Source THIRD_PARTY_NOTICES.md · 1de96aa

Third-party notices

Libris’s own source code is proprietary (see LICENSE). That does not replace the licenses of the components Libris uses, which keep their own terms and their own notices.

Dependencies

  • Interface: React, React Flow (@xyflow/react), Vite, TypeScript and the other packages listed in frontend/package-lock.json (MIT, ISC and BSD-3-Clause). The Schibsted Grotesk, EB Garamond and Source Serif 4 typefaces (@fontsource-variable/schibsted-grotesk, @fontsource-variable/eb-garamond, @fontsource-variable/source-serif-4) are distributed under the SIL Open Font License 1.1.
  • Server: FastAPI, Uvicorn, Pydantic, SQLAlchemy, Alembic, psycopg, HTTPX, cryptography, lxml and the other packages listed in backend/requirements.lock. EbookLib, which is AGPL, only builds the EPUBs the tests read: it is a test dependency and is not shipped in the image. ldap3, used for LDAP and Active Directory sign-in, is distributed under the GNU LGPL v3, like psycopg and psycopg-binary (the PostgreSQL driver): they are installed unmodified as separate Python packages, and can be replaced by another build of the same version. certifi (the CA bundle) is distributed under the Mozilla Public License 2.0, unmodified.
  • Database: the official PostgreSQL image.
  • EPUBCheck: downloaded from the official W3C release during the image build, with pinned security updates applied by scripts/harden_epubcheck.py. It keeps its own license (BSD-3-Clause) and notices, and so do the libraries it ships in /opt/epubcheck-*/lib, among them Saxon-HE (Mozilla Public License 2.0), Jing (BSD-3-Clause), ICU4J (Unicode License), Xerces, Guava and Apache Commons (Apache License 2.0).
  • Operating system of the images: the Debian 12 packages of the base image, among them the OpenJDK runtime EPUBCheck needs (GNU GPL v2 with the Classpath Exception). They are separate programs, installed unmodified from Debian; their licenses are in /usr/share/doc/*/copyright inside the image, and their sources are published by Debian (https://sources.debian.org, https://snapshot.debian.org).
  • Codex bridge (optional): installs the upstream @openai/codex package (Apache License 2.0) on Node.js (MIT), and the Python packages listed in codex_bridge/requirements.lock. Its license, and the terms of the OpenAI or ChatGPT account you connect, are separate from Libris.

The installed packages’ own license files are authoritative. In the images: the Python packages keep theirs in their *.dist-info directories, the interface’s in /app/frontend/dist/THIRD_PARTY_LICENSES.txt, the Debian packages’ in /usr/share/doc/*/copyright, EPUBCheck’s in /opt/epubcheck-*, and the Codex bridge’s in /opt/codex/CODEX_LICENSE and /opt/codex/CODEX_NOTICE (Codex, Apache-2.0) and /opt/codex/NODE_LICENSE (Node.js).

Project assets

The Libris logos in frontend/public/assets/ were supplied by the project owner. The name and logo do not allow anyone to imply official endorsement. Screenshot text and test fixtures were written for this project; they contain no commercial book.

Not part of this repository

Translations, imported books, model weights, provider credentials and data stored in an external OpenViking instance are not distributed with Libris.