# Third-party notices, and the source offer This file names every third-party work shipped inside this app, the licence each one is shipped under, where its licence text lives in this repository, and **where its source can be obtained**. It is the *source offer* that the app's licensing notice links to from the UI (`index.html` → "Third-party notices and source offer"; the assertion is `VAL-DEPLOY-003`, the evidence [`docs/verification-m6-licensing.md`](docs/verification-m6-licensing.md)). ## The app itself `chess-elo-app` — the page, `css/`, `js/`, `worker/` and the tests — is licensed **GPL-3.0-or-later**. The full text is [`LICENSE`](LICENSE) in this repository root, and `package.json` declares `"license": "GPL-3.0-or-later"`. It is free software: you may run it, study it, share it and change it. It comes with **absolutely no warranty**, to the extent the law allows. ## Third-party works shipped in this repository | Work | Version | Licence | Licence text in this repo | Source | |---|---|---|---|---| | **Stockfish** — `vendor/engine/stockfish-19-lite-single.{js,wasm}` (the WebAssembly engine) | 19.0.0, flavour `lite-single` | **GPL-3.0** | `vendor/engine/Copying.txt` — upstream's own file, shipped **beside the wasm** — and `vendor/engine/NOTICE.txt` | (engine) and (the build/wrapper), published as | | **chessground** — `vendor/chessground/` (the board) | `@lichess-org/chessground` 10.4.2 | **GPL-3.0-or-later** | `vendor/chessground/LICENSE` | , published as | | **chess.js** — `vendor/chess.js/` (the rules) | 1.4.0 | **BSD-2-Clause** (permissive, not copyleft) | `vendor/chess.js/LICENSE` | , published as | Checksums of every vendored file, the exact revisions, and the procedure for refreshing them are in [`docs/vendoring.md`](docs/vendoring.md). Nothing else third-party is shipped: there is no framework, no bundler, and no runtime dependency fetched from anywhere. ## The source offer ### This application The app is conveyed as **its own source**. There is no build step and no bundler, and nothing of ours is minified, so the directory the app is served from *is* the Corresponding Source: `index.html`, `css/app.css`, `js/*.js`, `worker/engine-worker.js`, `test/**`, `_headers`, `package.json` and this file are all readable exactly as delivered, from the same place the app is served from. (The one exception is the vendored engine, below: it is compiled object code, and its source is not its own directory.) ### The engine `vendor/engine/stockfish-19-lite-single.wasm` is **compiled object code** — a WebAssembly build of Stockfish 19 in the `lite-single` flavour of the `stockfish` npm package. Its Corresponding Source is: - the engine's own sources, (GPL-3.0; `vendor/engine/Copying.txt` is that licence); - the wrapper and build that produced this exact binary, , published as `stockfish@19.0.0` — . That is the revision pinned in `package.json` and checksummed in [`docs/vendoring.md`](docs/vendoring.md). Both are publicly available at no charge, and neither is modified here: the vendored files are byte-identical to what those projects publish (see the checksums in `docs/vendoring.md`). **Written offer.** If neither of those locations can be reached, a complete machine-readable copy of the engine's Corresponding Source — and of this app's source — will be supplied on request, free of charge, to anyone who received the app. This notice *is* that offer (GNU GPL v3.0 §6): the app is conveyed by whoever serves the site it was downloaded from, and a request made to them is a request made to the conveyor. ### Why the whole app carries the same licence Stockfish is GPL-3.0, and its WebAssembly build is what the page runs to choose its moves, so the combined work is conveyed under the GPL as well. That is why the app is GPL-3.0-or-later rather than something more permissive — a decision recorded in [`PLAN.md`](PLAN.md) §8.5 and accepted deliberately, with its distribution obligations tracked as a release blocker in §9.