39 lines
2.5 KiB
Markdown
39 lines
2.5 KiB
Markdown
# Sized 2.0 source and dependency notices
|
|
|
|
Sized and the exact public core snapshot retain GPL-3.0-only. The owner confirmed
|
|
that the first-party code was developed by Cole Speelman with Codex assistance.
|
|
The core forge remains private; `crates/sized-core` includes the required source
|
|
at `fb63e96266dcb8ffbca53b73c6c0f738ac3e827d`. `CORE-SNAPSHOT.json` records the
|
|
upstream revision and exact file hashes; `scripts/check-core.py` checks them.
|
|
The snapshot preserves upstream README/provenance as historical source records.
|
|
|
|
Each binary download is accompanied by its exact source archive, including
|
|
Cargo.lock, all registry dependencies, core source, build scripts and original
|
|
notices. Recipients need no forge credentials. The archive is checked with an
|
|
empty Cargo cache and offline mode. Preserve it as long as the binaries remain
|
|
available. Source-only development dependencies retain their original bundled
|
|
notices and package licence metadata in the vendor directory.
|
|
|
|
`scripts/package-notices.py` uses Cargo's normal/build tree for the target and
|
|
locked metadata to produce `DEPENDENCIES.json` and complete `LICENCES.txt`.
|
|
Development-only and inactive optional dependencies are excluded from the binary
|
|
inventory. Missing notices and new licence expressions stop packaging. Where a
|
|
choice is offered, this distribution uses MIT, or Apache-2.0 when MIT is absent;
|
|
all bundled alternative licence texts and copyright notices are preserved.
|
|
Unicode-3.0 notices are retained along with MIT/Apache notices where required.
|
|
No third-party licence is replaced by the first-party licence.
|
|
|
|
The existing `colored` 2.2.0 dependency is MPL-2.0. Its sources and notices are
|
|
unmodified; inspection found no Exhibit B declaration in its source files or
|
|
README. The generic Exhibit B in the MPL licence text itself is not an applied
|
|
declaration. Under MPL section 3.3, colored is additionally distributed under
|
|
GPL-3.0-only as part of this Larger Work. Its original MPL rights and notices
|
|
remain available to recipients. This notice accompanies both binary and source.
|
|
See Mozilla's [MPL/GPL guidance](https://www.mozilla.org/en-US/MPL/2.0/combining-mpl-and-gpl/)
|
|
and [MPL FAQ](https://www.mozilla.org/en-US/MPL/2.0/FAQ/#q14-may-i-combine-mpl-licensed-code-and-lgpl-licensed-code-in-the-same-executable-program).
|
|
|
|
The Mac CLI links Apple's system libraries; Linux dynamically links system
|
|
libraries including glibc. Each target's requirements and linked libraries are
|
|
recorded with its release verification. A new dependency, target or licence
|
|
expression requires reviewing the affected notices before distribution.
|