Files
regex-tools/THIRD_PARTY_NOTICES.md

19 KiB

Third-party notices

Regex Tools original source is GPL-3.0-or-later. The production browser bundle contains the compatible runtime components below. Exact dependency resolution is recorded in package-lock.json.

Component Version Licence Shipped Role and source
@add-ideas/toolbox-contract 0.2.2 Apache-2.0 Runtime Manifest contract; https://git.add-ideas.de/zemion/toolbox-sdk
@add-ideas/toolbox-shell-react 0.2.2 Apache-2.0 Runtime Shared shell; same source
@eslint-community/regexpp 4.12.2 MIT Syntax worker ECMAScript parser; https://github.com/eslint-community/regexpp
CodeMirror packages state 6.7.1; view 6.43.6; language 6.12.4; commands 6.10.4; search 6.7.1 MIT Runtime Editors; https://github.com/codemirror
@lezer/highlight 1.2.3 MIT Runtime Editor highlighting support; https://github.com/lezer-parser/highlight
React / React DOM 19.2.7 MIT Runtime User interface; https://github.com/facebook/react
fflate 0.8.3 MIT Runtime and build dependency Local corpus-output ZIP and deterministic release ZIP; https://github.com/101arrowz/fflate
Emscripten generated runtime 6.0.4 MIT OR NCSA Generated WebAssembly glue Standalone PCRE2 and C++ module toolchain; https://github.com/emscripten-core/emscripten
PCRE2 10.47 BSD-3-Clause WITH PCRE2-exception WebAssembly runtime Pinned official 8-bit engine; https://github.com/PCRE2Project/pcre2
PHP 8.5.8 PHP License 4 (BSD-3-Clause) PHP runtime preg_* execution; v4 elected through the earlier licence's later-version option; https://www.php.net/
PCRE2 in PHP 10.44 PCRE2 BSD licence PHP runtime Engine embedded in the PHP build; distinct from standalone PCRE2 10.47
WordPress Playground @php-wasm 3.1.46 GPL-2.0-or-later PHP runtime/host packages web-8-5, universal and pinned support packages; https://github.com/WordPress/wordpress-playground
Zend Engine and PHP bundled code PHP 8.5.8 Zend Engine License 2.00; MIT; public-domain/CC0 and component terms PHP WebAssembly Exact Zend, official README.REDIST.BINS, CLI HTTP parser and hash-code notices travel with the pack
PHP-vendored support code bcmath snapshot; timelib 2022.15; tzdata 2026.1; libmagic snapshot; Lexbor 2.7.0; libmbfl 1.3.2; uriparser 1.0.2; libavifinfo snapshot LGPL-2.0-or-later; MIT; public domain; BSD; Apache-2.0; LGPL-2.1; BSD and AOM patent terms PHP WebAssembly Exact php-src 8.5.8 component paths and legal routes are recorded in the native inventory
PHP data/archive/image libraries zlib 1.2.13; libzip 1.9.2; libxml2 2.9.10; SQLite 3.51.0; libgd 2.3.3 Zlib; BSD-3-Clause; MIT; public domain; BSD-like PHP WebAssembly Exact primary archive hashes/commits and separately pinned legal files
PHP image codec libraries libjpeg-turbo 3.0.3; libpng 1.6.39; libwebp/libsharpyuv pinned commit; libavif 1.3.0; libaom 3.12.1 with libyuv snapshot IJG/BSD/Zlib; Libpng; BSD/patent grants; BSD-2-Clause/AOM patent terms PHP WebAssembly libavif's local AOM 3.12.1 is linked; the adjacent standalone AOM 3.13.1 recipe is not
PHP network/text libraries OpenSSL 1.1.1t; curl 7.69.1; libiconv 1.17; Oniguruma 6.9.10 OpenSSL/SSLeay; curl; LGPL-2.1-or-later; BSD-2-Clause PHP WebAssembly Oniguruma's exact archive/header and bounded upstream source interval are recorded without claiming an unpinned build HEAD
Emscripten system code in PHP main linker 4.0.19; musl, compiler-rt, libc++, libc++abi and dlmalloc snapshots MIT/NCSA; MIT/component terms; Apache-2.0 WITH LLVM-exception plus legacy terms; public domain PHP WebAssembly Exact Emscripten commit and independently pinned component legal files
WebPerl / Perl 0.09-beta / 5.28.1 GPL-1.0-or-later OR Artistic-1.0-Perl Legacy Perl runtime Unmodified, explicitly legacy prebuilt engine; https://github.com/haukex/webperl
Emscripten used by WebPerl 1.38.28 MIT OR NCSA Legacy Perl loader/runtime Exact upstream-generated asset toolchain
Pyodide 314.0.3 MPL-2.0 Python runtime pack Self-hosted CPython browser runtime; https://github.com/pyodide/pyodide
Error Stack Parser / StackFrame 2.1.4 / 1.3.4 vendored ports MIT Python loader Exact upstream tags/archives and Pyodide port-source hashes are recorded
CPython 3.14.2 Python-2.0 and bundled terms Python runtime/stdlib re execution and bundled standard library; https://github.com/python/cpython
Expat / libmpdec / HACL* 2.7.3 / 2.5.1 / pinned HACL commit MIT / BSD-2-Clause / MIT Python base WebAssembly CPython-vendored static components; exact preferred HACL source and generated-source route are recorded
libffi / Hiwire pinned commit / 1.0.1 MIT / MPL-2.0 Python base WebAssembly Pyodide's exact _ctypes and JavaScript-reference bridge inputs
XZ liblzma / Zstandard 5.2.2 / 1.5.7 Public-domain fallback grant / BSD-3-Clause Python base WebAssembly Static compression modules from Pyodide's pinned primary source archives
SQLite 3.39.0 Public-domain dedication/blessing Python base WebAssembly Static _sqlite3 from the pinned official amalgamation archive
bzip2 / zlib 1.0.6 / 1.3.1 bzip2-1.0.6 / Zlib Python base WebAssembly Exact Emscripten 5.0.3 ports selected by Pyodide
Emscripten used by Pyodide 5.0.3 plus five pinned Pyodide patches MIT OR NCSA Python loader/WebAssembly Exact toolchain source tree, patches and recipe hashes
Emscripten system runtime snapshot in 5.0.3 MIT and Apache-2.0 WITH LLVM-exception Python base WebAssembly musl, compiler-rt, libc++, libc++abi, libunwind and dlmalloc conservative notice closure
MiniLZ4 snapshot in Emscripten 5.0.3 MIT Python loader Selected by Pyodide's -sLZ4=1; its source notice is restored outside the minified loader
ruby.wasm / CRuby 2.9.3-2.9.4 / 4.0.0 MIT host; Ruby/BSD and bundled terms Ruby runtime Minimal CRuby WebAssembly pack and complete upstream NOTICE; https://github.com/ruby/ruby.wasm
TeaVM 0.15.0 Apache-2.0 Generated Java engine module java.util.regex class-library implementation; https://github.com/konsoletyper/teavm
Emscripten system code in C++ Emscripten 6.0.4; musl 1.2.6; compiler-rt 22.1.8; libc++/libc++abi 21.1.8; emmalloc snapshot MIT/NCSA; MIT/component terms; Apache-2.0 WITH LLVM-exception plus legacy terms C++ WebAssembly Exact traced link and preferred-source/legal closure; libunwind 22.1.8 is retained as an audited non-selection
Go 1.26.5 BSD-3-Clause Go runtime/engine Standard-library regexp and official js/wasm support; https://go.dev/
Rust regex / toolchain regex 1.13.1 / rustc 1.97.1 MIT OR Apache-2.0 plus component terms Rust runtime/engine Exact Cargo graph, standard library and wasm-bindgen notices travel with the pack
.NET runtime 10.0.10 / SDK 10.0.302 MIT plus bundled component terms .NET runtime/engine Browser-WASM System.Text.RegularExpressions; https://github.com/dotnet/runtime
Vite 8.1.5 MIT Generated helpers Production build; https://github.com/vitejs/vite
Rolldown 1.1.5 MIT Generated helpers Production bundling; https://github.com/rolldown/rolldown

