feat(legal): bundle small dependencies, add notices, credits, and GPL source offers

Bundle (v4.7.0):
- MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via
  npm run bundle:markitdown; ML extras excluded) — built and verified
  locally: HTML/XLSX/PDF conversions pass through the bundled binary, and
  the app resolves bin/linux/markitdown first at runtime
- Packaging copies bundled markitdown alongside Pandoc for win/mac/linux;
  FFmpeg/sharp/KaTeX/fonts were already bundled

Legal artifacts:
- THIRD-PARTY-NOTICES.md: complete license inventory of everything
  distributed (binaries, npm runtime deps, fonts, embedded Python packages)
- SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2,
  ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking
  note for libvips
- third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0,
  OFL-1.1, PSF-Python texts
- Help > Third-Party Notices & Licenses: in-app viewer for both documents
- README: 'Bundled Dependencies, Legal Notices & Credits' section

Hardening:
- download-tools.js now SHA-256 pins every artifact, verifies after
  download AND against the cache on every run, and hard-fails on mismatch
  (closes security finding D6)

Large tools intentionally not bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre.

637/637 tests green; lint clean; clean boot; bundled binary verified.
This commit is contained in:
2026-09-05 22:30:54 +05:30
parent 58bd19ecd1
commit 1e24b52f3e
18 changed files with 2415 additions and 19 deletions
+23 -3
View File
@@ -7,7 +7,7 @@
*/
const os = require('os');
const path = require('path');
const { resolveMarkItDown, convertToMarkdown, COMMAND_CANDIDATES } = require('../../src/main/MarkItDown');
const { resolveMarkItDown, convertToMarkdown, commandCandidates } = require('../../src/main/MarkItDown');
const { setImmediate } = require('timers');
/**
@@ -58,8 +58,28 @@ describe('MarkItDown', () => {
it('probes every candidate before giving up (null)', async () => {
const runner = makeRunner({});
expect(await resolveMarkItDown(runner)).toBeNull();
// One probe per candidate
expect(runner.calls).toHaveLength(COMMAND_CANDIDATES.length);
// One probe per candidate (bundled binary included when present)
expect(runner.calls).toHaveLength(commandCandidates().length);
});
it('prefers the bundled binary when one ships with the app', async () => {
const candidates = commandCandidates();
if (!candidates[0].bundled) {
// Machine has no bin/<platform>/markitdown — assert ordering of the
// remaining candidates instead.
expect(candidates.map((c) => c.command)).toContain('markitdown');
return;
}
const runner = makeRunner({});
const first = candidates[0];
runner.calls.length = 0;
// Stub the bundled path's --version probe
const script = {};
script[`${first.command} --version`] = { stdout: 'markitdown 0.1.7' };
const stub = makeRunner(script);
const resolved = await resolveMarkItDown(stub);
expect(resolved.command).toBe(first.command);
expect(stub.calls[0].cmd).toBe(first.command);
});
it('treats a non-zero probe exit as unavailable', async () => {