# Third-party notices Regex Tools original source is GPL-3.0-or-later. The production browser bundle contains the compatible runtime components below. Exact dependency resolution is recorded in `package-lock.json`. | Component | Version | Licence | Shipped | Role and source | | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------- | -------------------------------------------------------------------------------------------------------------------------- | | `@add-ideas/toolbox-contract` | 0.2.3 | Apache-2.0 | Runtime | Manifest contract; | | `@add-ideas/toolbox-shell-react` | 0.2.3 | Apache-2.0 | Runtime | Shared shell; same source | | `@eslint-community/regexpp` | 4.12.2 | MIT | Syntax worker | ECMAScript parser; | | CodeMirror packages | state 6.7.1; view 6.43.6; language 6.12.4; commands 6.10.4; search 6.7.1 | MIT | Runtime | Editors; | | `@lezer/highlight` | 1.2.3 | MIT | Runtime | Editor highlighting support; | | React / React DOM | 19.2.7 | MIT | Runtime | User interface; | | `fflate` | 0.8.3 | MIT | Runtime and build dependency | Local corpus-output ZIP and deterministic release ZIP; | | Emscripten generated runtime | 6.0.4 | MIT OR NCSA | Generated WebAssembly glue | Standalone PCRE2 and C++ module toolchain; | | PCRE2 | 10.47 | BSD-3-Clause WITH PCRE2-exception | WebAssembly runtime | Pinned official 8-bit engine; | | PHP | 8.5.8 | PHP License 4 (BSD-3-Clause) | PHP runtime | `preg_*` execution; v4 elected through the earlier licence's later-version option; | | PCRE2 in PHP | 10.44 | PCRE2 BSD licence | PHP runtime | Engine embedded in the PHP build; distinct from standalone PCRE2 10.47 | | WordPress Playground `@php-wasm` | 3.1.46 | GPL-2.0-or-later | PHP runtime/host packages | `web-8-5`, `universal` and pinned support packages; | | Zend Engine and PHP bundled code | PHP 8.5.8 | Zend Engine License 2.00; MIT; public-domain/CC0 and component terms | PHP WebAssembly | Exact Zend, official `README.REDIST.BINS`, CLI HTTP parser and hash-code notices travel with the pack | | PHP-vendored support code | bcmath snapshot; timelib 2022.15; tzdata 2026.1; libmagic snapshot; Lexbor 2.7.0; libmbfl 1.3.2; uriparser 1.0.2; libavifinfo snapshot | LGPL-2.0-or-later; MIT; public domain; BSD; Apache-2.0; LGPL-2.1; BSD and AOM patent terms | PHP WebAssembly | Exact php-src 8.5.8 component paths and legal routes are recorded in the native inventory | | PHP data/archive/image libraries | zlib 1.2.13; libzip 1.9.2; libxml2 2.9.10; SQLite 3.51.0; libgd 2.3.3 | Zlib; BSD-3-Clause; MIT; public domain; BSD-like | PHP WebAssembly | Exact primary archive hashes/commits and separately pinned legal files | | PHP image codec libraries | libjpeg-turbo 3.0.3; libpng 1.6.39; libwebp/libsharpyuv pinned commit; libavif 1.3.0; libaom 3.12.1 with libyuv snapshot | IJG/BSD/Zlib; Libpng; BSD/patent grants; BSD-2-Clause/AOM patent terms | PHP WebAssembly | libavif's local AOM 3.12.1 is linked; the adjacent standalone AOM 3.13.1 recipe is not | | PHP network/text libraries | OpenSSL 1.1.1t; curl 7.69.1; libiconv 1.17; Oniguruma 6.9.10 | OpenSSL/SSLeay; curl; LGPL-2.1-or-later; BSD-2-Clause | PHP WebAssembly | Oniguruma's exact archive/header and bounded upstream source interval are recorded without claiming an unpinned build HEAD | | Emscripten system code in PHP | main linker 4.0.19; musl, compiler-rt, libc++, libc++abi and dlmalloc snapshots | MIT/NCSA; MIT/component terms; Apache-2.0 WITH LLVM-exception plus legacy terms; public domain | PHP WebAssembly | Exact Emscripten commit and independently pinned component legal files | | WebPerl / Perl | 0.09-beta / 5.28.1 | GPL-1.0-or-later OR Artistic-1.0-Perl | Legacy Perl runtime | Unmodified, explicitly legacy prebuilt engine; | | Emscripten used by WebPerl | 1.38.28 | MIT OR NCSA | Legacy Perl loader/runtime | Exact upstream-generated asset toolchain | | Pyodide | 314.0.3 | MPL-2.0 | Python runtime pack | Self-hosted CPython browser runtime; | | Error Stack Parser / StackFrame | 2.1.4 / 1.3.4 vendored ports | MIT | Python loader | Exact upstream tags/archives and Pyodide port-source hashes are recorded | | CPython | 3.14.2 | Python-2.0 and bundled terms | Python runtime/stdlib | `re` execution and bundled standard library; | | Expat / libmpdec / HACL* | 2.7.3 / 2.5.1 / pinned HACL commit | MIT / BSD-2-Clause / MIT | Python base WebAssembly | CPython-vendored static components; exact