Problem
Loop Studio ships third-party code and fonts without their notices. Measured on main d97ae72, with the three builds made with source maps:
| What is shipped |
Count |
Licences |
| npm packages inside the scripts |
28 (one in two versions) |
MIT, ISC, BSD-3-Clause |
| of those, in the PWA build only |
7 (idb and six workbox-*) |
MIT, ISC |
| font packages (IBM Plex Sans, Mono, Sans Thai), 14 files |
3 |
OFL-1.1 |
runtime code the build tools write into the output (vite, rolldown) |
2 |
MIT |
The built files contain no licence text at all: no licence comment in the scripts or the stylesheet, no licence or notice file in any build. MIT, ISC and BSD ask that the copyright notice and the permission text travel with the distribution, and OFL-1.1 asks the same for each copy of a font.
Nothing installed is under GPL, LGPL or AGPL, and no shipped package carries a NOTICE file, so this is a matter of showing notices, not of changing dependencies.
Proposal
The About dialog becomes:
- app name, version, build
- the current copyright line and the link to the source repository
- an Open-source licences button
The button opens a separate scrollable screen that lists, for every shipped item, the name, the version, the copyright holder and the full licence text. It works offline in the web, PWA and portable builds, and it covers fonts, icons, copied code and image assets, not only npm packages.
Separate from #296 and #300. #300 adds no library: it uses Web Crypto only.
Contract
The screen
- Reached from About, in every build flavour, with no network: the notices are part of the build, inlined in the portable file and precached in the PWA.
- One entry per shipped item: name, version, SPDX identifier, copyright lines, and the licence text as published. Licence texts are shown verbatim and are not translated; the surrounding UI strings follow the app language.
- Identical licence texts may be shown once and referenced by several entries, as long as each entry keeps its own copyright lines.
- An item that is not a package (a font, an icon, adapted code, an image) has the same fields plus its source.
The generated file
- The build writes
THIRD_PARTY_NOTICES from what is really bundled: the bundler's module graph and the font files the build emits. It is not written by hand and not derived from the lockfile alone.
- The lockfile is not a substitute. Today it lists six packages that are not shipped (type declarations) and misses seven that are (the service-worker runtime comes from a development dependency).
- Non-package items come from a small registry in the repository that records source, copyright holder and licence for each.
The check fails the build on:
- a dependency whose licence is missing or cannot be identified
- a licence outside the allow-list
- a missing copyright line, or a NOTICE file that exists in the package but is not carried
- a difference between the real bundle and the notice list
- a new external asset with no source and licence recorded in the registry
- a registry entry whose provenance is still marked unresolved
GPL, LGPL and AGPL are never auto-allowed: they stop the build and go to a manual review, because a notice may not be all they ask for.
Decisions
- The pure-JS inflate in
src/model/share.ts — a blocking precondition. Its comment says it is adapted from "tiny inflate (public domain)". The words "public domain" are removed: tinf is under the zlib licence. Structure alone does not settle whether the code derives from tinf or from zlib's contrib/puff/puff.c, so neither is asserted as the origin. Either the code is replaced by an implementation whose origin is clear, or the origin is established from the repository's own record and then the exact zlib notice and an "altered" mark are added to the source. No notice list is generated before this is closed.
- Loop Studio's own licence. About keeps the current copyright line; there is no separate licence link. The project's own licence is undecided and does not block the third-party notices. Opening the source under a licence is a separate decision by the owner.
- Build-tool runtime.
vite and rolldown are in the notice list: their code is in the shipped files and listing them costs two entries.
- The allow-list. Only what is shipped today is auto-allowed:
MIT, ISC, BSD-3-Clause, OFL-1.1. BSD-2-Clause, 0BSD and Apache-2.0 are not allowed in advance. A new licence is reviewed by hand once and then added; Apache-2.0 is added only together with its NOTICE handling.
- The 20 inline SVG drawings. Until the author confirms where they come from they are recorded as
provenance unresolved, not as own work. Drawings the author made, or that were generated for this project, go into the own-work registry. Any that followed an external icon is recorded with its source and licence.
- The analytics script. It is injected by the host on the production origin and is in no build, so it is outside the licence screen. What it collects, whether it sets cookies and where it sends data is a separate privacy and analytics investigation. No wording about it goes into About before that is known.
Inventory (the full table is kept outside the repository until this is implemented)
- Scripts:
react, react-dom, scheduler, use-sync-external-store, @xyflow/react, @xyflow/system, zustand (two versions), classcat, nine d3-* packages, intl-messageformat, three @formatjs/* packages; in the PWA also idb and six workbox-* packages.
