mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 09:19:34 +05:30
feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0): - MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via npm run bundle:markitdown; ML extras excluded) — built and verified locally: HTML/XLSX/PDF conversions pass through the bundled binary, and the app resolves bin/linux/markitdown first at runtime - Packaging copies bundled markitdown alongside Pandoc for win/mac/linux; FFmpeg/sharp/KaTeX/fonts were already bundled Legal artifacts: - THIRD-PARTY-NOTICES.md: complete license inventory of everything distributed (binaries, npm runtime deps, fonts, embedded Python packages) - SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2, ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking note for libvips - third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0, OFL-1.1, PSF-Python texts - Help > Third-Party Notices & Licenses: in-app viewer for both documents - README: 'Bundled Dependencies, Legal Notices & Credits' section Hardening: - download-tools.js now SHA-256 pins every artifact, verifies after download AND against the cache on every run, and hard-fails on mismatch (closes security finding D6) Large tools intentionally not bundled (documented): LibreOffice, MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre. 637/637 tests green; lint clean; clean boot; bundled binary verified.
This commit is contained in:
+23
@@ -1,5 +1,28 @@
|
||||
# PanConverter - Updates & Changelog
|
||||
|
||||
## Version 4.7.0 (2026-09-05)
|
||||
|
||||
### Bundling & Legal Compliance
|
||||
- **MarkItDown is now bundled**: `npm run bundle:markitdown` freezes Microsoft's
|
||||
markitdown (MIT) + embedded Python runtime into a single ~75MB per-platform
|
||||
binary (`bin/<platform>/markitdown`) via PyInstaller (ML extras excluded);
|
||||
the app prefers the bundled binary and falls back to system installs
|
||||
- Packaging copies the bundled markitdown for Windows/macOS/Linux alongside Pandoc
|
||||
- **THIRD-PARTY-NOTICES.md** — full license inventory of everything distributed
|
||||
(bundled binaries, npm runtime deps, fonts, embedded Python packages)
|
||||
- **SOURCES.md** — GPL §3(b) written source offer for Pandoc / FFmpeg (GPL build) /
|
||||
PyInstaller bootloader, with pinned versions + SHA-256; LGPL relinking note for libvips
|
||||
- **third-party-licenses/** — canonical texts: GPL-2.0, LGPL-2.1, MPL-2.0,
|
||||
Apache-2.0, OFL-1.1, PSF-Python
|
||||
- **Help → Third-Party Notices & Licenses** — in-app viewer for both documents
|
||||
- **download-tools.js** now SHA-256 pins and verifies every downloaded artifact
|
||||
(post-download and against the cache on every run; hard-fails on mismatch)
|
||||
- README gains a "Bundled Dependencies, Legal Notices & Credits" section
|
||||
- Large optional tools intentionally NOT bundled (documented): LibreOffice,
|
||||
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre
|
||||
|
||||
---
|
||||
|
||||
## Version 4.6.1 (2026-09-05)
|
||||
|
||||
### New Features
|
||||
|
||||
Reference in New Issue
Block a user