MPL 2.0 COVERED SOFTWARE — SOURCE CODE AVAILABILITY Baseline: 30 July 2026 Mirage MLS may compile the following unmodified crates into an executable-form artifact: - hpke-rs 0.5.1 https://crates.io/api/v1/crates/hpke-rs/0.5.1/download - hpke-rs-crypto 0.4.0 https://crates.io/api/v1/crates/hpke-rs-crypto/0.4.0/download - hpke-rs-libcrux 0.5.1 https://crates.io/api/v1/crates/hpke-rs-libcrux/0.5.1/download - hpke-rs-rust-crypto 0.4.0 https://crates.io/api/v1/crates/hpke-rs-rust-crypto/0.4.0/download These crates identify their license as Mozilla Public License 2.0. Their complete license is supplied in MPL-2.0.txt. Exact registry package versions and notices are also indexed in cargo-lock-notices.txt. Mirage does not patch these registry crates. The URLs above provide their corresponding Source Code Form at no charge. If an upstream URL becomes unavailable while a Mirage executable containing that version remains distributed, contact prorok1015@gmail.com for a copy. The release maintainer must retain the exact `.crate` archives and make them available for at least the period required by MPL 2.0. Only the MPL-covered crate files are offered under MPL 2.0. The surrounding Mirage Larger Work remains under its own license as permitted by MPL 2.0. Mirage core desktop builds may compile the following unmodified sources into the mirage library. They are pinned as git submodules of mirage-core/third_party/libdatachannel: - libdatachannel 0.24.6, commit 6b1e2e620f1e37f0eafeee702eaea0043cb305fd https://github.com/paullouisageneau/libdatachannel/tree/6b1e2e620f1e37f0eafeee702eaea0043cb305fd - libjuice 1.7.4, commit b89c792e3612faf2f12cf35bcc56857313a06be3 https://github.com/paullouisageneau/libjuice/tree/b89c792e3612faf2f12cf35bcc56857313a06be3 These projects identify their license as Mozilla Public License 2.0. Mirage does not patch them; the URLs above provide their corresponding Source Code Form at no charge, and the same availability, retention and Larger Work terms stated above for the crates apply to them. The browser build of the core does not include them. cbindgen 0.27.0 also uses MPL 2.0 but is a build tool and is not copied into Mirage runtime artifacts: https://crates.io/api/v1/crates/cbindgen/0.27.0/download