theseus/THIRD-PARTY-NOTICES.md
Local Dev 13e4c6997c Licenses: MPL-2.0 for Theseus, Ariadne and Hephaestus; Apache-2.0 for Argus; CC BY 4.0 for the documents
The public repos carried no license, so nobody could legally copy or build
on the code, and the whitepaper's "free software" had nothing behind it.
Theseus and its companions take the Mozilla Public License 2.0, the
file-level copyleft Firefox and Brave use, which is compatible with every
component they bundle. The resolver and gateway libraries take Apache-2.0
so that other implementations of the registry can reuse them without
copyleft in the way. The protocol documents and the whitepaper are CC BY 4.0.

A third-party notices file lists what the browser ships and fetches, with
the source offer the GPL sing-box binary the VPN add-on downloads requires;
the matching source archive is now published beside the binaries. The
names and marks are reserved in TRADEMARKS.md, separate from the code
license, so a fork must ship under its own name. Settings › General says
the license and links the three files; the whitepaper says the same.
2026-09-29 00:18:00 +02:00

85 lines
4.7 KiB
Markdown

# Third-party notices
Theseus Navigator is licensed under the Mozilla Public License 2.0 (see `LICENSE`). It ships with, or
fetches at runtime, the components below, each under its own license. Copyright notices and license texts
for the npm packages are in their folders under `node_modules/`; the vendored components carry theirs
next to the files. Nothing in this list changes the license of the component it names.
## Runtime and platform
| Component | Version | License | Where |
| --- | --- | --- | --- |
| Electron (Chromium, Node.js) | 44.4.3 | MIT; Chromium BSD-3-Clause and others (see `LICENSES.chromium.html` in the install) | the application shell |
| Tor | 0.4.9.11 | BSD-3-Clause | `resources/tor/`, started by the Tor toggle |
| Node.js runtime inside Electron | bundled with Electron | MIT | main process |
## Bundled npm packages
| Package | Version | License |
| --- | --- | --- |
| @bch-wc2/interfaces | 0.0.16 | MIT |
| @bitauth/libauth | 3.1.0-next.8 | MIT |
| @bitcoinerlab/secp256k1 | 1.2.0 | MIT |
| @duckduckgo/autoconsent | 16.42.0 | MPL-2.0 |
| @ghostery/adblocker | 2.18.2 | MPL-2.0 |
| @noble/curves | 2.0.1 | MIT |
| @noble/hashes | 2.0.1 | MIT |
| @scure/bip32 | 2.0.1 | MIT |
| @wizardconnect/core | 0.2.4 | LGPL-3.0-or-later |
| @wizardconnect/wallet | 0.2.3 | LGPL-3.0-or-later |
| bip32 | 4.0.0 | MIT |
| bip39 | 3.1.0 | ISC |
| bitcoinjs-lib | 6.1.7 | MIT |
| ecpair | 2.1.0 | MIT |
| eventemitter3 | 5.0.4 | MIT |
| fetch-socks | 1.3.3 | MIT |
| isomorphic-ws | 5.0.0 | MIT |
| lossless-json | 4.3.1 | MIT |
| nostr-tools | 2.24.2 | Unlicense |
| psl | 1.15.0 | MIT |
| socks-proxy-agent | 10.1.0 | MIT |
| ws | 8.21.1 | MIT |
Packages these depend on are bundled with them and keep their own licenses, listed in their `package.json`.
## Vendored into bundled add-ons
| Component | License | Add-on | Notes |
| --- | --- | --- | --- |
| DuckDuckGo autoconsent rules and runtime | MPL-2.0 | Cookie Pop-ups | Inlined into `inject.js` by `build-inject.js`; the source of the inlined files is the npm package above, and `LICENSE-autoconsent` sits beside it |
| EasyList | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easylist.txt`, refreshed from easylist.to; used as data |
| EasyPrivacy | GPL-3.0 or CC BY-SA 3.0 (dual) | Shield | `lists/easyprivacy.txt`, refreshed from easylist.to; used as data |
| pdf.js | Apache-2.0 | PDF Editor | `vendor/pdfjs/`, license beside the files |
| pdf-lib | MIT | PDF Editor | `vendor/pdf-lib/` |
| mammoth | BSD-2-Clause | Word editor | `vendor/docx-vendor.js`, shipped with small local patches described in `vendor/LICENSES.txt` |
| Ubuntu font family | Ubuntu Font Licence 1.0 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` |
| Fraunces font family | SIL Open Font License 1.1 | Word editor | woff2 subsets built by Google Fonts, shipped unmodified; `fonts/LICENSES.txt` |
## Fetched at runtime by the VPN add-on
| Component | Version | License | Notes |
| --- | --- | --- | --- |
| sing-box | 1.14.1 | GPL-3.0-or-later | Downloaded on first use from `navigate.st/bns/theseus.x/vpn-binaries/`, hash-checked against `binary-manifest.json`, and run as a separate process. The VPN add-on talks to it over a local SOCKS5 port and does not link against it. |
**Source offer for sing-box.** Because Silent Mode redistributes sing-box binaries, the complete corresponding
source of the version served is published beside them at
`https://navigate.st/bns/theseus.x/vpn-binaries/sing-box-1.14.1-source.tar.gz`
(SHA-256 `1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321`), unmodified from
`https://github.com/SagerNet/sing-box/archive/refs/tags/v1.14.1.tar.gz`. Anyone who received a binary from
Silent Mode may also request that source on physical media; write to the address on silentmode.st. The offer
is valid for three years from the date the binary was served.
## Notes on the copyleft components
- **WizardConnect** (LGPL-3.0-or-later) is loaded by the Aegis plug-in as a separate module from
`node_modules/@wizardconnect/`. Replacing those files with a modified version of the library is possible
without rebuilding Theseus, which is what section 4 of the LGPL requires for a combined work.
- **autoconsent and the Ghostery adblocker** (MPL-2.0) are used unmodified; any modification Silent Mode
makes to an MPL-covered file is published under the MPL in the Theseus source repository.
- **EasyList and EasyPrivacy** are used as filter data and are redistributed unmodified under the CC BY-SA
3.0 option with this attribution: EasyList authors, https://easylist.to/.
## Search engine icons
`engine-icons/*.png` are the favicons of the respective search engines, reproduced at 64 pixels to identify
those services in the engine picker. They remain the marks of their owners.