2 Commits
Author SHA1 Message Date
amitwh 1e24b52f3e feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0):
- MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via
  npm run bundle:markitdown; ML extras excluded) — built and verified
  locally: HTML/XLSX/PDF conversions pass through the bundled binary, and
  the app resolves bin/linux/markitdown first at runtime
- Packaging copies bundled markitdown alongside Pandoc for win/mac/linux;
  FFmpeg/sharp/KaTeX/fonts were already bundled

Legal artifacts:
- THIRD-PARTY-NOTICES.md: complete license inventory of everything
  distributed (binaries, npm runtime deps, fonts, embedded Python packages)
- SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2,
  ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking
  note for libvips
- third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0,
  OFL-1.1, PSF-Python texts
- Help > Third-Party Notices & Licenses: in-app viewer for both documents
- README: 'Bundled Dependencies, Legal Notices & Credits' section

Hardening:
- download-tools.js now SHA-256 pins every artifact, verifies after
  download AND against the cache on every run, and hard-fails on mismatch
  (closes security finding D6)

Large tools intentionally not bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre.

637/637 tests green; lint clean; clean boot; bundled binary verified.
2026-09-05 22:30:54 +05:30
amitwh 58bd19ecd1 feat(import): embed Microsoft MarkItDown for any-file → Markdown import
- File → Import with MarkItDown (Any Format)…: PDF, DOCX, PPTX, XLSX,
  Outlook .msg/.eml, EPUB, images, CSV/JSON/XML, ZIP (audio/OCR via the
  [all] extras) — verified live against HTML, XLSX (our own exporter's
  output), and PDF fixtures
- Command auto-resolution with caching: markitdown binary → python -m
  markitdown → python3 -m markitdown
- SEC-1 argv discipline (execFile only, user paths never through a shell),
  50MB cap, 120s timeout, sanitized errors that surface markitdown's own
  "pip install 'markitdown[pdf]'" hints for missing format extras
- Output lands next to the source as <name>.md (numeric suffix, never
  overwrites) and opens in a new tab; markitdown:available/convert IPC
  allowlisted for renderer flows
- Help → Dependencies lists MarkItDown; README/UPDATES updated (v4.6.1)

12 new tests (629 green); lint clean; clean app boot
2026-09-05 22:10:35 +05:30