- Build-tool runtime: the module-preload helper from
vite and the module wrapper from rolldown.
- Fonts: 14 files from three
@fontsource/ibm-plex-* packages, copyright IBM Corp., no Reserved Font Name declared.
- Own work with no third-party source: the four app icons (drawn by
scripts/gen-icons.mjs), the bundled templates and examples.
- Provenance unresolved: the 20 inline SVG drawings; the pure-JS inflate.
- Twelve distinct licence texts among the packages, about 33 KB before compression.
Implementation gates
Verification
- The list on the screen equals the generated file, and the generated file equals the packages found in the bundle, in each of the three builds.
- Adding a dependency with an unknown licence, a licence outside the four allowed, or a package with a NOTICE file that is not carried fails the build. So does adding a font or an image without a registry entry, and a registry entry marked unresolved.
- The PWA-only packages appear in the PWA build's list and not in the web build's.
vite and rolldown appear in every build's list.
- The screen opens with the network off in the web, PWA and portable builds.
- Keyboard and screen-reader path, forced colours, right-to-left; licence texts keep their left-to-right direction inside a right-to-left UI.
Out of scope
- Choosing Loop Studio's own licence.
- The analytics script and anything else about privacy: a separate investigation.
- Replacing any dependency other than what Decision 1 may require.
- Legal review. This issue records the product structure; it is not legal advice.
Not verified
- The licence metadata inside the
.woff2 files (the three .woff files do carry a copyright line and the OFL address).
- Which original, if any, the inflate was written from.
Problem
Loop Studio ships third-party code and fonts without their notices. Measured on
main d97ae72, with the three builds made with source maps:idband sixworkbox-*)vite,rolldown)The built files contain no licence text at all: no licence comment in the scripts or the stylesheet, no licence or notice file in any build. MIT, ISC and BSD ask that the copyright notice and the permission text travel with the distribution, and OFL-1.1 asks the same for each copy of a font.
Nothing installed is under GPL, LGPL or AGPL, and no shipped package carries a NOTICE file, so this is a matter of showing notices, not of changing dependencies.
Proposal
The About dialog becomes:
The button opens a separate scrollable screen that lists, for every shipped item, the name, the version, the copyright holder and the full licence text. It works offline in the web, PWA and portable builds, and it covers fonts, icons, copied code and image assets, not only npm packages.
Separate from #296 and #300. #300 adds no library: it uses Web Crypto only.
Contract
The screen
The generated file
THIRD_PARTY_NOTICESfrom what is really bundled: the bundler's module graph and the font files the build emits. It is not written by hand and not derived from the lockfile alone.The check fails the build on:
GPL, LGPL and AGPL are never auto-allowed: they stop the build and go to a manual review, because a notice may not be all they ask for.
Decisions
src/model/share.ts— a blocking precondition. Its comment says it is adapted from "tiny inflate (public domain)". The words "public domain" are removed: tinf is under the zlib licence. Structure alone does not settle whether the code derives from tinf or from zlib'scontrib/puff/puff.c, so neither is asserted as the origin. Either the code is replaced by an implementation whose origin is clear, or the origin is established from the repository's own record and then the exact zlib notice and an "altered" mark are added to the source. No notice list is generated before this is closed.viteandrolldownare in the notice list: their code is in the shipped files and listing them costs two entries.MIT,ISC,BSD-3-Clause,OFL-1.1. BSD-2-Clause, 0BSD and Apache-2.0 are not allowed in advance. A new licence is reviewed by hand once and then added; Apache-2.0 is added only together with its NOTICE handling.provenance unresolved, not as own work. Drawings the author made, or that were generated for this project, go into the own-work registry. Any that followed an external icon is recorded with its source and licence.Inventory (the full table is kept outside the repository until this is implemented)
react,react-dom,scheduler,use-sync-external-store,@xyflow/react,@xyflow/system,zustand(two versions),classcat, nined3-*packages,intl-messageformat, three@formatjs/*packages; in the PWA alsoidband sixworkbox-*packages.viteand the module wrapper fromrolldown.@fontsource/ibm-plex-*packages, copyright IBM Corp., no Reserved Font Name declared.scripts/gen-icons.mjs), the bundled templates and examples.Implementation gates
Verification
viteandrolldownappear in every build's list.Out of scope
Not verified
.woff2files (the three.wofffiles do carry a copyright line and the OFL address).