# Third-party notices Regex Tools original source is GPL-3.0-or-later. The production browser bundle contains the compatible runtime components below. Exact dependency resolution is recorded in `package-lock.json`. | Component | Version | Licence | Shipped | Role and source | | -------------------------------- | ------------------------------------------------------------------------ | --------------------------------- | ---------------------------- | -------------------------------------------------------------------------------------------- | | `@add-ideas/toolbox-contract` | 0.2.2 | Apache-2.0 | Runtime | Manifest contract; | | `@add-ideas/toolbox-shell-react` | 0.2.2 | Apache-2.0 | Runtime | Shared shell; same source | | `@eslint-community/regexpp` | 4.12.2 | MIT | Syntax worker | ECMAScript parser; | | CodeMirror packages | state 6.7.1; view 6.43.6; language 6.12.4; commands 6.10.4; search 6.7.1 | MIT | Runtime | Editors; | | `@lezer/highlight` | 1.2.3 | MIT | Runtime | Editor highlighting support; | | React / React DOM | 19.2.7 | MIT | Runtime | User interface; | | `fflate` | 0.8.3 | MIT | Runtime and build dependency | Local corpus-output ZIP and deterministic release ZIP; | | Emscripten generated runtime | 6.0.4 | MIT | Generated WebAssembly glue | PCRE2 module loader/runtime; | | PCRE2 | 10.47 | BSD-3-Clause WITH PCRE2-exception | WebAssembly runtime | Pinned official 8-bit engine; | | Pyodide | 314.0.3 | MPL-2.0 | Python runtime pack | Self-hosted CPython browser runtime; | | CPython | 3.14.2 | PSF-2.0 | Python runtime/stdlib | `re` execution and bundled standard library; | | TeaVM | 0.15.0 | Apache-2.0 | Generated Java engine module | `java.util.regex` class-library implementation; | | Vite | 8.1.5 | MIT | Generated helpers | Production build; | | Rolldown | 1.1.5 | MIT | Generated helpers | Production bundling; | `@add-ideas/toolbox-testkit` 0.2.2 and the other test/build dependencies are development-only and are not part of the static runtime bundle. `recheck` 4.5.0 and `regexp-ast-analysis` 0.7.1 were inspected but deliberately not installed or shipped. PCRE2 source is not vendored; its generated WebAssembly pack is shipped with exact metadata, checksums and licence. Pyodide is pinned as an npm build input and its reviewed self-hosted runtime files are copied into the Python pack. The TeaVM module contains its compiled class library and is explicitly identified as TeaVM, not OpenJDK. Licence texts and copyright notices for the ordinary bundled dependencies are in `LICENSES/`. Each engine pack carries its exact upstream licence/notice files alongside the runtime. The release package additionally carries the exact Vite and Rolldown legal files under `LICENSES/build/`, including Vite's bundled-dependency notices for code emitted by the production build.