2.5 KiB
Sized 2.0 source and dependency notices
Sized and the exact public core snapshot retain GPL-3.0-only. The owner confirmed
that the first-party code was developed by Cole Speelman with Codex assistance.
The core forge remains private; crates/sized-core includes the required source
at fb63e96266dcb8ffbca53b73c6c0f738ac3e827d. CORE-SNAPSHOT.json records the
upstream revision and exact file hashes; scripts/check-core.py checks them.
The snapshot preserves upstream README/provenance as historical source records.
Each binary download is accompanied by its exact source archive, including Cargo.lock, all registry dependencies, core source, build scripts and original notices. Recipients need no forge credentials. The archive is checked with an empty Cargo cache and offline mode. Preserve it as long as the binaries remain available. Source-only development dependencies retain their original bundled notices and package licence metadata in the vendor directory.
scripts/package-notices.py uses Cargo's normal/build tree for the target and
locked metadata to produce DEPENDENCIES.json and complete LICENCES.txt.
Development-only and inactive optional dependencies are excluded from the binary
inventory. Missing notices and new licence expressions stop packaging. Where a
choice is offered, this distribution uses MIT, or Apache-2.0 when MIT is absent;
all bundled alternative licence texts and copyright notices are preserved.
Unicode-3.0 notices are retained along with MIT/Apache notices where required.
No third-party licence is replaced by the first-party licence.
The existing colored 2.2.0 dependency is MPL-2.0. Its sources and notices are
unmodified; inspection found no Exhibit B declaration in its source files or
README. The generic Exhibit B in the MPL licence text itself is not an applied
declaration. Under MPL section 3.3, colored is additionally distributed under
GPL-3.0-only as part of this Larger Work. Its original MPL rights and notices
remain available to recipients. This notice accompanies both binary and source.
See Mozilla's MPL/GPL guidance
and MPL FAQ.
The Mac CLI links Apple's system libraries; Linux dynamically links system libraries including glibc. Each target's requirements and linked libraries are recorded with its release verification. A new dependency, target or licence expression requires reviewing the affected notices before distribution.