theseus/THIRD-PARTY-NOTICES.md

86 lines
4.7 KiB
Markdown
Raw Permalink Normal View History

# Third-party notices
Theseus Navigator is licensed under the Mozilla Public License 2.0 (see `LICENSE`). It ships with, or
fetches at runtime, the components below, each under its own license. Copyright notices and license texts
for the npm packages are in their folders under `node_modules/`; the vendored components carry theirs
next to the files. Nothing in this list changes the license of the component it names.
## Runtime and platform
| Component | Version | License | Where |
| --- | --- | --- | --- |
| Electron (Chromium, Node.js) | 44.4.3 | MIT; Chromium BSD-3-Clause and others (see `LICENSES.chromium.html` in the install) | the application shell |
| Tor | 0.4.9.11 | BSD-3-Clause | `resources/tor/`, started by the Tor toggle |
| Node.js runtime inside Electron | bundled with Electron | MIT | main process |
## Bundled npm packages
| Package | Version | License |
| --- | --- | --- |
| @bch-wc2/interfaces | 0.0.16 | MIT |
| @bitauth/libauth | 3.1.0-next.8 | MIT |
| @bitcoinerlab/secp256k1 | 1.2.0 | MIT |
| @duckduckgo/autoconsent | 16.42.0 | MPL-2.0 |
| @ghostery/adblocker | 2.18.2 | MPL-2.0 |
| @noble/curves | 2.0.1 | MIT |
| @noble/hashes | 2.0.1 | MIT |
| @scure/bip32 | 2.0.1 | MIT |
| @wizardconnect/core | 0.2.4 | LGPL-3.0-or-later |
| @wizardconnect/wallet | 0.2.3 | LGPL-3.0-or-later |
| bip32 | 4.0.0 | MIT |
| bip39 | 3.1.0 | ISC |
| bitcoinjs-lib | 6.1.7 | MIT |
| ecpair | 2.1.0 | MIT |
| eventemitter3 | 5.0.4 | MIT |
| fetch-socks | 1.3.3 | MIT |
| isomorphic-ws | 5.0.0 | MIT |
| lossless-json | 4.3.1 | MIT |
| nostr-tools | 2.24.2 | Unlicense |
| psl | 1.15.0 | MIT |
| socks-proxy-agent | 10.1.0 | MIT |
| ws | 8.21.1 | MIT |
Packages these depend on are bundled with them and keep their own licenses, listed in their `package.json`.
## Vendored into bundled add-ons
| Component | License | Add-on | Notes |
| --- | --- | --- | --- |
| DuckDuckGo autoconsent rules and runtime | MPL-2.0 | Cookie Pop-ups | Inlined into `inject.js` by `build-inject.js`; the source of the inlined files is the npm package above, and `LICENSE-autoconsent` sits beside it |
| EasyList | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easylist.txt`, refreshed from easylist.to; used as data |
| EasyPrivacy | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easyprivacy.txt`, refreshed from easylist.to; used as data |
| pdf.js | Apache-2.0 | PDF Editor | `vendor/pdfjs/`, license beside the files |
| pdf-lib | MIT | PDF Editor | `vendor/pdf-lib/` |
| mammoth | BSD-2-Clause | Word editor | `vendor/docx-vendor.js`, shipped with small local patches described in `vendor/LICENSES.txt` |
| Ubuntu font family | Ubuntu Font Licence 1.0 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` |
| Fraunces font family | SIL Open Font License 1.1 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` |
## Fetched at runtime by the VPN add-on
| Component | Version | License | Notes |
| --- | --- | --- | --- |
| sing-box | 1.14.1 | GPL-3.0-or-later | Downloaded on first use from `navigate.st/bns/theseus.x/vpn-binaries/`, hash-checked against `binary-manifest.json`, and run as a separate process. The VPN add-on talks to it over a local SOCKS5 port and does not link against it. |
**Source offer for sing-box.** Because Silent Mode redistributes sing-box binaries, the complete corresponding
source of the version served is published beside them at
`https://navigate.st/bns/theseus.x/vpn-binaries/sing-box-1.14.1-source.tar.gz`
(SHA-256 `1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321`), unmodified from
`https://github.com/SagerNet/sing-box/archive/refs/tags/v1.14.1.tar.gz`. Anyone who received a binary from
Silent Mode may also request that source on physical media; write to the address on silentmode.st. The offer
is valid for three years from the date the binary was served.
## Notes on the copyleft components
- **WizardConnect** (LGPL-3.0-or-later) is loaded by the Aegis plug-in as a separate module from
`node_modules/@wizardconnect/`. Replacing those files with a modified version of the library is possible
without rebuilding Theseus, which is what section 4 of the LGPL requires for a combined work.
- **autoconsent and the Ghostery adblocker** (MPL-2.0) are used unmodified; any modification Silent Mode
makes to an MPL-covered file is published under the MPL in the Theseus source repository.
- **EasyList and EasyPrivacy** are used as filter data and are redistributed unmodified under the CC BY-SA
3.0 option with this attribution: EasyList authors, https://easylist.to/.
## Search engine icons
`engine-icons/*.png` are the favicons of the respective search engines, reproduced at 64 pixels to identify
those services in the engine picker. They remain the marks of their owners.