# Third-party licences

Xglide's original code and materials are proprietary software owned by
Fernando Balladares Jr. (see [LICENSE](LICENSE)). This document covers the
separate licences of third-party components used by Xglide; it does not grant
an open-source licence to Xglide itself.

Every direct dependency is listed below with the exact version Xglide pins
and the licence declared in its published `Cargo.toml`. Versions are pinned with
`=x.y.z` in the workspace manifest so a build is reproducible and so this table
cannot silently go stale.

## Shared dependencies

| Crate | Version | Licence | Why Xglide uses it |
|-------|---------|---------|------------------------|
| [serde](https://crates.io/crates/serde) | 1.0.228 | MIT OR Apache-2.0 | derive-based serialization for protocol messages, configuration and stored state |
| [serde_json](https://crates.io/crates/serde_json) | 1.0.145 | MIT OR Apache-2.0 | the wire encoding inside each protocol frame, and the on-disk identity/trust files |
| [thiserror](https://crates.io/crates/thiserror) | 2.0.20 | MIT OR Apache-2.0 | error enums in the library crates |
| [anyhow](https://crates.io/crates/anyhow) | 1.0.104 | MIT OR Apache-2.0 | error handling in the desktop and CLI applications |
| [tracing](https://crates.io/crates/tracing) | 0.1.44 | MIT | structured logging |
| [tracing-subscriber](https://crates.io/crates/tracing-subscriber) | 0.3.23 | MIT | log formatting, filtering and optional newline-delimited JSON output |
| [snow](https://crates.io/crates/snow) | 0.9.6 | Apache-2.0 OR MIT | the Noise protocol implementation behind the mutually authenticated, encrypted session |
| [rand](https://crates.io/crates/rand) | 0.10.2 | MIT OR Apache-2.0 | reconnect jitter and one-session QUIC authentication tokens |
| [ctrlc](https://crates.io/crates/ctrlc) | 3.5.2 | MIT OR Apache-2.0 | reliable process termination handling for the advanced CLI |
| [eframe](https://crates.io/crates/eframe) | 0.36.1 | MIT OR Apache-2.0 | the native guided desktop interface on macOS and Windows |
| [egui-phosphor](https://crates.io/crates/egui-phosphor) | 0.14.0 | MIT OR Apache-2.0 | shortcut-action icons; bundles the Phosphor Icons regular font (MIT, © Phosphor Icons — Helena Zhang and Tobias Fried) |
| [whisper-rs](https://crates.io/crates/whisper-rs) | 0.16.0 | Unlicense | Rust bindings to whisper.cpp for offline dictation |
| [whisper-rs-sys](https://crates.io/crates/whisper-rs-sys) | 0.15.0 (vendored in `third_party/`, build script patched for cross-compiling) | Unlicense; bundles [whisper.cpp and ggml](https://github.com/ggml-org/whisper.cpp) under MIT (© The ggml authors) | the speech recognition engine itself |
| [cpal](https://crates.io/crates/cpal) | 0.18.2 | Apache-2.0 | microphone capture while the Dictate key is held |
| [ureq](https://crates.io/crates/ureq) | 3.4.2 | MIT OR Apache-2.0 | the one-time, user-approved speech model download (with webpki-roots, CDLA-Permissive-2.0) |
| [ab_glyph](https://crates.io/crates/ab_glyph) | 0.2.32 | Apache-2.0 | drawing text in the dictation indicator |
| [ring](https://crates.io/crates/ring) | 0.17.14 | Apache-2.0 AND ISC | Ed25519 signature checks for license keys and the update feed (already used through QUIC/TLS) |
| [flate2](https://crates.io/crates/flate2) | 1.1.9 | MIT OR Apache-2.0 | compressing the diagnostics zip |
| [rustybuzz](https://crates.io/crates/rustybuzz) | 0.20.1 | MIT | shaping Arabic and Hindi words (and every other script) for the live dictation preview |
| [epaint_default_fonts](https://crates.io/crates/epaint_default_fonts) | 0.36.1 | (MIT OR Apache-2.0) AND OFL-1.1 AND Ubuntu-font-1.0 | the Ubuntu font used for the indicator's text (already shipped through eframe) |
| [sha2](https://crates.io/crates/sha2) | 0.10.9 | MIT OR Apache-2.0 | clipboard content hashing, device-id derivation, short-auth-code derivation |
| [hex](https://crates.io/crates/hex) | 0.4.3 | MIT OR Apache-2.0 | hex encoding of public keys and hashes |
| [toml](https://crates.io/crates/toml) | 1.1.4 | MIT OR Apache-2.0 | the human-editable configuration file |
| [clap](https://crates.io/crates/clap) | 4.5.41 | MIT OR Apache-2.0 | the command line interface (built without its ANSI colour stack) |
| [dirs](https://crates.io/crates/dirs) | 5.0.1 | MIT OR Apache-2.0 | locating the per-user configuration directory on each platform |
| [arboard](https://crates.io/crates/arboard) | 3.6.1 | MIT OR Apache-2.0 | native clipboard access (built without image support) |
| [bytes](https://crates.io/crates/bytes) | 1.12.1 | MIT | fixed-size pointer datagrams passed to Quinn without extra copies |
| [quinn](https://crates.io/crates/quinn) | 0.11.11 | MIT OR Apache-2.0 | encrypted, authenticated, unreliable QUIC pointer datagrams |
| [rcgen](https://crates.io/crates/rcgen) | 0.14.9 | MIT OR Apache-2.0 | ephemeral per-session QUIC certificates exchanged through Noise |
| [rustls](https://crates.io/crates/rustls) | 0.23.43 | Apache-2.0 OR ISC OR MIT | pinned TLS 1.3 authentication beneath QUIC |
| [tokio](https://crates.io/crates/tokio) | 1.53.1 | MIT | isolated runtime for the QUIC endpoint and 120 Hz motion cadence |
| [embed-resource](https://crates.io/crates/embed-resource) | 3.0.11 | MIT | build-time embedding of Xglide's icon and version information in the Windows executable |

