# Third-Party Notices for Substrike > **Status update, 2026-09-20 (later than the inventory below):** (a) `extract-embedding.exe` was rebuilt without the GPL > eSpeak NG library (0 markers; the original finding is kept in section 1.4 for the record) and the build now refuses to ship > it; (b) every sidecar download and model is pinned to an exact version with a SHA-256 check (`scripts/sidecar-versions.json`, > `docs/sidecar-pinning.md`); (c) an About & licences screen now ships with the app. Still open: FFmpeg's GPL source offer > (decided: our own pinned build with the matching source hosted next to each release; not built yet) and the items in > section 6 not marked resolved. Where a later section contradicts this note, this note is newer. > > **Packaging changes, later on 2026-09-20 (v1.0 first-run work):** (d) the small Whisper **tiny.en** speech model > (`ggml-tiny.en.bin`, 77,704,715 bytes, MIT) is now bundled INSIDE the installer, as a Tauri resource, for the > "try it on 15 seconds of your own clip" preview (section 2); (e) **`vcomp140.dll`** (Microsoft's Visual C++ OpenMP > runtime, needed by `ggml-base.dll` and every `ggml-cpu-*.dll`) is now bundled, copied unmodified from the Visual Studio > redistributable folder (section 1.2a); (f) the installer no longer contains `SDL2.dll`, `parakeet.dll`, the top-level > `llama.dll`, or the seven llama.cpp command-line-tool DLLs (`llama-cli/bench/batched-bench/completion/fit-params/perplexity/quantize-impl.dll`): > nothing loads them (proved with `dumpbin /dependents` and by real runs; the derivation is recorded as `shipDllsNote` in `scripts/sidecar-versions.json`), and > `tauri.windows.conf.json` now lists the shipped files one by one instead of `binaries/*.dll`. Statements below that say those > DLLs ship describe the 0.2.13 installer and are kept for the record. The **Microsoft Visual C++ runtime** itself > (`MSVCP140.dll`, `MSVCP140_1.dll`, `VCRUNTIME140.dll`, `VCRUNTIME140_1.dll`) was NOT bundled up to 0.3.3; from the release after 0.3.3 it is > bundled app-local, next to `Substrike.exe` and again in `binaries/llama/` (section 1.6). > > **Licence work, 2026-09-25:** (g) the complete attribution text for every > Rust crate compiled into the app (324) and every npm package in the frontend bundle (11), with the licence and notice > files each publishes, plus the bundled programs and all six models, is now generated by `scripts/gen-notices.py` into > `src-tauri/resources/licenses/THIRD-PARTY-LICENSES.txt`; `tests/notices.test.ts` fails when `Cargo.lock` or > `package-lock.json` changes without a regeneration. The installer ships a `licenses/` folder (that file, this file, > `SOURCE-OFFER.txt`, the licence text for the FFmpeg build we ship), and the About dialog shows all of them offline. > Sections 3.1, 3.2 and 4 below are the 2026-09-20 hand snapshot, kept for the record; the generated file is current. > (h) Every bundled file now needs a licence entry in `scripts/bundle-licences.json`; `tests/bundle-licences.test.ts` > refuses copyleft entries other than ffmpeg, and `scripts/check-bundle-gpl.py` byte-scans every bundled file in the > release build. (i) FFmpeg: the pinned binary was Gyan's 9.0.1 essentials build (SHA-256 pinned, no longer an > unversioned download); the source offer is on `site/source.html` and `SOURCE-OFFER.txt`, and > `scripts/archive-copyleft-sources.py` builds the per-release source archive. > > **Owner decision, 2026-09-28 (newest note, it overrides anything below):** minimise patent and licence liability for > a paid app sold in the US and Australia, so no software encoder for a patent-pool codec. Substrike's published FFmpeg > is build s2, **LGPL-2.1-or-later** as configured (no `--enable-gpl`, no `--enable-version3`; `ffmpeg -L` prints "GNU > Lesser General Public License ... version 2.1 of the License, or (at your option) any later version"). An earlier > internal test build s1 (GPL-3.0-or-later, with libx264, section 1.1a) was never distributed to anyone outside the > owner's own PC and has been withdrawn; its public release was deleted 2026-09-28. s2 has no libx264 and no native > FFmpeg `aac` encoder: video is encoded only by GPU vendor encoders (NVIDIA NVENC, AMD AMF, Intel QuickSync) or > Windows Media Foundation (`h264_mf` etc.), and AAC audio only by Windows Media Foundation (`aac_mf`); Opus is now > available via `libopus` (royalty-free, BSD-3-Clause). Full detail: section 1.1 below. The installer's `licenses/` > folder ships `LGPL-2.1.txt`; the retired `GPL-3.0.txt`, kept only because s1 was built and never used, is at > `_shelf/GPL-3.0.txt.retired-2026-09-28`. Substrike 