MIRAGE THIRD-PARTY NOTICES Generated baseline: 30 July 2026 Mirage includes third-party software. Those components are not covered by the Mirage proprietary license. They remain under the licenses identified below. The required license texts, notices, and attribution links used by release artifacts are in the legal/third_party directory. CLIENT RUNTIME - Electron 41.0.3 — MIT. Electron distributions also carry LICENSE.electron.txt and LICENSES.chromium.html generated by Electron. - better-sqlite3 12.2.0 — MIT. - electron-log 5.4.3 — MIT. - electron-updater 6.8.3 — MIT. - keytar 7.9.0 — MIT. - koffi 2.15.2 — MIT. - argon2 0.31.2 — MIT. - bip39 3.1.0 — ISC. - jsQR 1.4.0 — Apache-2.0. - qrcodejs 1.0.0 — MIT. - Tailwind CSS browser bundle 3.4.x — MIT. - Font Awesome Free 6.5.2 — code: MIT; fonts: SIL OFL 1.1; icons: CC BY 4.0. Font Awesome copyright Fonticons, Inc. - Remaining packaged npm modules are locked by mirage-client/package-lock.json. Their declared license expressions are checked against legal/dependency_licenses.json during every legal gate. Exact deduplicated copyright/license notices for the production dependency tree are in legal/third_party/npm-production-notices.txt. CORE RUNTIME - ngtcp2 1.21.90 — MIT. - BoringSSL — Apache-2.0 and bundled third-party notices. - Argon2 reference implementation 20190702 — Apache-2.0 selected from the upstream CC0-1.0 OR Apache-2.0 choice. - libvpx 1.14.1 — BSD-3-Clause and bundled libwebm, libyuv and x86inc notices. - miniaudio 0.11.25 — MIT-0 selected from the upstream public-domain OR MIT-0 choice. Copyright David Reid. - Boost 1.91.0 — Boost Software License 1.0. - Opus 1.6.1 — BSD-3-Clause-style Opus license; copyright Xiph.Org Foundation and other contributors named in the supplied text. - libdatachannel 0.24.6 and libjuice 1.7.4 — MPL-2.0. Desktop builds only (MIRAGE_ENABLE_WEBRTC); the browser build does not link them. Source Code Form availability is documented in legal/third_party/MPL-2.0-SOURCE.txt. - usrsctp 0.9.5.0 — BSD-3-Clause; plog 1.1.10 — MIT. Linked through libdatachannel; notices in legal/third_party/libdatachannel.txt. - Crashpad is an optional build feature and must not be enabled in a release until its exact resolved version and license files are added to the release inventory. - libva is no longer linked. The Linux VA-API H.264 backend that pulled it in was removed in the media-canonical-core-capture epic phase 0 (Issue #290, 2026-09-09) — its decoder was never implemented and its runtime-test gate was never defined, so nothing regressed by deleting it. A future VA-API return needs a real decoder and runtime-test gate before this notice covers it again. MLS BRIDGE - OpenMLS 0.8.1 and OpenMLS support crates 0.5.0 — MIT. - tls_codec 0.4.x — MIT selected from Apache-2.0 OR MIT. - hpke-rs 0.5.1, hpke-rs-crypto 0.4.0, hpke-rs-libcrux 0.5.1 and hpke-rs-rust-crypto 0.4.0 — MPL-2.0. Source Code Form availability is documented in legal/third_party/MPL-2.0-SOURCE.txt. - cbindgen 0.27.x — MPL-2.0, build-only and not included in runtime artifacts. - Exact deduplicated notices for every registry package in Cargo.lock, including build-only and target-specific crates, are in legal/third_party/cargo-lock-notices.txt. SERVER BINARIES - quic-go 0.49.0 and its linked Go dependencies — permissive MIT/BSD licenses; see mirage-relay/THIRD_PARTY_NOTICES.txt. - go-telegram/bot 1.20.0 — MIT; see mirage-healthbot/THIRD_PARTY_NOTICES.txt. NOTES 1. A component's own copyright and attribution notices remain controlling. 2. License choices above apply only where upstream offered an explicit choice. 3. Build tools not copied into an artifact are recorded as build-only in the machine-readable inventory. 4. The lockfile hashes in legal/dependency_licenses.json make dependency changes fail the gate until this notice and the inventory are reviewed.