## Windows-only

| Crate | Version | Licence | Why Xglide uses it |
|-------|---------|---------|------------------------|
| [windows-sys](https://crates.io/crates/windows-sys) | 0.59.0 | MIT OR Apache-2.0 | `SetWindowsHookExW`, `SendInput`, `SetCursorPos`, DPI awareness — the Win32 capture and injection surface |

## macOS-only

| Crate | Version | Licence | Why Xglide uses it |
|-------|---------|---------|------------------------|
| [core-graphics](https://crates.io/crates/core-graphics) | 0.24.0 | MIT OR Apache-2.0 | `CGEventTap` capture, `CGEvent` injection, display geometry (with the `highsierra` feature for `CGEventCreateScrollWheelEvent2`) |
| [core-foundation](https://crates.io/crates/core-foundation) | 0.10.0 | MIT OR Apache-2.0 | the run loop and Mach port plumbing an event tap needs |
| [block2](https://crates.io/crates/block2) | 0.6.2 | MIT | safe Objective-C block support for macOS power notifications |
| [objc2](https://crates.io/crates/objc2) | 0.6.4 | MIT | typed Objective-C runtime bindings |
| [objc2-foundation](https://crates.io/crates/objc2-foundation) | 0.3.2 | MIT | Foundation notification objects and queues |
| [objc2-app-kit](https://crates.io/crates/objc2-app-kit) | 0.3.2 | Zlib OR Apache-2.0 OR MIT | AppKit workspace sleep and shutdown notifications |
| [objc2-core-graphics](https://crates.io/crates/objc2-core-graphics) | 0.3.2 | Zlib OR Apache-2.0 OR MIT | typed conversion between Quartz and AppKit media-key events |

## Notes

* Every licence above is a permissive one (MIT, Apache-2.0, Zlib, Unlicense,
  CDLA-Permissive-2.0, or a choice among those licences), plus the OFL-1.1 and
  Ubuntu Font Licence for bundled fonts, which permit bundling with software.
* The live dictation preview draws Chinese, Japanese, Hindi and Arabic with
  fonts that come with macOS or Windows (for example Hiragino Sans GB,
  Kohinoor, Geeza Pro, Microsoft YaHei, Nirmala UI, Segoe UI). They are read
  from the operating system at run time and are not bundled or redistributed.
* The Windows package includes whisper.cpp's ggml backend libraries
  (`ggml*.dll`, `whisper.dll`, MIT), among them the optional Vulkan GPU
  backend. It was built against the Khronos Vulkan headers (Apache-2.0 / MIT)
  with shaderc's `glslc` (Apache-2.0) compiling ggml's own shaders; neither
  tool is shipped. `third_party/vulkan-import/vulkan-1.lib` is an import
  library generated from those headers (see its README); the real
  `vulkan-1.dll` comes from the PC's graphics driver.
* The Windows installer is built with NSIS (Nullsoft Scriptable Install
  System); its installer stub is distributed under the zlib/libpng licence
  (with bzip2 and CPL portions as described in the NSIS licence), which
  allows commercial use.
* The cat animation on the setup welcome screen was generated by the owner
  with Higgsfield and cut out for Xglide; its use is subject to Higgsfield's
  terms for generated content.
* The pixel-art monitors, cat, mouse and keyboard in the interface are
  original artwork made for Xglide.
* The Whisper speech models are not bundled. Xglide downloads the official
  whisper.cpp conversion of OpenAI's Whisper weights (MIT) only after the user
  approves it, and verifies the published SHA-256. There is **no copyleft dependency** in the tree,
  direct or transitive. Xglide distributions must preserve the notices and
  other obligations that apply to these components.
* Transitive dependencies are not listed individually; they are pinned by
  `Cargo.lock`. To produce a complete audited list:

  ```bash
  cargo install cargo-license
  cargo license --avoid-build-deps
  ```

  and to check for advisories:

  ```bash
  cargo install cargo-audit
  cargo audit
  ```

* No code was copied from Synergy, Barrier, Input Leap or Deskflow. Those
  projects are GPL-licensed and were consulted only for what users expect a
  software KVM to do, never for implementation. CI enforces that their names do
  not appear in the source except in provenance notes like this one.
