theseus/THIRD-PARTY-NOTICES.md
Local Dev 13e4c6997c Licenses: MPL-2.0 for Theseus, Ariadne and Hephaestus; Apache-2.0 for Argus; CC BY 4.0 for the documents
The public repos carried no license, so nobody could legally copy or build
on the code, and the whitepaper's "free software" had nothing behind it.
Theseus and its companions take the Mozilla Public License 2.0, the
file-level copyleft Firefox and Brave use, which is compatible with every
component they bundle. The resolver and gateway libraries take Apache-2.0
so that other implementations of the registry can reuse them without
copyleft in the way. The protocol documents and the whitepaper are CC BY 4.0.

A third-party notices file lists what the browser ships and fetches, with
the source offer the GPL sing-box binary the VPN add-on downloads requires;
the matching source archive is now published beside the binaries. The
names and marks are reserved in TRADEMARKS.md, separate from the code
license, so a fork must ship under its own name. Settings › General says
the license and links the three files; the whitepaper says the same.
2026-09-29 00:18:00 +02:00

4.7 KiB

Third-party notices

Theseus Navigator is licensed under the Mozilla Public License 2.0 (see LICENSE). It ships with, or fetches at runtime, the components below, each under its own license. Copyright notices and license texts for the npm packages are in their folders under node_modules/; the vendored components carry theirs next to the files. Nothing in this list changes the license of the component it names.

Runtime and platform

Component Version License Where
Electron (Chromium, Node.js) 44.4.3 MIT; Chromium BSD-3-Clause and others (see LICENSES.chromium.html in the install) the application shell
Tor 0.4.9.11 BSD-3-Clause resources/tor/, started by the Tor toggle
Node.js runtime inside Electron bundled with Electron MIT main process

Bundled npm packages

Package Version License
@bch-wc2/interfaces 0.0.16 MIT
@bitauth/libauth 3.1.0-next.8 MIT
@bitcoinerlab/secp256k1 1.2.0 MIT
@duckduckgo/autoconsent 16.42.0 MPL-2.0
@ghostery/adblocker 2.18.2 MPL-2.0
@noble/curves 2.0.1 MIT
@noble/hashes 2.0.1 MIT
@scure/bip32 2.0.1 MIT
@wizardconnect/core 0.2.4 LGPL-3.0-or-later
@wizardconnect/wallet 0.2.3 LGPL-3.0-or-later
bip32 4.0.0 MIT
bip39 3.1.0 ISC
bitcoinjs-lib 6.1.7 MIT
ecpair 2.1.0 MIT
eventemitter3 5.0.4 MIT
fetch-socks 1.3.3 MIT
isomorphic-ws 5.0.0 MIT
lossless-json 4.3.1 MIT
nostr-tools 2.24.2 Unlicense
psl 1.15.0 MIT
socks-proxy-agent 10.1.0 MIT
ws 8.21.1 MIT

Packages these depend on are bundled with them and keep their own licenses, listed in their package.json.

Vendored into bundled add-ons

Component License Add-on Notes
DuckDuckGo autoconsent rules and runtime MPL-2.0 Cookie Pop-ups Inlined into inject.js by build-inject.js; the source of the inlined files is the npm package above, and LICENSE-autoconsent sits beside it
EasyList GPL-3.0 or CC BY-SA 3.0 (dual) Shield lists/easylist.txt, refreshed from easylist.to; used as data
EasyPrivacy GPL-3.0 or CC BY-SA 3.0 (dual) Shield lists/easyprivacy.txt, refreshed from easylist.to; used as data
pdf.js Apache-2.0 PDF Editor vendor/pdfjs/, license beside the files
pdf-lib MIT PDF Editor vendor/pdf-lib/
mammoth BSD-2-Clause Word editor vendor/docx-vendor.js, shipped with small local patches described in vendor/LICENSES.txt
Ubuntu font family Ubuntu Font Licence 1.0 Word editor woff2 subsets built by Google Fonts, shipped unmodified; fonts/LICENSES.txt
Fraunces font family SIL Open Font License 1.1 Word editor woff2 subsets built by Google Fonts, shipped unmodified; fonts/LICENSES.txt

Fetched at runtime by the VPN add-on

Component Version License Notes
sing-box 1.14.1 GPL-3.0-or-later Downloaded on first use from navigate.st/bns/theseus.x/vpn-binaries/, hash-checked against binary-manifest.json, and run as a separate process. The VPN add-on talks to it over a local SOCKS5 port and does not link against it.

Source offer for sing-box. Because Silent Mode redistributes sing-box binaries, the complete corresponding source of the version served is published beside them at https://navigate.st/bns/theseus.x/vpn-binaries/sing-box-1.14.1-source.tar.gz (SHA-256 1ea41f7d06b0017fe3d3ba7ee30959048aa0ddde31cb0165dab9257edf673321), unmodified from https://github.com/SagerNet/sing-box/archive/refs/tags/v1.14.1.tar.gz. Anyone who received a binary from Silent Mode may also request that source on physical media; write to the address on silentmode.st. The offer is valid for three years from the date the binary was served.

Notes on the copyleft components

  • WizardConnect (LGPL-3.0-or-later) is loaded by the Aegis plug-in as a separate module from node_modules/@wizardconnect/. Replacing those files with a modified version of the library is possible without rebuilding Theseus, which is what section 4 of the LGPL requires for a combined work.
  • autoconsent and the Ghostery adblocker (MPL-2.0) are used unmodified; any modification Silent Mode makes to an MPL-covered file is published under the MPL in the Theseus source repository.
  • EasyList and EasyPrivacy are used as filter data and are redistributed unmodified under the CC BY-SA 3.0 option with this attribution: EasyList authors, https://easylist.to/.

Search engine icons

engine-icons/*.png are the favicons of the respective search engines, reproduced at 64 pixels to identify those services in the engine picker. They remain the marks of their owners.