0.3.3 (`com.substrike.app`, Windows x64 NSIS installer). Inventory produced 2026-09-20, refreshed 2026-09-25 for the "What ships" file list, the FFmpeg/whisper.cpp/llama.cpp sections below it and the NeMo TitaNet-small licence (section 2); everything else keeps its original 2026-09-20 evidence dates unless a later status note above says otherwise. This file lists the third-party software, models and assets that ship inside the Substrike installer or that the app downloads on the user's behalf. It is an inventory and attribution file, NOT legal advice, and it is not yet a finished shipping document: see `docs/license-compliance.md` for what still has to happen before a commercial release (notably the GPL source-distribution work for ffmpeg, and one unexpected GPL component described in section 1.4). ## How this file was produced, and what "verified" means Every fact below is tagged with how it was established: - **repo** = read from a file in this repository (script, config, Cargo.lock, package-lock.json). - **binary** = obtained by running or byte-scanning the actual binary in `src-tauri/binaries/` (read-only, from the main working tree; hashes are SHA-256 of those exact files) or by listing the built 0.2.13 installer with 7-Zip. - **upstream** = a page or file on the project's own site/GitHub/Hugging Face page, fetched on 2026-09-20 (URL given). - **UNVERIFIED** = not confirmed from the repo, a binary or an authoritative upstream page. Most of these are licence names taken from general knowledge about a well-known project; treat them as leads to confirm, not facts. Generation of the machine-made lists: - Rust crates: `cargo metadata --locked --offline --format-version 1 --filter-platform x86_64-pc-windows-msvc` in `src-tauri/`, then walked the resolved dependency graph from the root package following only normal (non-dev, non-build) edges. That yields the 313 crates that are compiled into the Windows binary (section 3). The 22 build-only crates (build scripts, code generators) are listed separately and are not shipped. Licence strings are the `license` field in each crate's own `Cargo.toml` (the SPDX expression the crate author declared); they were not independently checked against each crate's LICENSE files. Crates that only appear for Linux/macOS/Android targets in `Cargo.lock` are excluded by the platform filter. - JS packages: parsed `package-lock.json` (lockfileVersion 3) with a small script; the `license` field is the one npm records. `dev: true` entries are build tooling and are not shipped. (`npm ls` was not used because `node_modules` is not installed in this checkout; the lockfile carries the same information.) - The binary facts (versions, configure lines, hashes) were captured from the files in the main tree's `src-tauri/binaries/` as of the last local `get-sidecars` run (ffmpeg downloaded 2026-08-12, whisper.cpp DLLs 2026-08-20, llama.cpp 2026-08-25). A fresh CI build will download different files (see "unpinned downloads" in `docs/license-compliance.md`), so re-run this audit against the actual release artifacts. What ships: the installer's file list (7-Zip listing of `Substrike_0.3.3_x64-setup.exe`, **binary**, the 21:12 2026-09-25 build) is: `clipcaption.exe` (the app itself; the executable kept its pre-rename internal name at that build, see `docs/license-compliance.md` item 15 - **RESOLVED 2026-09-28**: `tauri.conf.json` now sets `mainBinaryName: "substrike"`, so a build made after that date ships `substrike.exe` instead), `ffmpeg.exe`, `ffprobe.exe`, `extract-embedding.exe`, `whisper-cli.exe`, `whisper.dll`, `ggml*.dll` (11), `sherpa-onnx-offline-speaker-diarization.exe`, three bundled `.onnx` models (`sherpa-embedding.onnx`, `sherpa-pyannote-segmentation.onnx`, `sherpa-audio-tagging.onnx`), the bundled `ggml-tiny.en.bin` speech model, the Microsoft Visual C++ runtime DLLs (`msvcp140.dll`, `msvcp140_1.dll`, `vcruntime140.dll`, `vcruntime140_1.dll`, `vcomp140.dll`), `binaries\llama\` (`llama-server.exe` plus 26 DLLs, including its own copy of the four Visual C++ runtime DLLs), a `fonts\` folder (five caption-preset font families, each with its own `OFL.txt`), a `licenses\` folder (`LGPL-2.1.txt`, `SOURCE-OFFER.txt`, `THIRD-PARTY-LICENSES.txt`, `THIRD-PARTY-NOTICES.md` - this file - and `inventory.json`), and `uninstall.exe`. (The listing also has a `$PLUGINSDIR\` group of NSIS installer-stub files - `NSISdl.dll`, `StartMenu.dll`, `System.dll`, `nsDialogs.dll`, `nsis_tauri_utils.dll` and two bitmaps - which are the NSIS installer's own scaffolding, run once during setup and not copied into the app's install