The public repos carried no license, so nobody could legally copy or build on the code, and the whitepaper's "free software" had nothing behind it. Theseus and its companions take the Mozilla Public License 2.0, the file-level copyleft Firefox and Brave use, which is compatible with every component they bundle. The resolver and gateway libraries take Apache-2.0 so that other implementations of the registry can reuse them without copyleft in the way. The protocol documents and the whitepaper are CC BY 4.0. A third-party notices file lists what the browser ships and fetches, with the source offer the GPL sing-box binary the VPN add-on downloads requires; the matching source archive is now published beside the binaries. The names and marks are reserved in TRADEMARKS.md, separate from the code license, so a fork must ship under its own name. Settings › General says the license and links the three files; the whitepaper says the same.
4.7 KiB
Third-party notices
Theseus Navigator is licensed under the Mozilla Public License 2.0 (see LICENSE). It ships with, or
fetches at runtime, the components below, each under its own license. Copyright notices and license texts
for the npm packages are in their folders under node_modules/; the vendored components carry theirs
next to the files. Nothing in this list changes the license of the component it names.
Runtime and platform
| Component | Version | License | Where |
|---|---|---|---|
| Electron (Chromium, Node.js) | 44.4.3 | MIT; Chromium BSD-3-Clause and others (see LICENSES.chromium.html in the install) |
the application shell |
| Tor | 0.4.9.11 | BSD-3-Clause | resources/tor/, started by the Tor toggle |
| Node.js runtime inside Electron | bundled with Electron | MIT | main process |
Bundled npm packages
| Package | Version | License |
|---|---|---|
| @bch-wc2/interfaces | 0.0.16 | MIT |
| @bitauth/libauth | 3.1.0-next.8 | MIT |
| @bitcoinerlab/secp256k1 | 1.2.0 | MIT |
| @duckduckgo/autoconsent | 16.42.0 | MPL-2.0 |
| @ghostery/adblocker | 2.18.2 | MPL-2.0 |
| @noble/curves | 2.0.1 | MIT |
| @noble/hashes | 2.0.1 | MIT |
| @scure/bip32 | 2.0.1 | MIT |
| @wizardconnect/core | 0.2.4 | LGPL-3.0-or-later |
| @wizardconnect/wallet | 0.2.3 | LGPL-3.0-or-later |
| bip32 | 4.0.0 | MIT |
| bip39 | 3.1.0 | ISC |
| bitcoinjs-lib | 6.1.7 | MIT |
| ecpair | 2.1.0 | MIT |
| eventemitter3 | 5.0.4 | MIT |
| fetch-socks | 1.3.3 | MIT |
| isomorphic-ws | 5.0.0 | MIT |
| lossless-json | 4.3.1 | MIT |
| nostr-tools | 2.24.2 | Unlicense |
| psl | 1.15.0 | MIT |
| socks-proxy-agent | 10.1.0 | MIT |
| ws | 8.21.1 | MIT |
Packages these depend on are bundled with them and keep their own licenses, listed in their package.json.
Vendored into bundled add-ons
| Component | License | Add-on | Notes |
|---|---|---|---|
| DuckDuckGo autoconsent rules and runtime | MPL-2.0 | Cookie Pop-ups | Inlined into inject.js by build-inject.js; the source of the inlined files is the npm package above, and LICENSE-autoconsent sits beside it |
| EasyList | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | lists/easylist.txt, refreshed from easylist.to; used as data |
| EasyPrivacy | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | lists/easyprivacy.txt, refreshed from easylist.to; used as data |
| pdf.js | Apache-2.0 | PDF Editor | vendor/pdfjs/, license beside the files |
| pdf-lib | MIT | PDF Editor | vendor/pdf-lib/ |
| mammoth | BSD-2-Clause | Word editor | vendor/docx-vendor.js, shipped with small local patches described in vendor/LICENSES.txt |
| Ubuntu font family | Ubuntu Font Licence 1.0 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; fonts/LICENSES.txt |
| Fraunces font family | SIL Open Font License 1.1 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; fonts/LICENSES.txt |
Fetched at runtime by the VPN add-on
| Component | Version | License | Notes |
|---|---|---|---|
| sing-box | 1.14.1 | GPL-3.0-or-later | Downloaded on first use from navigate.st/bns/theseus.x/vpn-binaries/, hash-checked against binary-manifest.json, and run as a separate process. The VPN add-on talks to it over a local SOCKS5 port and does not link against it. |
Source offer for sing-box. Because Silent Mode redistributes sing-box binaries, the complete corresponding
source of the version served is published beside them at
https://navigate.st/bns/theseus.x/vpn-binaries/sing-box-1.14.1-source.tar.gz
(SHA-256 1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321), unmodified from
https://github.com/SagerNet/sing-box/archive/refs/tags/v1.14.1.tar.gz. Anyone who received a binary from
Silent Mode may also request that source on physical media; write to the address on silentmode.st. The offer
is valid for three years from the date the binary was served.
Notes on the copyleft components
- WizardConnect (LGPL-3.0-or-later) is loaded by the Aegis plug-in as a separate module from
node_modules/@wizardconnect/. Replacing those files with a modified version of the library is possible without rebuilding Theseus, which is what section 4 of the LGPL requires for a combined work. - autoconsent and the Ghostery adblocker (MPL-2.0) are used unmodified; any modification Silent Mode makes to an MPL-covered file is published under the MPL in the Theseus source repository.
- EasyList and EasyPrivacy are used as filter data and are redistributed unmodified under the CC BY-SA 3.0 option with this attribution: EasyList authors, https://easylist.to/.
Search engine icons
engine-icons/*.png are the favicons of the respective search engines, reproduced at 64 pixels to identify
those services in the engine picker. They remain the marks of their owners.