mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 09:19:34 +05:30
feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0): - MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via npm run bundle:markitdown; ML extras excluded) — built and verified locally: HTML/XLSX/PDF conversions pass through the bundled binary, and the app resolves bin/linux/markitdown first at runtime - Packaging copies bundled markitdown alongside Pandoc for win/mac/linux; FFmpeg/sharp/KaTeX/fonts were already bundled Legal artifacts: - THIRD-PARTY-NOTICES.md: complete license inventory of everything distributed (binaries, npm runtime deps, fonts, embedded Python packages) - SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2, ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking note for libvips - third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0, OFL-1.1, PSF-Python texts - Help > Third-Party Notices & Licenses: in-app viewer for both documents - README: 'Bundled Dependencies, Legal Notices & Credits' section Hardening: - download-tools.js now SHA-256 pins every artifact, verifies after download AND against the cache on every run, and hard-fails on mismatch (closes security finding D6) Large tools intentionally not bundled (documented): LibreOffice, MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre. 637/637 tests green; lint clean; clean boot; bundled binary verified.
This commit is contained in:
+55
@@ -0,0 +1,55 @@
|
||||
# Source Code Availability (GPL / LGPL Written Offer)
|
||||
|
||||
MarkdownConverter distributes the following binaries built from GPL-licensed
|
||||
software. Per GPL §3(b), this document is the written offer: **corresponding
|
||||
source code for the exact versions listed below is available on request for
|
||||
at least three years from each release**, and permanently at the referenced
|
||||
public locations. Write to: amit.wh@gmail.com (or open a GitHub issue at
|
||||
https://github.com/amitwh/markdown-converter/issues).
|
||||
|
||||
## Pandoc — GPL-2.0-or-later
|
||||
|
||||
- Binary shipped: `bin/pandoc` (v3.9.0.2, official upstream release, unmodified)
|
||||
- SHA-256 (linux): `7d124235998ecd3cdd9a463b1e5f6691a178b6461824c29a36170a0882f05597`
|
||||
- Source: <https://github.com/jgm/pandoc/archive/refs/tags/3.9.0.2.tar.gz>
|
||||
- Pandoc statically links Haskell libraries (GHC ecosystem, mostly BSD-3);
|
||||
their sources are included in the upstream release tarball's dependency set.
|
||||
|
||||
## FFmpeg — GPL-3.0-or-later (build configuration)
|
||||
|
||||
- Binary shipped: `ffmpeg` provided by the npm package `ffmpeg-static@5.3.0`
|
||||
(Linux: johnvansickle.com build; Windows: gyan.dev; macOS: evermeet.cx —
|
||||
all `--enable-gpl` builds including x264/x265, per the build banner)
|
||||
- Source:
|
||||
- FFmpeg: <https://ffmpeg.org/releases/> (use the release matching
|
||||
`ffmpeg -version` of the shipped binary)
|
||||
- Build scripts & pinned versions: <https://github.com/eugeneware/ffmpeg-static>
|
||||
- x264: <https://code.videolan.org/videolan/x264> ·
|
||||
x265: <https://bitbucket.org/multicoreware/x265_git/> ·
|
||||
other `--enable-lib*` components: their upstream sources (all free/open)
|
||||
|
||||
## PyInstaller bootloader (inside the bundled MarkItDown binary) — GPL-2.0 with boot-exception
|
||||
|
||||
- Binary shipped: `bin/markitdown` (MarkItDown 0.1.7 frozen with PyInstaller 6.x)
|
||||
- PyInstaller grants a special exception allowing the bootloader to be
|
||||
embedded in non-GPL frozen applications; source anyway:
|
||||
<https://github.com/pyinstaller/pyinstaller>
|
||||
- Everything frozen above the bootloader (markitdown + Python packages +
|
||||
CPython runtime) is permissively licensed (MIT/Apache/BSD/PSF/MPL);
|
||||
see THIRD-PARTY-NOTICES.md §2 for the list.
|
||||
- CPython runtime source: <https://www.python.org/downloads/source/>
|
||||
(PSF License — not GPL, listed here for completeness).
|
||||
|
||||
## libvips (via sharp prebuilt binaries) — LGPL-2.1-or-later
|
||||
|
||||
- Shipped as dynamically-loaded libraries from `@img/*` prebuilts for sharp 0.35.4
|
||||
- Source: <https://github.com/libvips/libvips> · prebuilt bundle sources:
|
||||
<https://github.com/lovell/sharp-builds>
|
||||
- LGPL compliance: the app's own source is public (MIT) and the libraries
|
||||
remain separately replaceable files in the installation directory
|
||||
(`node_modules/@img/`), satisfying the relinking requirement.
|
||||
|
||||
---
|
||||
|
||||
_Versions and hashes above correspond to the release this file ships with;
|
||||
update them when bumping bundled tool versions._
|
||||
Reference in New Issue
Block a user