directory; see section 1.6 for NSIS's licence.) This replaces the 0.2.13 audit below, which found `clipcaption.exe`, `ffmpeg.exe`, `ffprobe.exe`, `whisper-cli.exe`, `whisper.dll`, `ggml*.dll` (11), `SDL2.dll`, `llama.dll`, `parakeet.dll`, `extract-embedding.exe`, `sherpa-onnx-offline-speaker-diarization.exe`, two bundled `.onnx` models, `binaries\llama\` (`llama-server.exe` plus 29 DLLs) and `uninstall.exe`, with no licence or notice files and no bundled speech model; those statements are section 1's history, not 0.3.3's shipping list. The 0.3.3 installer now carries a `licenses\` folder offline (the About & licences screen shows the same files, section 6 item 6) and four bundled models instead of none: the two speaker-diarization `.onnx` files, the Whisper tiny.en preview model, and the zipformer audio-tagging model behind the experimental laughter pass (section 2). The recommended larger speech, alignment and cleanup models are still downloaded at run time. --- ## 1. Binaries / sidecars ### 1.1 FFmpeg (ffmpeg.exe and ffprobe.exe) - THE LGPL COMPONENT Substrike's own build, build revision s2, shipped from 2026-09-28. Owner decision 2026-09-28: minimise patent and licence liability for a paid app sold in the US and Australia, so no software encoder for a patent-pool codec. s2 drops `--enable-gpl` and `--enable-version3` and removes libx264; it is licensed under the **LGPL-2.1-or-later**, not the GPL. Full design, inventory and verification: `docs/ffmpeg-build.md`. An earlier internal test build s1 (GPL-3.0-or-later, with libx264), never distributed, is noted in 1.1a below; the stopgap Gyan Doshi build before that is 1.1b. Neither is installed by a fresh `get-sidecars.ps1` run any more. | | | |---|---| | Component | `ffmpeg.exe` and `ffprobe.exe`, `9.0.1-substrike2` (build revision s2) | | Licence | **LGPL-2.1-or-later** (**binary**: `ffmpeg -L` prints "GNU Lesser General Public License ... version 2.1 of the License, or (at your option) any later version"; configure has no `--enable-gpl`, no `--enable-version3`, no `--enable-nonfree`) | | Built by | `ffmpeg-build/build.sh` in GitHub Actions (`.github/workflows/build-ffmpeg.yml`, run 36370104475), cross-compiled on Ubuntu 24.04 with mingw-w64 GCC 13.2.0 (**repo**) | | Published | Published at https://github.com/Chronox2290/substrike-releases/releases/tag/ffmpeg-9.0.1-s2 (public repo `Chronox2290/substrike-releases`): `substrike-ffmpeg-9.0.1-s2-win64.zip` (28,295,780 bytes, SHA-256 `c84f36965e8a756ba0ca0da4e8e96c036331dbbf5d1d158ff9b4ddc2f5c8e53e`), `substrike-ffmpeg-9.0.1-s2-source.tar` (73,021,440 bytes, SHA-256 `31d58736ef02437514a773cd6fa80a2954f8153f2d260cdc23508e454f48252f`), `SHA256SUMS.txt`, `BUILDINFO.txt`. This is the only FFmpeg build Substrike has ever distributed or will distribute; the earlier s1 test build was never published to users and its release has been deleted (section 1.1a). | | SHA-256 (files) | ffmpeg.exe (33,443,328 bytes) `43551b8136537a62a54da51cbf2c947e6bd9752687562e039f7b10007fed810d`; ffprobe.exe (33,241,088 bytes) `d3c070196209b00ffa605f4c5871b7dc02aeed4c97491a3c17b378001744f276` | | Corresponding source | `substrike-ffmpeg-9.0.1-s2-source.tar`: every source tarball below byte for byte, the build scripts, configure output and the mingw-w64 runtime source. Published beside the zip. | Compiled in (**repo**: `ffmpeg-build/sources.lock`, every tarball SHA-256 pinned; licences as each project declares them, not re-read file by file): | Library | Version | Licence | |---|---|---| | FFmpeg | 9.0.1 as configured for s2 | LGPL-2.1-or-later as configured | | dav1d | 1.5.4 | BSD-2-Clause | | Opus | 1.6.1 (**new in s2**) | BSD-3-Clause | | libass | 0.17.5 | ISC | | FreeType | 2.14.3 | FTL (FreeType Licence) | | FriBidi | 1.0.17 | LGPL-2.1-or-later | | HarfBuzz | 14.5.0 | MIT (Old MIT) | | zlib | 1.3.2 | Zlib | | nv-codec-headers | 12.1.14.1 | MIT | | AMF headers | 1.5.2 | MIT | | libvpl | 2.17.0 | MIT | | mingw-w64 C runtime and winpthreads | 11.0.1 (Ubuntu 11.0.1-3build1) | ZPL-2.1, MIT and public domain parts | | libgcc, libstdc++ | GCC 13.2.0 (Ubuntu 13.2.0-6ubuntu1+26.1) | GPL-3.0-or-later with the GCC Runtime Library Exception | x264 is **removed** in s2 (it was GPL-only and is why the withdrawn s1 test build was GPL-3.0-or-later, see 1.1a). Encoders compiled in: h264/hevc/av1 via nvenc/amf/qsv/mf, `aac_mf`, `libopus`, `pcm_s16le`, `pcm_f32le`, `mjpeg`, `png`, `gif`, `rawvideo`, `wrapped_avframe`, `ass`, `ssa`, `srt`, `subrip`, `mov_text`, `webvtt`. There is no software (CPU) H.264/HEVC/AV1 encoder and no native FFmpeg `aac` encoder in this build: video is encoded only by a GPU