@add-ideas/toolbox-testkit 0.2.2 and the other test/build dependencies are development-only and are not part of the static runtime bundle.

The PHP pack's native-components.json is scoped to the exact php.wasm SHA-256 and routes every linked component above to one or more of 42 independently verifier-pinned licence, notice or patent files. It separately records and tests the false-positive/unshipped detections for GMP, libsodium, tidy, ICU/intl, FreeType, ImageMagick/imagick and AOM 3.13.1.

recheck 4.5.0 and regexp-ast-analysis 0.7.1 were inspected but deliberately not installed or shipped. PCRE2 source is not vendored; its generated WebAssembly pack is shipped with exact metadata, checksums and licence. Pyodide, PHP WebAssembly and ruby.wasm are pinned npm build inputs whose reviewed self-hosted files are copied into engine packs. The Python pack's SOURCE-MANIFEST.json distinguishes the optional wheel catalogue from files actually shipped, inventories the complete linked base runtime and provides exact preferred-form/archive/Git/patch identities. The TeaVM module contains its compiled class library and is explicitly identified as TeaVM, not OpenJDK; the Scala compatibility profile shares it and ships no Scala runtime.

Licence texts and copyright notices for the ordinary bundled dependencies are in LICENSES/. Each engine pack carries its exact upstream licence/notice files alongside the runtime. The release package additionally carries the exact Vite and Rolldown legal files under LICENSES/build/, including Vite's bundled-dependency notices for code emitted by the production build.