# Third-party notices — KEC CAD Viewer

Revision 0 · 2026-10-10 · prepared by Codex

This folder includes third-party browser code. Keep these notices, individual copyright/license files, source archives and source-access instructions with any public release. Component licenses are preserved; this document does not replace them or certify legal compliance.

## Principal components

| Component | Version used | Upstream declared license | Role |
|---|---|---|---|
| `@mlightcad/cad-simple-viewer` | 1.7.4 | MIT | CAD document/view/controller runtime |
| `@mlightcad/three-renderer` | 1.7.4 | MIT | CAD scene rendering |
| `@mlightcad/data-model` | 1.15.1 | MIT | CAD data model and DXF parser |
| `@mlightcad/libredwg-converter` | 3.15.1 | GPL-3.0 | DWG conversion adapter and distributed parser worker |
| `@mlightcad/libredwg-web` | 0.7.17 installed; 0.7.14 binary retained inside converter | GPL-3.0 | LibreDWG C/WASM and JavaScript bindings; see exact distinction below |
| `@mlightcad/common`, `geometry-engine`, `graphic-interface` | 1.15.1 / 3.15.1 / 3.15.1 | MIT | Shared CAD primitives |
| `@mlightcad/emf-converter` | 1.15.1 | Apache-2.0 | Embedded metafile conversion; its upstream/modification NOTICE is retained |
| `@mlightcad/mtext-parser`, `mtext-renderer`, `shx-parser` | 1.5.3 / 0.13.2 / 1.4.5 | MIT | Text parsing/rendering |
| Three.js | 0.172.0 | MIT | WebGL rendering |
| `idb` | 8.0.4 | ISC | Browser storage helper |
| `@velipso/polybool`, `tslib` | 1.1.1 / 2.8.1 | 0BSD | Geometry and TypeScript helpers |
| Lodash ES, OpenType.js, iconv-lite, loglevel, uid, csprng, safer-buffer | See `pnpm-lock.yaml` | MIT | Runtime utilities |
| esbuild | 0.25.12 | MIT | Build-time bundler |
| Source Sans 3 regular | Local font file | SIL Open Font License 1.1 | Drawing-text fallback font; license in `assets/fonts/SOURCE_SANS_LICENSE.md` |

The actual unmodified license text files are in [`licenses/`](licenses/). [`licenses/packages.json`](licenses/packages.json) is generated from installed package folders and can include unused/stale package versions. Use `pnpm-lock.yaml`, `package.json`, the build source map and build script to determine what a particular release uses. The source map is useful for tracing bundled code; it is not a substitute for the preferred upstream source trees.

The brand logo/mark and embedded brand-font styling were supplied by the existing KEC tool assets. Their provenance should remain associated with the website's existing brand-asset records; no new third-party brand-font license was inferred from the ability to copy those assets.

## Exact DWG binary/source provenance

The deployed `assets/libredwg-parser-worker.js` and `assets/libredwg-web.wasm` are copied unchanged from **libredwg-converter 3.15.1**. The WASM is **9,496,803 bytes**, SHA-256:

```text
431576487027122a28e5ac99d91fe6366f81ecda743a4676878c75c85fe82c53
```

That binary matches the binary stored in the **libredwg-web v0.7.14 source tree**, commit `1dd682f46339f37b67c5ff1085d10d04a8c16d7e`, and the npm 0.7.14, 0.7.15 and 0.7.16 releases. The installed dependency 0.7.17 contains a different WASM binary and is **not** substituted beside this older prebuilt worker. Source for both v0.7.14 and v0.7.17 is retained because the installed JavaScript dependency and the deployed worker/WASM do not share the same release.

Exact local source archives, npm archives, package registry metadata, provenance attestations, checksums and an automated audit are in [`source-archives/`](source-archives/). The archive source tags match the source commits claimed by the saved npm provenance statements. npm `gitHead` was absent. Attestation contents were inspected, but their cryptographic signature chain was not independently validated. The npm tarball SHA-512 integrity values and worker/WASM byte equality were checked.

The GPL source trees include C/C++/TypeScript, interfaces and build scripts. The `jsmn` git submodule omitted by GitHub's parent tarball is supplied separately at exact commit `85695f3d5903b1cd5b4030efe50db3b4f5f3c928`.

## Publication requirements

Serving the browser JavaScript/WASM gives users copies of the program. This is a GPL-inclusive build, not an MIT-only viewer. Preserve GPL notices, provide accessible source/build instructions with the deployed build, and use a compatible release license for the combined application. See [`SOURCE_OFFER.md`](SOURCE_OFFER.md) for the concrete files and deployment method. A link to an upstream repository's moving default branch is not the source-delivery plan.

The exact applicable text is supplied as [`licenses/GPL-3.0.txt`](licenses/GPL-3.0.txt); the [GNU GPL v3](https://www.gnu.org/licenses/gpl-3.0.html) defines Corresponding Source and its conveyance requirements. These notes describe the implemented packaging evidence and remaining checks; they do not certify that every distribution scenario complies.

## Change history

| Date | Author | Action and reason |
|---|---|---|
| 2026-10-10 | Codex | Retained exact GPL source/package artifacts and licenses. Found converter's bundled WASM differs from installed dependency 0.7.17; matched it to v0.7.14 source-tree binary and retained both source versions to avoid an incorrect provenance claim. |
