mirror of
https://github.com/amitwh/markdown-converter.git
synced 2026-10-01 09:19:34 +05:30
feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0): - MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via npm run bundle:markitdown; ML extras excluded) — built and verified locally: HTML/XLSX/PDF conversions pass through the bundled binary, and the app resolves bin/linux/markitdown first at runtime - Packaging copies bundled markitdown alongside Pandoc for win/mac/linux; FFmpeg/sharp/KaTeX/fonts were already bundled Legal artifacts: - THIRD-PARTY-NOTICES.md: complete license inventory of everything distributed (binaries, npm runtime deps, fonts, embedded Python packages) - SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2, ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking note for libvips - third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0, OFL-1.1, PSF-Python texts - Help > Third-Party Notices & Licenses: in-app viewer for both documents - README: 'Bundled Dependencies, Legal Notices & Credits' section Hardening: - download-tools.js now SHA-256 pins every artifact, verifies after download AND against the cache on every run, and hard-fails on mismatch (closes security finding D6) Large tools intentionally not bundled (documented): LibreOffice, MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre. 637/637 tests green; lint clean; clean boot; bundled binary verified.
This commit is contained in:
@@ -26,3 +26,70 @@ describe('Bundled Pandoc binary', () => {
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('Bundled MarkItDown binary (optional)', () => {
|
||||
const rootDir = path.resolve(__dirname, '..');
|
||||
const platform = process.platform;
|
||||
const binaryPath = path.join(rootDir, 'bin', platform, 'markitdown');
|
||||
const windowsBinaryPath = path.join(rootDir, 'bin', platform, 'markitdown.exe');
|
||||
|
||||
// The binary is built on demand (npm run bundle:markitdown), so CI machines
|
||||
// that haven't built it yet skip these — but when present it must be valid.
|
||||
const hasBinary = fs.existsSync(binaryPath) || fs.existsSync(windowsBinaryPath);
|
||||
const which = platform === 'win32' ? windowsBinaryPath : binaryPath;
|
||||
|
||||
(hasBinary ? describe : describe.skip)('binary present', () => {
|
||||
test('is executable', () => {
|
||||
const stats = fs.statSync(which);
|
||||
expect(stats.mode & 0o111).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
test('answers --version', (done) => {
|
||||
const { execFile } = require('child_process');
|
||||
execFile(which, ['--version'], { timeout: 30000 }, (error, stdout) => {
|
||||
expect(error).toBeNull();
|
||||
expect(stdout.toLowerCase()).toContain('markitdown');
|
||||
done();
|
||||
});
|
||||
}, 60000);
|
||||
});
|
||||
});
|
||||
|
||||
describe('Legal compliance artifacts', () => {
|
||||
const rootDir = path.resolve(__dirname, '..');
|
||||
|
||||
test('THIRD-PARTY-NOTICES.md and SOURCES.md ship at the repo root', () => {
|
||||
expect(fs.existsSync(path.join(rootDir, 'THIRD-PARTY-NOTICES.md'))).toBe(true);
|
||||
expect(fs.existsSync(path.join(rootDir, 'SOURCES.md'))).toBe(true);
|
||||
});
|
||||
|
||||
test('canonical copyleft license texts are present', () => {
|
||||
for (const file of ['GPL-2.0.txt', 'LGPL-2.1.txt', 'MPL-2.0.txt', 'Apache-2.0.txt', 'OFL-1.1.txt']) {
|
||||
expect(fs.existsSync(path.join(rootDir, 'third-party-licenses', file))).toBe(true);
|
||||
}
|
||||
});
|
||||
|
||||
test('notices mention every bundled external binary', () => {
|
||||
const notices = fs.readFileSync(path.join(rootDir, 'THIRD-PARTY-NOTICES.md'), 'utf-8');
|
||||
for (const component of ['Pandoc', 'FFmpeg', 'MarkItDown', 'libvips', 'KaTeX', 'JetBrains Mono']) {
|
||||
expect(notices).toContain(component);
|
||||
}
|
||||
// GPL source offer must reference the sources document
|
||||
expect(notices).toContain('SOURCES.md');
|
||||
});
|
||||
|
||||
test('SOURCES.md covers every GPL-licensed binary with a source link', () => {
|
||||
const sources = fs.readFileSync(path.join(rootDir, 'SOURCES.md'), 'utf-8');
|
||||
for (const section of ['Pandoc', 'FFmpeg', 'PyInstaller', 'libvips']) {
|
||||
expect(sources).toContain(section);
|
||||
}
|
||||
expect(sources).toMatch(/https:\/\/github\.com\/jgm\/pandoc/);
|
||||
expect(sources).toMatch(/https:\/\/ffmpeg\.org\/releases\//);
|
||||
});
|
||||
|
||||
test('packaging includes the legal documents in build.files', () => {
|
||||
const pkg = JSON.parse(fs.readFileSync(path.join(rootDir, 'package.json'), 'utf-8'));
|
||||
expect(pkg.build.files).toContain('THIRD-PARTY-NOTICES.md');
|
||||
expect(pkg.build.files).toContain('SOURCES.md');
|
||||
});
|
||||
});
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
*/
|
||||
const os = require('os');
|
||||
const path = require('path');
|
||||
const { resolveMarkItDown, convertToMarkdown, COMMAND_CANDIDATES } = require('../../src/main/MarkItDown');
|
||||
const { resolveMarkItDown, convertToMarkdown, commandCandidates } = require('../../src/main/MarkItDown');
|
||||
const { setImmediate } = require('timers');
|
||||
|
||||
/**
|
||||
@@ -58,8 +58,28 @@ describe('MarkItDown', () => {
|
||||
it('probes every candidate before giving up (null)', async () => {
|
||||
const runner = makeRunner({});
|
||||
expect(await resolveMarkItDown(runner)).toBeNull();
|
||||
// One probe per candidate
|
||||
expect(runner.calls).toHaveLength(COMMAND_CANDIDATES.length);
|
||||
// One probe per candidate (bundled binary included when present)
|
||||
expect(runner.calls).toHaveLength(commandCandidates().length);
|
||||
});
|
||||
|
||||
it('prefers the bundled binary when one ships with the app', async () => {
|
||||
const candidates = commandCandidates();
|
||||
if (!candidates[0].bundled) {
|
||||
// Machine has no bin/<platform>/markitdown — assert ordering of the
|
||||
// remaining candidates instead.
|
||||
expect(candidates.map((c) => c.command)).toContain('markitdown');
|
||||
return;
|
||||
}
|
||||
const runner = makeRunner({});
|
||||
const first = candidates[0];
|
||||
runner.calls.length = 0;
|
||||
// Stub the bundled path's --version probe
|
||||
const script = {};
|
||||
script[`${first.command} --version`] = { stdout: 'markitdown 0.1.7' };
|
||||
const stub = makeRunner(script);
|
||||
const resolved = await resolveMarkItDown(stub);
|
||||
expect(resolved.command).toBe(first.command);
|
||||
expect(stub.calls[0].cmd).toBe(first.command);
|
||||
});
|
||||
|
||||
it('treats a non-zero probe exit as unavailable', async () => {
|
||||
|
||||
Reference in New Issue
Block a user