vendor encoder (NVIDIA NVENC, AMD AMF, Intel QuickSync) or Windows Media Foundation, and AAC audio only by Windows Media Foundation (`aac_mf`). **LGPL obligations and how they are met:** the licence text ships (`LGPL-2.1.txt`, this folder); the complete corresponding source is published beside the binary (a static build, so all of it), with the written offer (`SOURCE-OFFER.txt`) as backup, kept for at least three years. Relinking (LGPL-2.1 section 6): Substrike never links FFmpeg, it runs `ffmpeg.exe` and `ffprobe.exe` as separate programs, so a user can rebuild them from the source archive with any modification and replace the two shipped files; no Substrike object files are needed. ### 1.1a FFmpeg s1 build (internal test build, withdrawn) An earlier internal build, revision s1 (`9.0.1-substrike1`, GPL-3.0-or-later as configured, with `libx264` compiled in), was built 2026-09-28 but never distributed to anyone outside the owner's own PC. Its public release has been deleted and is withdrawn. Build s2 (section 1.1) is the only FFmpeg build Substrike has ever distributed or will distribute. ### 1.1b Gyan Doshi FFmpeg build (history, shipped until 2026-09-28) The stopgap this replaced. Never distributed on its own past 2026-09-28: its statically linked library sources were not all known, so complete corresponding source could not be assembled for it (`scripts/bundle-licences.json` `sourceCompleteNote`, historical value). Kept here only as a record of what earlier pre-release builds shipped. | Field | Value | |---|---| | Component | FFmpeg `ffmpeg.exe` and `ffprobe.exe` (two separate ~100 MB executables) | | Version | `9.0.1-essentials_build-www.gyan.dev` (**binary**: `ffmpeg -version`; libavcodec 63.1.101, libavformat 63.1.101, libavfilter 12.1.101). Built with gcc 16.1.0 (MSYS2, Rev2). | | Licence | **GPL-3.0-or-later** (SPDX `GPL-3.0-or-later`). **binary**: `ffmpeg -L` prints "GNU General Public License ... version 3 or later"; the configure line has `--enable-gpl --enable-version3`. **upstream**: gyan.dev states "All builds are 64-bit, static and licensed as GPLv3". Not `--enable-nonfree` (**binary**: not in the configure line), so it is redistributable under the GPL. | | Copyright | "Copyright (c) 2000-2026 the FFmpeg developers" (**binary**: banner) | | Upstream | https://ffmpeg.org/ (source), https://github.com/FFmpeg/FFmpeg ; build by Gyan Doshi: https://www.gyan.dev/ffmpeg/builds/ | | Where Substrike gets it | `scripts/get-sidecars.ps1` downloads `https://www.gyan.dev/ffmpeg/builds/ffmpeg-release-essentials.zip` (**repo**). This URL is an unversioned "latest" link: it currently serves a newer release than the 9.0.1 binary in this tree (**upstream**: the source link on the gyan page is FFmpeg commit `946fcce07b`, whose message is "Update for 9.0.2"). | | Linking | Statically linked build (`--enable-static`, **binary**): all external libraries below are compiled into the single `ffmpeg.exe` / `ffprobe.exe`. No FFmpeg or codec DLLs are shipped. | | SHA-256 (local files) | ffmpeg.exe `72a489eccd008c2ec2c0a5856c5c75bc3d8bbfa90166c4566865c246445e6aa3`; ffprobe.exe `19202b23c0043f15ad1b7bce2344f406fd52bd6efd8f995ce02e7392a1cec52f` | | How Substrike uses it | Runs it as a **separate process** by command line (`src-tauri/src/sidecar.rs` builds a `std::process::Command`, **repo**): probe, extract 16 kHz audio, burn ASS subtitles (`subtitles=` filter, libass), cut/concat, encode H.264 (`libx264` for the CPU/software path and for two-pass "fit under 10 MB" mode; `h264_nvenc` / `h264_amf` / `h264_qsv` when a GPU encoder works), AAC audio, reframe (`libx264`). | Exact configure line of the shipped binary (**binary**, `ffmpeg -version`): ``` --enable-gpl --enable-version3 --enable-static --disable-w32threads --disable-autodetect --enable-cairo --enable-fontconfig --enable-iconv --enable-gnutls --enable-libxml2 --enable-gmp --enable-bzlib --enable-lzma --enable-zlib --enable-libsrt --enable-libssh --enable-libzmq --enable-avisynth --enable-sdl2 --enable-libwebp --enable-libx264 --enable-libx265 --enable-libxvid --enable-libaom --enable-libopenjpeg --enable-libvpx --enable-mediafoundation --enable-libass --enable-libfreetype --enable-libfribidi --enable-libharfbuzz --enable-libvidstab --enable-libvmaf --enable-libzimg --enable-amf --enable-cuda-llvm --enable-cuvid --enable-dxva2 --enable-d3d11va --enable-d3d12va --enable-ffnvcodec --enable-libvpl --enable-nvdec --enable-nvenc --enable-vaapi --enable-openal --enable-libgme --enable-libopenmpt --enable-libopencore-amrwb --enable-libmp3lame --enable-libtheora --enable-libvo-amrwbenc --enable-libgsm --enable-libopencore-amrnb --enable-libopus --enable-libspeex --enable-libvorbis --enable-librubberband ``` Libraries compiled into that binary, and their own licences. Only the GPL-forcing ones are confirmed from FFmpeg's own `LICENSE.md` (**upstream**, https://github.com/FFmpeg/FFmpeg/blob/master/LICENSE.md, which lists libx264, libx265, libxvid, libvidstab, librubberband and avisynth as GPL-only and gmp / Apache-2.0 libraries such as VMAF as requiring `--enable-version3`). The rest are from general knowledge and are **UNVERIFIED for this specific build**: | Library | Licence | Status | |---|---|---| | libx264 (H.264 encoder) | GPL-2.0-or-later (also sold under a separate commercial licence by its owners) | GPL-only confirmed (upstream FFmpeg LICENSE.md); dual-licence offer UNVERIFIED | | libx265 (HEVC encoder) | GPL-2.0-or-later (commercial licence also offered by MulticoreWare) | GPL-only confirmed; dual-licence UNVERIFIED | | libxvid (Xvid MPEG-4) | GPL-2.0-or-later | confirmed GPL-only | | libvidstab | GPL-2.0-or-later | confirmed GPL-only | | librubberband | GPL-2.0-or-later (commercial licence offered separately) | confirmed GPL-only; dual-licence UNVERIFIED | | avisynth (AviSynth+ interface) | GPL-2.0-or-later (with a linking exception upstream) | FFmpeg requires `--enable-gpl` for it; exception wording UNVERIFIED | | gmp | LGPL-3.0-or-later OR GPL-2.0-or-later | v3 requirement confirmed; SPDX UNVERIFIED | | libvmaf, libopencore-amrnb/-amrwb, libvo-amrwbenc | BSD-2-Clause-Patent; Apache-2.0; Apache-2.0 | UNVERIFIED (Apache-2.0 libs need `--enable-version3`, confirmed) | | GnuTLS (`GnuTLS 3.6.16` string in the binary), libssh, libiconv, libmp3lame, libgme, OpenAL Soft, cairo, fribidi, libsrt, libzmq | LGPL-2.1-or-later / LGPL-2.0-or-later / MPL-2.0 / (libzmq: LGPL-3.0-or-later with static-linking exception or MPL-2.0 depending on version) | UNVERIFIED | | libass, libfreetype, libharfbuzz, fontconfig, libxml2, zlib, bzip2, xz/liblzma | ISC; FTL or GPL-2.0 (dual); MIT; MIT-style; MIT; zlib; BSD-style; 0BSD/public domain | UNVERIFIED | | libaom, libvpx, libopus, libvorbis, libtheora, libspeex, libwebp, libopenjpeg, libopenmpt, libzimg, libgsm, SDL2, libvpl / AMF / ffnvcodec headers | BSD-2/3-Clause (libaom also has a patent grant); BSD-3-Clause; BSD-3-Clause; BSD-3-Clause; BSD-3-Clause; BSD-3-Clause; BSD-3-Clause; BSD-2-Clause; BSD-3-Clause; WTFPL; permissive (TU Berlin); zlib; MIT | UNVERIFIED | Important build-scope note: `ffprobe.exe` is a second full static copy of the same libraries and is GPL-3.0-or-later on exactly the same footing. Substrike does not need `ffplay`-style SDL output or most of the listed libraries; the app only uses libx264, libass (+freetype/fribidi/harfbuzz/ fontconfig), the native AAC encoder, the hardware-encoder wrappers, and ordinary decoders. ### 1.2 whisper.cpp (whisper-cli.exe, whisper.dll, ggml*.dll; the zip's parakeet.dll and SDL2.dll are no longer shipped) | Field | Value | |---|---| | Component | `whisper-cli.exe` (479,232 bytes) + `whisper.dll`, `ggml.dll`, `ggml-base.dll`, 9 `ggml-cpu-*.dll`, all from the whisper.cpp Windows x64 release zip, plus `vcomp140.dll` (section 1.2a). The zip's `parakeet.dll` and `SDL2.dll` are no longer installed or bundled (**repo**: `shipDlls` in `scripts/sidecar-versions.json`). | | Version | whisper.cpp **1.9.3** (**binary**: the string `1.9.3` is present in `whisper.dll`; the files are dated 2026-08-20). `get-sidecars.ps1` fetches the *latest* GitHub release with no pin (**repo**); GitHub now lists v1.9.4 as newer (**upstream** releases page), so a fresh CI build will not match this. | | Licence | **MIT** (SPDX `MIT`) - **upstream**: https://raw.githubusercontent.com/ggml-org/whisper.cpp/master/LICENSE, "Copyright (c) 2023-2026 The ggml authors". ggml (the tensor library inside `ggml*.dll`) is under the same repository licence. | | Upstream | https://github.com/ggml-org/whisper.cpp | | How Substrike uses it | Separate process (`whisper-cli.exe`): speech-to-text with word timestamps; loads the user-downloaded Whisper model (section 2). | | `SDL2.dll` | SDL 2.28.5 (**binary**: string `SDL-release-2.28.5`, file version info "Copyright (C) 2023 Sam Lantinga"). Licence zlib (SPDX `Zlib`) - **UNVERIFIED** (not fetched). Not used by Substrike's own code (**repo** grep). It was in the 0.2.13 installer only because it sits in the whisper.cpp zip and the old `get-sidecars.ps1` copied every DLL; **no longer shipped** (**binary**: `dumpbin /dependents` shows no whisper.cpp binary imports it, and `whisper-cli` transcribes identically without it). | | `parakeet.dll` | Ships in the same whisper.cpp