preferred HACL source and generated-source route are recorded | | libffi / Hiwire | pinned commit / 1.0.1 | MIT / MPL-2.0 | Python base WebAssembly | Pyodide's exact `_ctypes` and JavaScript-reference bridge inputs | | XZ liblzma / Zstandard | 5.2.2 / 1.5.7 | Public-domain fallback grant / BSD-3-Clause | Python base WebAssembly | Static compression modules from Pyodide's pinned primary source archives | | SQLite | 3.39.0 | Public-domain dedication/blessing | Python base WebAssembly | Static `_sqlite3` from the pinned official amalgamation archive | | bzip2 / zlib | 1.0.6 / 1.3.1 | bzip2-1.0.6 / Zlib | Python base WebAssembly | Exact Emscripten 5.0.3 ports selected by Pyodide | | Emscripten used by Pyodide | 5.0.3 plus five pinned Pyodide patches | MIT OR NCSA | Python loader/WebAssembly | Exact toolchain source tree, patches and recipe hashes | | Emscripten system runtime | snapshot in 5.0.3 | MIT and Apache-2.0 WITH LLVM-exception | Python base WebAssembly | musl, compiler-rt, libc++, libc++abi, libunwind and dlmalloc conservative notice closure | | MiniLZ4 | snapshot in Emscripten 5.0.3 | MIT | Python loader | Selected by Pyodide's `-sLZ4=1`; its source notice is restored outside the minified loader | | ruby.wasm / CRuby | 2.9.3-2.9.4 / 4.0.0 | MIT host; Ruby/BSD and bundled terms | Ruby runtime | Minimal CRuby WebAssembly pack and complete upstream NOTICE; | | TeaVM | 0.15.0 | Apache-2.0 | Generated Java engine module | `java.util.regex` class-library implementation; | | Emscripten system code in C++ | Emscripten 6.0.4; musl 1.2.6; compiler-rt 22.1.8; libc++/libc++abi 21.1.8; emmalloc snapshot | MIT/NCSA; MIT/component terms; Apache-2.0 WITH LLVM-exception plus legacy terms | C++ WebAssembly | Exact traced link and preferred-source/legal closure; libunwind 22.1.8 is retained as an audited non-selection | | Go | 1.26.5 | BSD-3-Clause | Go runtime/engine | Standard-library `regexp` and official `js/wasm` support; | | Rust `regex` / toolchain | regex 1.13.1 / rustc 1.97.1 | MIT OR Apache-2.0 plus component terms | Rust runtime/engine | Exact Cargo graph, standard library and wasm-bindgen notices travel with the pack | | .NET | runtime 10.0.10 / SDK 10.0.302 | MIT plus bundled component terms | .NET runtime/engine | Browser-WASM `System.Text.RegularExpressions`; | | Vite | 8.1.5 | MIT | Generated helpers | Production build; | | Rolldown | 1.1.5 | MIT | Generated helpers | Production bundling; | The application icon adapts and recolours the MIT-licensed [OOjs UI regular-expression-progressive icon](https://commons.wikimedia.org/wiki/File:OOjs_UI_icon_regular-expression-progressive.svg) inside original Regex Tools file artwork. Its copyright notice, source and licence are preserved in `LICENSES/OOjs-UI-icon-MIT.txt`. `@add-ideas/toolbox-testkit` 0.2.3 and the other test/build dependencies are development-only and are not part of the static runtime bundle. The PHP pack's `native-components.json` is scoped to the exact `php.wasm` SHA-256 and routes every linked component above to one or more of 42 independently verifier-pinned licence, notice or patent files. It separately records and tests the false-positive/unshipped detections for GMP, libsodium, tidy, ICU/intl, FreeType, ImageMagick/imagick and AOM 3.13.1. `recheck` 4.5.0 and `regexp-ast-analysis` 0.7.1 were inspected but deliberately not installed or shipped. PCRE2 source is not vendored; its generated WebAssembly pack is shipped with exact metadata, checksums and licence. Pyodide, PHP WebAssembly and ruby.wasm are pinned npm build inputs whose reviewed self-hosted files are copied into engine packs. The Python pack's `SOURCE-MANIFEST.json` distinguishes the optional wheel catalogue from files actually shipped, inventories the complete linked base runtime and provides exact preferred-form/archive/Git/patch identities. The TeaVM module contains its compiled class library and is explicitly identified as TeaVM, not OpenJDK; the Scala compatibility profile shares it and ships no Scala runtime. Licence texts and copyright notices for the ordinary bundled dependencies are in `LICENSES/`. Each engine pack carries its exact upstream licence/notice files alongside the runtime. The release package additionally carries the exact Vite and Rolldown legal files under `LICENSES/build/`, including Vite's bundled-dependency notices for code emitted by the production build.