# Third-party notices Theseus Navigator is licensed under the Mozilla Public License 2.0 (see `LICENSE`). It ships with, or fetches at runtime, the components below, each under its own license. Copyright notices and license texts for the npm packages are in their folders under `node_modules/`; the vendored components carry theirs next to the files. Nothing in this list changes the license of the component it names. ## Runtime and platform | Component | Version | License | Where | | --- | --- | --- | --- | | Electron (Chromium, Node.js) | 44.4.3 | MIT; Chromium BSD-3-Clause and others (see `LICENSES.chromium.html` in the install) | the application shell | | Tor | 0.4.9.11 | BSD-3-Clause | `resources/tor/`, started by the Tor toggle | | Node.js runtime inside Electron | bundled with Electron | MIT | main process | ## Bundled npm packages | Package | Version | License | | --- | --- | --- | | @bch-wc2/interfaces | 0.0.16 | MIT | | @bitauth/libauth | 3.1.0-next.8 | MIT | | @bitcoinerlab/secp256k1 | 1.2.0 | MIT | | @duckduckgo/autoconsent | 16.42.0 | MPL-2.0 | | @ghostery/adblocker | 2.18.2 | MPL-2.0 | | @noble/curves | 2.0.1 | MIT | | @noble/hashes | 2.0.1 | MIT | | @scure/bip32 | 2.0.1 | MIT | | @wizardconnect/core | 0.2.4 | LGPL-3.0-or-later | | @wizardconnect/wallet | 0.2.3 | LGPL-3.0-or-later | | bip32 | 4.0.0 | MIT | | bip39 | 3.1.0 | ISC | | bitcoinjs-lib | 6.1.7 | MIT | | ecpair | 2.1.0 | MIT | | eventemitter3 | 5.0.4 | MIT | | fetch-socks | 1.3.3 | MIT | | isomorphic-ws | 5.0.0 | MIT | | lossless-json | 4.3.1 | MIT | | nostr-tools | 2.24.2 | Unlicense | | psl | 1.15.0 | MIT | | socks-proxy-agent | 10.1.0 | MIT | | ws | 8.21.1 | MIT | Packages these depend on are bundled with them and keep their own licenses, listed in their `package.json`. ## Vendored into bundled add-ons | Component | License | Add-on | Notes | | --- | --- | --- | --- | | DuckDuckGo autoconsent rules and runtime | MPL-2.0 | Cookie Pop-ups | Inlined into `inject.js` by `build-inject.js`; the source of the inlined files is the npm package above, and `LICENSE-autoconsent` sits beside it | | EasyList | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easylist.txt`, refreshed from easylist.to; used as data | | EasyPrivacy | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easyprivacy.txt`, refreshed from easylist.to; used as data | | pdf.js | Apache-2.0 | PDF Editor | `vendor/pdfjs/`, license beside the files | | pdf-lib | MIT | PDF Editor | `vendor/pdf-lib/` | | mammoth | BSD-2-Clause | Word editor | `vendor/docx-vendor.js`, shipped with small local patches described in `vendor/LICENSES.txt` | | Ubuntu font family | Ubuntu Font Licence 1.0 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` | | Fraunces font family | SIL Open Font License 1.1 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` | ## Fetched at runtime by the VPN add-on | Component | Version | License | Notes | | --- | --- | --- | --- | | sing-box | 1.14.1 | GPL-3.0-or-later | Downloaded on first use from `navigate.st/bns/theseus.x/vpn-binaries/`, hash-checked against `binary-manifest.json`, and run as a separate process. The VPN add-on talks to it over a local SOCKS5 port and does not link against it. | **Source offer for sing-box.** Because Silent Mode redistributes sing-box binaries, the complete corresponding source of the version served is published beside them at `https://navigate.st/bns/theseus.x/vpn-binaries/sing-box-1.14.1-source.tar.gz` (SHA-256 `1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321`), unmodified from `https://github.com/SagerNet/sing-box/archive/refs/tags/v1.14.1.tar.gz`. Anyone who received a binary from Silent Mode may also request that source on physical media; write to the address on silentmode.st. The offer is valid for three years from the date the binary was served. ## Notes on the copyleft components - **WizardConnect** (LGPL-3.0-or-later) is loaded by the Aegis plug-in as a separate module from `node_modules/@wizardconnect/`. Replacing those files with a modified version of the library is possible without rebuilding Theseus, which is what section 4 of the LGPL requires for a combined work. - **autoconsent and the Ghostery adblocker** (MPL-2.0) are used unmodified; any modification Silent Mode makes to an MPL-covered file is published under the MPL in the Theseus source repository. - **EasyList and EasyPrivacy** are used as filter data and are redistributed unmodified under the CC BY-SA 3.0 option with this attribution: EasyList authors, https://easylist.to/. ## Search engine icons `engine-icons/*.png` are the favicons of the respective search engines, reproduced at 64 pixels to identify those services in the engine picker. They remain the marks of their owners.