Files
amitwh 1e24b52f3e feat(legal): bundle small dependencies, add notices, credits, and GPL source offers
Bundle (v4.7.0):
- MarkItDown frozen to a single ~75MB per-platform binary (PyInstaller via
  npm run bundle:markitdown; ML extras excluded) — built and verified
  locally: HTML/XLSX/PDF conversions pass through the bundled binary, and
  the app resolves bin/linux/markitdown first at runtime
- Packaging copies bundled markitdown alongside Pandoc for win/mac/linux;
  FFmpeg/sharp/KaTeX/fonts were already bundled

Legal artifacts:
- THIRD-PARTY-NOTICES.md: complete license inventory of everything
  distributed (binaries, npm runtime deps, fonts, embedded Python packages)
- SOURCES.md: GPL §3(b) written source offers for Pandoc 3.9.0.2,
  ffmpeg-static's GPL build, and the PyInstaller bootloader; LGPL relinking
  note for libvips
- third-party-licenses/: canonical GPL-2.0, LGPL-2.1, MPL-2.0, Apache-2.0,
  OFL-1.1, PSF-Python texts
- Help > Third-Party Notices & Licenses: in-app viewer for both documents
- README: 'Bundled Dependencies, Legal Notices & Credits' section

Hardening:
- download-tools.js now SHA-256 pins every artifact, verifies after
  download AND against the cache on every run, and hard-fails on mismatch
  (closes security finding D6)

Large tools intentionally not bundled (documented): LibreOffice,
MiKTeX/TeX Live, ImageMagick, PlantUML+JRE, Calibre.

637/637 tests green; lint clean; clean boot; bundled binary verified.
2026-09-05 22:30:54 +05:30

2.8 KiB

Source Code Availability (GPL / LGPL Written Offer)

MarkdownConverter distributes the following binaries built from GPL-licensed software. Per GPL §3(b), this document is the written offer: corresponding source code for the exact versions listed below is available on request for at least three years from each release, and permanently at the referenced public locations. Write to: amit.wh@gmail.com (or open a GitHub issue at https://github.com/amitwh/markdown-converter/issues).

Pandoc — GPL-2.0-or-later

  • Binary shipped: bin/pandoc (v3.9.0.2, official upstream release, unmodified)
  • SHA-256 (linux): 7d124235998ecd3cdd9a463b1e5f6691a178b6461824c29a36170a0882f05597
  • Source: https://github.com/jgm/pandoc/archive/refs/tags/3.9.0.2.tar.gz
  • Pandoc statically links Haskell libraries (GHC ecosystem, mostly BSD-3); their sources are included in the upstream release tarball's dependency set.

FFmpeg — GPL-3.0-or-later (build configuration)

PyInstaller bootloader (inside the bundled MarkItDown binary) — GPL-2.0 with boot-exception

  • Binary shipped: bin/markitdown (MarkItDown 0.1.7 frozen with PyInstaller 6.x)
  • PyInstaller grants a special exception allowing the bootloader to be embedded in non-GPL frozen applications; source anyway: https://github.com/pyinstaller/pyinstaller
  • Everything frozen above the bootloader (markitdown + Python packages + CPython runtime) is permissively licensed (MIT/Apache/BSD/PSF/MPL); see THIRD-PARTY-NOTICES.md §2 for the list.
  • CPython runtime source: https://www.python.org/downloads/source/ (PSF License — not GPL, listed here for completeness).

libvips (via sharp prebuilt binaries) — LGPL-2.1-or-later

  • Shipped as dynamically-loaded libraries from @img/* prebuilts for sharp 0.35.4
  • Source: https://github.com/libvips/libvips · prebuilt bundle sources: https://github.com/lovell/sharp-builds
  • LGPL compliance: the app's own source is public (MIT) and the libraries remain separately replaceable files in the installation directory (node_modules/@img/), satisfying the relinking requirement.

Versions and hashes above correspond to the release this file ships with; update them when bumping bundled tool versions.