mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 09:19:34 +05:30
feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0): - MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via npm run bundle:markitdown; ML extras excluded) — built and verified locally: HTML/XLSX/PDF conversions pass through the bundled binary, and the app resolves bin/linux/markitdown first at runtime - Packaging copies bundled markitdown alongside Pandoc for win/mac/linux; FFmpeg/sharp/KaTeX/fonts were already bundled Legal artifacts: - THIRD-PARTY-NOTICES.md: complete license inventory of everything distributed (binaries, npm runtime deps, fonts, embedded Python packages) - SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2, ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking note for libvips - third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0, OFL-1.1, PSF-Python texts - Help > Third-Party Notices & Licenses: in-app viewer for both documents - README: 'Bundled Dependencies, Legal Notices & Credits' section Hardening: - download-tools.js now SHA-256 pins every artifact, verifies after download AND against the cache on every run, and hard-fails on mismatch (closes security finding D6) Large tools intentionally not bundled (documented): LibreOffice, MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre. 637/637 tests green; lint clean; clean boot; bundled binary verified.
This commit is contained in:
+24
-3
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "markdown-converter",
|
||||
"version": "4.6.1",
|
||||
"version": "4.7.0",
|
||||
"description": "Professional Markdown editor and universal file converter with PDF editing, batch processing, and syntax highlighting",
|
||||
"main": "src/main.js",
|
||||
"scripts": {
|
||||
@@ -24,6 +24,7 @@
|
||||
"dist": "electron-builder --publish=never",
|
||||
"dist:all": "electron-builder -mwl",
|
||||
"download-tools": "node scripts/download-tools.js",
|
||||
"bundle:markitdown": "node scripts/bundle-markitdown.js",
|
||||
"generate-icons": "node scripts/generate-icons.js"
|
||||
},
|
||||
"keywords": [
|
||||
@@ -112,7 +113,9 @@
|
||||
"assets/**/*",
|
||||
"scripts/**/*",
|
||||
"node_modules/**/*",
|
||||
"package.json"
|
||||
"package.json",
|
||||
"THIRD-PARTY-NOTICES.md",
|
||||
"SOURCES.md"
|
||||
],
|
||||
"asarUnpack": [
|
||||
"node_modules/ffmpeg-static/**",
|
||||
@@ -147,7 +150,17 @@
|
||||
],
|
||||
"mac": {
|
||||
"category": "public.app-category.productivity",
|
||||
"identity": null
|
||||
"identity": null,
|
||||
"extraFiles": [
|
||||
{
|
||||
"from": "bin/darwin/pandoc",
|
||||
"to": "bin/pandoc"
|
||||
},
|
||||
{
|
||||
"from": "bin/darwin/markitdown",
|
||||
"to": "bin/markitdown"
|
||||
}
|
||||
]
|
||||
},
|
||||
"win": {
|
||||
"target": [
|
||||
@@ -179,6 +192,10 @@
|
||||
{
|
||||
"from": "bin/win32/pandoc.exe",
|
||||
"to": "bin/pandoc.exe"
|
||||
},
|
||||
{
|
||||
"from": "bin/win32/markitdown.exe",
|
||||
"to": "bin/markitdown.exe"
|
||||
}
|
||||
]
|
||||
},
|
||||
@@ -210,6 +227,10 @@
|
||||
{
|
||||
"from": "bin/linux/pandoc",
|
||||
"to": "bin/pandoc"
|
||||
},
|
||||
{
|
||||
"from": "bin/linux/markitdown",
|
||||
"to": "bin/markitdown"
|
||||
}
|
||||
]
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user