices.py) for the deb/rpm venv and the frozen Windows node — PyAV's wheel grafts in libx264 and libx265, which its BSD licence does not mention — and the vendored browser libraries get their licence texts and htm-preact.js its provenance. Wheels carry SPDX metadata, RPMs %license, debs a DEP-5 copyright file, every Windows target LICENSE.txt. test_licensing.py holds the line: the LGPL layer imports nothing under the AGPL, the reference application nothing outside the application interface, and every SPDX line is one of the known ones. Co-Authored-By: Claude Opus 5.5 --- .../src/meshbay_hub/static/vendor/PROVENANCE.md | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) (limited to 'packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md') diff --git a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md index 6935e91..53d4af3 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md +++ b/packages/meshbay-hub/src/meshbay_hub/static/vendor/PROVENANCE.md @@ -34,3 +34,25 @@ The browser never requests it — `argon2.min.js` carries the same bytes inline a data URL. It is kept because the cross-language parity test drives the vendored library under node, where the emscripten loader takes its file path instead of the inline copy, and a test that cannot run is a test that stops being true. + +## htm-preact.js + +| | | +|---|---| +| Package | `htm` 3.1.1 (npm) — Apache-2.0 | +| Source | https://registry.npmjs.org/htm/-/htm-3.1.1.tgz | +| Tarball sha256 | `2425b9bee11409177bcabc7f32e319926fc6690c1701c0b257c88bdff2d5ba90` | +| Tarball sha1 (npm dist.shasum) | `49266582be0dc66ed2235d5ea892307cc0c24b78` | +| File taken | `package/preact/standalone.module.js` | +| File sha256 | `72284e8e9079c87817145df1110f74e8a2aa040b2fc384922e18dfcb46fc1fd7` | + +htm's "standalone" build: htm and Preact 10 (MIT) with its hooks, in one ES +module, so the SPA has a component model without a bundler or a second request. +The same bytes ship in htm 3.1.0; this entry was identified after the fact, by +matching the committed file against both releases. + +## Licences + +`LICENSES.txt`, beside these files, carries the licence text of each of them; +the MIT and Apache licences both ask for it to travel with every copy. A file +added here adds its licence there. -- cgit v1.2.3