DREALT Website - Third Party Notices QRCode for JavaScript Copyright (c) 2009 Kazuhiko Arase URL: http://www.d-project.com/ License: MIT Bundled QR generator used by /useful/toolbox/ was copied from the existing DREALT mobile PWA bundle and is based on qrcode-terminal 0.12.0 vendor/QRCode, with DREALT UTF-8/SVG modifications. The word "QR Code" is a registered trademark of DENSO WAVE INCORPORATED. === v0.6.0 PDF browser tools === PDF-LIB 1.17.1 (MIT License) https://github.com/Hopding/pdf-lib Served locally from /assets/vendor/pdf-lib-1.17.1/. Used for client-side PDF creation, merge, extraction, reordering and rotation. PDF.js 6.3.289 legacy ESM (Apache-2.0 plus bundled permissive licenses) https://github.com/mozilla/pdf.js/releases/tag/v6.3.289 Served locally, unchanged, from /assets/vendor/pdfjs-dist-6.3.289/. Canvas-only rendering with real module Worker, XFA disabled, WASM disabled; no scripting viewer or sandbox loaded. Full LICENSE.txt, BUNDLED-NOTICES.txt, LICENSE_CORE_JS.txt, LICENSE_BROTLI.txt, LICENSE_EMSCRIPTEN.txt, CMap/Foxit and decoder licenses are beside these files. See SOURCE.txt and provenance.json for exact files and hashes. Optional Liberation fonts (GPL plus font exception) are NOT included; system-font behavior is preserved. DREALT does not upload user-selected PDF/image files to its server for these tools. === v0.8.34 card Excel browser tool === SheetJS Community Edition 0.20.3 https://git.sheetjs.com/sheetjs/sheetjs Served locally, unmodified, from /assets/vendor/sheetjs-0.20.3/xlsx-0.20.3.min.js. Apache-2.0; full LICENSE.txt and provenance SOURCE.txt are in that directory. Used by /card/tools/ to read XLSX/XLS. CSV/TSV uses DREALT parsing code. User-selected contact files are not uploaded to the DREALT server by this tool. === v0.8.43 image/generator tools === JSZip 3.10.1 (MIT License) https://github.com/Stuk/jszip Served locally from /assets/vendor/jszip-3.10.1/. Used by /useful/toolbox/image-tools/ to package Instagram split images and favicon output files into ZIP archives inside the browser. JsBarcode 3.11.6 (MIT License) https://github.com/lindell/JsBarcode Served locally from /assets/vendor/jsbarcode-3.11.6/. Used by /useful/toolbox/ to generate CODE128, EAN-13 and CODE39 barcodes inside the browser. User-selected images and entered barcode values are not uploaded to the DREALT server by these tools. === v0.8.67 external dependency hardening === Local library files are unmodified copies of their fixed upstream versions. Full primary licenses are beside each library under assets/vendor/. Additional bundled-component notices are in assets/vendor/component-licenses/. JSZip is used under the MIT option. Component notice version labels identify the notice source, not a reconstruction of the upstream minified bundle build. Pretendard 1.3.9 and SUIT 2.0.5: unmodified WOFF2 files, SIL Open Font License 1.1. Full notices: assets/vendor/pretendard-1.3.9/LICENSE.txt and assets/vendor/suit-2.0.5/LICENSE.txt. SheetJS was upgraded to official CE 0.20.3 in v0.8.68, outside the affected ranges of CVE-2023-30533 and CVE-2024-22363. This is not a guarantee against unknown vulnerabilities. === v0.8.68 license reconciliation === Full QR MIT license, qrcode-terminal Apache license, base64-arraybuffer MIT, tslib copyright, bundled PDF notices and Google Fonts OFL texts have been added. See assets/vendor/component-licenses/ and the BUNDLED-NOTICES.txt files. The shipped JSZip browser bundle includes pako 1.0.5, lie 3.3.0, immediate 3.0.6 and setimmediate 1.0.5. Its stream dependency resolves to a browser stub; readable-stream and related Node-only notices retained from v0.8.67 do not prove those packages are in the shipped bundle. PDF-LIB source map and release lock confirm @pdf-lib/standard-fonts 1.0.0, @pdf-lib/upng 1.0.1, tslib 1.11.1 and pako 1.0.10/1.0.11 source trees. Pako includes zlib-derived code (MIT AND Zlib). Adobe Core 14 font metrics in PDF-LIB: original redistribution terms and metric copyright notices are provided in assets/vendor/pdf-lib-1.17.1/Adobe-AFM-MustRead.html and FONT-METRICS-NOTICES.txt. The upstream compressed-JSON transformation is documented; DREALT did not modify the library. === v0.8.107 OCR language-data staging === Tesseract tessdata_fast language data: English + Korean Upstream: https://github.com/tesseract-ocr/tessdata_fast Build-environment packages: tesseract-ocr-eng 1:4.1.0-2, tesseract-ocr-kor 1:4.1.0-2 License: Apache License 2.0 Served locally from /assets/vendor/tesseract-v08107/lang/ as gzip-compressed traineddata for a future locally hosted browser OCR fallback. The traineddata contents are not edited. Full license, copyright, source/version information and SHA-256 hashes are beside the files. Tesseract.js / tesseract.js-core runtime files are NOT shipped in v0.8.107; no CDN runtime is referenced. === v0.8.111 local browser OCR runtime === Tesseract.js 7.0.0 (Apache License 2.0) https://github.com/naptha/tesseract.js Tesseract.js-core 7.0.0 (Apache License 2.0) https://github.com/naptha/tesseract.js-core Served locally from /assets/vendor/tesseract-v08111/. No runtime CDN is used. Full upstream licenses, minified-bundle license notices, provenance and SHA-256 hashes are shipped beside the files. DREALT does not upload user-selected OCR images to its server. TextDetector is used when available; otherwise the locally hosted Tesseract.js worker/core and previously staged English/Korean traineddata are used. The OCR page alone permits WebAssembly compilation via its page-scoped CSP; the global site CSP is unchanged.