@@ -0,0 +1,41 @@
|
||||
# Third-party notices for the ProxyWarden offline bundle
|
||||
|
||||
This file records the third-party runtime payload planned for the ProxyWarden
|
||||
`1.2.0` Windows x64 installer. It is an engineering inventory, not legal advice
|
||||
or a completed distribution approval. Exact bundled hashes and sizes are owned
|
||||
by `src-tauri/bundled/components/catalog.json`.
|
||||
|
||||
## Managed runtime assets
|
||||
|
||||
| Component | Pinned asset and official source | License copy | Update trust and distribution note |
|
||||
| ---------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| ProxiFyre | `2.4.0`, [`ProxiFyre-v2.4.0-x64-signed.zip`](https://github.com/wiresock/proxifyre/releases/download/v2.4.0/ProxiFyre-v2.4.0-x64-signed.zip); [commit-pinned source archive](https://github.com/wiresock/proxifyre/archive/dd1512840e1e3bc596b06b80eda4e2dcd6a9c9ed.tar.gz) | `AGPL-3.0-only`; `src-tauri/bundled/components/proxifyre/LICENSE` | Origin is accepted only with the official GitHub release digest and the Authenticode publisher `The Anti-Cloud Corporation` on the inner executable. Before release, the project/release owner must record the corresponding-source or written-source-offer decision and approve redistribution. |
|
||||
| Windows Packet Filter | release `3.6.2`, product `3.6.2.1`, [`Windows.Packet.Filter.3.6.2.1.x64.msi`](https://github.com/wiresock/ndisapi/releases/download/v3.6.2/Windows.Packet.Filter.3.6.2.1.x64.msi); [commit-pinned source archive](https://github.com/wiresock/ndisapi/archive/417b8734e844083a10236387fba705d94a2d6bc9.tar.gz) | `MIT`; `src-tauri/bundled/components/windows-packet-filter/LICENSE` | Origin is accepted only with the official GitHub release digest and MSI Authenticode publisher `The Anti-Cloud Corporation`. The MSI is a shared system dependency; its presence alone does not prove ProxyWarden ownership and does not authorize uninstall. |
|
||||
| Microsoft Visual C++ x64 Redistributable | file/product version `14.51.36247.0`, [`VC_redist.x64.exe`](https://aka.ms/vs/18/release/14.51.36247/VC_redist.x64.exe) | `LicenseRef-Microsoft-Visual-Cpp-v14-Redistributable-2026`; [`src-tauri/bundled/components/vc-runtime/LICENSE.docx`](https://visualstudio.microsoft.com/wp-content/uploads/2025/10/Visual-C-V14-License-Redistributable_and_Runtime_ENU.docx) | Build-time refresh only. The pinned file must retain a valid Microsoft Corporation Authenticode signature; no in-app remote update is offered. This is proprietary Microsoft software, so the project/release owner must approve its redistribution under the bundled official terms before release. |
|
||||
| sing-box | `1.13.19`, [`sing-box-1.13.19-windows-amd64.zip`](https://github.com/SagerNet/sing-box/releases/download/v1.13.19/sing-box-1.13.19-windows-amd64.zip); [commit-pinned source archive](https://github.com/SagerNet/sing-box/archive/b5ebaa1fc0f2b94256180b95468e73ef53caa27d.tar.gz) | `LicenseRef-Sing-Box-Project` (GPL-3.0-or-later plus the upstream name restriction); `src-tauri/bundled/components/sing-box/LICENSE` | Origin is accepted only with the official GitHub release digest. Redistribution must preserve the GPL terms and the upstream name restriction. Before release, the project/release owner must record the corresponding-source/source-offer decision and approve the notice text. |
|
||||
| WinSW | `2.12.0`, [`WinSW.NET461.exe`](https://github.com/winsw/winsw/releases/download/v2.12.0/WinSW.NET461.exe); [commit-pinned source archive](https://github.com/winsw/winsw/archive/eef5bade59fca0254e387ac73ed7625ba6aa7147.tar.gz) | `MIT`; `src-tauri/bundled/components/winsw/LICENSE.txt` | The selected binary is IL-only AnyCPU and is used on the x64 target with supported .NET Framework 4.8/4.8.1. Upstream supplies neither an independent digest nor an Authenticode signature for this asset, so it is `bundled-only/no-independent-proof`: remote update is disabled and a newer bundle is required to replace it. |
|
||||
|
||||
## WebView2 prerequisite
|
||||
|
||||
Microsoft Edge WebView2 Runtime is not part of the managed component catalog and
|
||||
does not receive an in-app update action. Tauri packages the Microsoft WebView2
|
||||
Evergreen Standalone Offline Installer into the NSIS installer through
|
||||
`bundle.windows.webviewInstallMode.type = "offlineInstaller"`. Microsoft/Windows
|
||||
owns later runtime servicing. The release evidence must prove that the offline
|
||||
payload is present and that a clean Windows 10/11 x64 machine can install and
|
||||
start ProxyWarden without network access. See the official
|
||||
[WebView2 distribution page](https://developer.microsoft.com/en-us/microsoft-edge/webview2/).
|
||||
|
||||
## Release compliance gate
|
||||
|
||||
No license or distribution sign-off is claimed by this file. Before tagging or
|
||||
publishing `1.2.0`, the project/release owner must record in
|
||||
`docs/goals/production-ready-offline-migration/EVIDENCE.md`:
|
||||
|
||||
- the exact installer composition and catalog hashes;
|
||||
- the reviewed license copies and source links;
|
||||
- the corresponding-source/source-offer decisions for ProxiFyre and sing-box;
|
||||
- the Microsoft Visual C++ and WebView2 redistribution decision;
|
||||
- reviewer name/date and explicit approval.
|
||||
|
||||
Until that record exists, license/distribution remains a release blocker.
|
||||
Reference in New Issue
Block a user