release zip. Not referenced by Substrike (**repo** grep). Licence presumed MIT as part of whisper.cpp - **UNVERIFIED**. **No longer shipped** (nothing imports it, same evidence as `SDL2.dll`). | | SHA-256 (local) | whisper-cli.exe `800a0fd7...ef638a65` (full: `800a0fd754afa75e109c7248286ad735670fb6b23d92ca5d12604647ef638a65`), whisper.dll `0a29e5824c7495185b833ad07df7ab9cadf130a9be848f967c6b88aeca971566`, parakeet.dll `8f864b1008c8b98861583a09ea6035c547cb46a9715b609c7dd7ccca138d1b7e` | | Also present | A second `llama.dll` at the top level of `binaries/` (2,459,136 bytes) that is NOT the one used by llama-server; it is bundled by `binaries/*.dll` in `tauri.windows.conf.json`. Its provenance is now known: it is inside the whisper.cpp 1.9.3 zip (`docs/sidecar-pinning.md`), so MIT. It is **no longer shipped** (nothing imports it; the `llama.dll` next to `llama-server.exe` is a different file and is still needed). | ### 1.2a Microsoft Visual C++ OpenMP runtime (vcomp140.dll) - added 2026-09-20 | Field | Value | |---|---| | Component | `vcomp140.dll` (Microsoft's OpenMP runtime for the Visual C++ compiler), installed next to `whisper-cli.exe` | | Why it is needed | **binary**: `dumpbin /dependents` shows `ggml-base.dll` and all nine `ggml-cpu-*.dll` import `VCOMP140.DLL`; `ggml-base.dll` is loaded when `whisper-cli.exe` starts. With that import renamed so the loader cannot find it (a stand-in for a PC that has no copy), `whisper-cli.exe` exits at once with 0xC0000135 (STATUS_DLL_NOT_FOUND) and prints nothing. With the bundled copy next to it the process loads that copy, not one from `System32` (checked from its loaded-module list). | | Version | 14.51.36247.0 (the copy taken from the Visual Studio 2026 Build Tools redistributable folder on the build PC; `scripts/get-sidecars.ps1` takes the newest one it finds and refuses anything that is not validly signed by Microsoft Corporation or is older than 14.40) | | Licence / right to redistribute | Microsoft software licence terms. **upstream**: Microsoft's Visual Studio Redistribution page (the `Redist.txt` file, https://aka.ms/vs/17/redistribution and https://aka.ms/vs/18/redistribution, fetched 2026-09-20 for the 2026 edition) says that, subject to the licence terms of the Visual Studio edition, you may copy and distribute with your program any of the files under `[VisualStudioFolder]\VC\Redist` and its subfolders (except the `debug_nonredist` folders), unmodified, and that this right is limited to licensed Visual Studio users. `vcomp140.dll` lives in `VC\Redist\MSVC\\x64\Microsoft.VC*.OpenMP`. **Not legal advice:** the person or CI runner that builds the installer must hold a Visual Studio edition whose licence allows this (Community has eligibility conditions - **UNVERIFIED** here). No separate notice text ships with the file. | | SHA-256 | Not pinned (differs by Visual Studio version and is backwards compatible); the script prints the version and source path of what it bundled. | | Related | `MSVCP140.dll`, `MSVCP140_1.dll`, `VCRUNTIME140.dll`, `VCRUNTIME140_1.dll` are bundled app-local from the release after 0.3.3 on the same Redist.txt terms - see section 1.6. | ### 1.3 llama.cpp (binaries/llama/llama-server.exe and DLLs) | Field | Value | |---|---| | Component | `llama-server` (installed as `binaries/llama/llama-server.exe`) plus (in 0.2.13) 29 DLLs in the same folder, now 22 (see "Files no longer shipped"), from the llama.cpp `llama-*-bin-win-cpu-x64.zip` release | | Version | `version: 0.3.0-dev (build 10621, commit c1d0e7a00)`, built with Clang 20.1.8 for Windows x86_64 (**binary**: `llama-server --version`; matches `docs/cleanup-model-evaluation.md`). Downloaded as "the first release that has a win-cpu-x64 zip" with no pin (**repo**). | | Licence | **MIT** (SPDX `MIT`) - **upstream**: https://raw.githubusercontent.com/ggml-org/llama.cpp/master/LICENSE, "Copyright (c) 2023-2026 The ggml authors". llama.cpp vendors small permissively-licensed libraries (e.g. an HTTP server library, JSON library, image loader); their individual licences are **UNVERIFIED** and should be taken from the `licenses/` folder of the exact build's source tag. | | `libomp.dll` | LLVM OpenMP runtime (**binary**: string "LLVM OMP API version: 5.0"). Licence: Apache-2.0 WITH LLVM-exception (LLVM project) - **UNVERIFIED**. | | Upstream | https://github.com/ggml-org/llama.cpp | | How Substrike uses it | Separate process, bound to 127.0.0.1 (`polish.rs`, **repo**): runs the cleanup LLM (section 2). | | Files no longer shipped | The 0.2.13 folder also contained `llama-cli-impl.dll`, `llama-bench-impl.dll`, `llama-perplexity-impl.dll`, `llama-quantize-impl.dll`, `llama-completion-impl.dll`, `llama-batched-bench-impl.dll`, `llama-fit-params-impl.dll` (**binary**): the command-line tools' code, imported by nothing in the server. They are gone from the pinned install (`shipDlls` in `scripts/sidecar-versions.json`). The folder is now `llama-server.exe` plus 22 DLLs (the server's own closure - `llama-server-impl`, `llama-common`, `llama`, `mtmd`, `ggml`, `ggml-base`, `ggml-rpc`, 14 `ggml-cpu-*`, `libomp`); a real `llama-server` start and chat request work with exactly that set. | | SHA-256 (local) | llama-server.exe `0f706d509ce7937504d527f49cc1e68a0e45ee60cfc4153b3ff16f76a0f4e3ac` | ### 1.4 sherpa-onnx speaker diarization + Substrike's own extract-embedding tool **sherpa-onnx-offline-speaker-diarization.exe** | Field | Value | |---|---| | Version | sherpa-onnx **v1.12.15**, pinned (**repo**: `get-sidecars.ps1` downloads `sherpa-onnx-v1.12.15-win-x64-static.tar.bz2`). The local exe is dated 2025-10-22. I could not confirm the version string inside the exe (**UNVERIFIED** that it is exactly 1.12.15, though the pin and date are consistent). | | Licence | **Apache-2.0** (SPDX `Apache-2.0`) - **upstream**: https://raw.githubusercontent.com/k2-fsa/sherpa-onnx/master/LICENSE ("Apache License Version 2.0, January 2004"; the copyright line in the LICENSE file is the unfilled boilerplate; copyright holders are the k2-fsa contributors - UNVERIFIED). | | Contains | A statically linked ONNX Runtime (Microsoft, MIT; **binary**: ORT strings present, the embedded string `1.17.1` and `git-commit-id=8f5c79cb6` suggest ONNX Runtime 1.17.1, probable but UNVERIFIED), plus kaldi-decoder / OpenFst / kaldi-native-fbank style components (Apache-2.0, **binary** strings, UNVERIFIED). Its own notice files are not in the installer. | | SHA-256 (local) | `d97d71fd5413f0a3adaf80c117f61dda7cb755d1b7ae9a6136ac17e74bce45ce` | | Use | Separate process: clusters voices into speakers (pyannote segmentation + speaker embedding models, section 2). | **extract-embedding.exe (built by Substrike from `src-tauri/embed-tool/`)** | Field | Value | |---|---| | What it is | A small C++ program (`extract_embedding.cpp`, owned by the Substrike author) compiled by `scripts/build-embed-tool.ps1` (CMake + MSVC) against the sherpa-onnx v1.12.15 static release. | | Licence of what is inside | Substrike's own code + sherpa-onnx (Apache-2.0) + ONNX Runtime (MIT) **+ the eSpeak NG text-to-speech library (GPL-3.0-or-later)**. | | **Finding** | **binary**: byte-scanning the shipped `extract-embedding.exe` finds the full eSpeak NG API (`espeak_ng_Initialize`, `espeak_ng_Synthesize`, ... about 60 `espeak_*` symbols), the strings `Software\eSpeak NG`, `%s/espeak-ng-data` and piper's `phonemize_eSpeak`. The diarization exe from the same release does NOT contain them. Cause (**repo**, `CMakeLists.txt`): the tool links *every* `.lib` in the sherpa-onnx static release ("cheap, and safe against a transitive dependency this list didn't guess"), and the C API library drags in the TTS phonemizer, which uses eSpeak NG. **upstream**: eSpeak NG's README says it "is released under the GPL version 3 or later license" (https://github.com/espeak-ng/espeak-ng). | | Consequence | If that GPL code is genuinely linked into the executable (the binary evidence says it is), then `extract-embedding.exe` is itself a GPL-3.0-or-later work and cannot be distributed under Substrike's proprietary terms without also providing its complete corresponding source under the GPL. This is a second, separate GPL problem on top of ffmpeg, and it is one Substrike can fix in its own build (link only the libraries actually needed, or build sherpa-onnx with TTS disabled). See `docs/license-compliance.md`. | | SHA-256 (local) | `826f271e4afba1e42a6e559586d9f45b0a3e78105ae5657a176b5236d34203d3` | ### 1.5 ONNX Runtime inside the Substrike executable (Rust `ort` crate) | Field | Value | |---|---| | Component | ONNX Runtime 1.28 prebuilt static library, downloaded at build time by the `ort-sys` 2.0.0-rc.13 build script from `https://cdn.pyke.io/0/pyke:ort-rs/ms@1.28.0/x86_64-pc-windows-msvc+directml.tar.lzma2` (**repo**: `ort-sys`'s `dist.tsv`; sha256 `f7c654b3729cb9e5ad2a36a0c38e5b48e63bf4eed22968931aed33a0ad0b527d`). Linked statically into `substrike.exe` (`rustc-link-lib=static=onnxruntime`). | | Licence | **MIT** (SPDX `MIT`), "Copyright (c) Microsoft Corporation" (**upstream**: https://raw.githubusercontent.com/microsoft/onnxruntime/main/LICENSE). Microsoft also ships a `ThirdPartyNotices.txt` covering ORT's own dependencies; that file must accompany a binary redistribution (**UNVERIFIED** whether the pyke archive includes it). | | Note | The archive is the "directml" variant. It also contains `DirectML.dll` (Microsoft); the `copy-dylibs` feature copies it next to `substrike.exe` in dev/target builds (seen in `target/release/`), but it is NOT in the 0.2.13 installer (**binary**: 7-Zip listing). Redistribution terms of `DirectML.dll` were not checked (**UNVERIFIED**); this is fine as long as it stays out of the installer. | | Use | In-process forced alignment with the wav2vec2 model (`align.rs`). | ### 1.6 Tauri runtime, WebView2, installer | Component | Licence | Notes | |---|---|---| | Tauri 2 (`tauri` 2.11.5, `wry` 0.55.1, `tao` 0.35.3, plugins dialog/updater/process) | Apache-2.0 OR MIT | **repo** (Cargo metadata). See section 3. | | Microsoft Edge WebView2 Runtime | Microsoft software licence terms (proprietary, free to redistribute/bootstrap) | Not bundled. `tauri.conf.json` sets no `webviewInstallMode`, so Tauri's default (download the Evergreen bootstrapper at install time) applies - **UNVERIFIED** (default behaviour from Tauri docs, not fetched). | | NSIS (installer generator; its stub is inside `setup.exe` and `uninstall.exe`) | zlib/libpng licence (NSIS) - **UNVERIFIED** | Produced by the Tauri bundler. | | Microsoft Visual C++ runtime (`MSVCP140.dll`, `MSVCP140_1.dll`, `VCRUNTIME140.dll`, `VCRUNTIME140_1.dll`) | Bundled app-local from the release after 0.3.3 (**repo**: `src-tauri/tauri.windows.conf.json` maps all four DLLs to the install root and to `binaries/llama/`; `scripts/get-sidecars.ps1` copies them unmodified from the newest `VC\Redist\MSVC\\x64\Microsoft.VC*.CRT` folder after checking each carries a valid Microsoft Authenticode signature and is at least 14.40; `tests/bundle-resources.test.ts` fails the gate if the entries go). Right to redistribute: the same Redist.txt terms and the same **UNVERIFIED** Visual Studio edition eligibility caveat as section 1.2a; Microsoft's app-local deployment gets no Windows Update servicing, so each release re-copies the newest runtime from the build machine. Up to 0.3.3 it was not bundled (**binary**: none in the installer). It IS needed: **binary** (`dumpbin /dependents`) - the release `substrike.exe` imports `MSVCP140.dll` and `MSVCP140_1.dll`, and `whisper-cli.exe`, `whisper.dll` and the ggml DLLs import `MSVCP140.dll`, `VCRUNTIME140.dll` and `VCRUNTIME140_1.dll` (the Universal C Runtime, `api-ms-win-crt-*`, is part of Windows 10/11). A PC that has never installed the Visual C++ 2015-2022 Redistributable would fail to start the app itself, not just speech recognition; that redistributable's own installer also installs `vcomp140.dll`. Not tested on a machine without it. Decided 2026-09-24: ship those DLLs app-local rather than run the redistributable from the installer, because the per-user NSIS install needs no administrator prompt that way and the app-local copies are found first by every executable (same Redist.txt terms as section 1.2a). | | --- ## 2. Models Four model files are inside the installer: the two speaker-diarization `.onnx` files, (added 2026-09-20) the Whisper tiny.en preview model and (added 2026-09-24) the audio tagging model behind the experimental laughter pass. Everything else is downloaded at run time from Hugging Face into `%APPDATA%\com.substrike.app\models` (`models.rs` and `polish.rs`, **repo**). Since 2026-09-20 every download is pinned to an exact Hugging Face commit and checked against a SHA-256 (`docs/sidecar-pinning.md`); the URLs in the table below that say `main` are the pre-pin ones and are kept as originally inventoried. | Model | Ships how | File / size | Source | Licence | Status | |---|---|---|---|---|---| | **Whisper large-v3-turbo** (recommended default) | Downloaded at run time | `ggml-large-v3-turbo.bin`, ~1620 MB | `https://huggingface.co/ggerganov/whisper.cpp/resolve/main/ggml-large-v3-turbo.bin` (**repo**) - ggml conversion of OpenAI's `openai/whisper-large-v3-turbo` | **MIT**. **upstream**: HF API for `ggerganov/whisper.cpp` returns `cardData.license = "mit"`; the OpenAI model card `openai/whisper-large-v3-turbo` says `mit`; the whisper.cpp repo card says "OpenAI's Whisper models converted to ggml format". Copyright: OpenAI (**UNVERIFIED** - not read from a copyright line). | Verified (licence); no hash check in app | | **Whisper tiny.en** (15-second preview) | **Bundled** in installer (copied into the models folder at first launch, hash-checked) | `ggml-tiny.en.bin`, 77,704,715 bytes, SHA-256 `921e4cf8686fdd993dcd081a5da5b6c365bfde1162e72b08d75ac75289920b1f` | `https://huggingface.co/ggerganov/whisper.cpp/resolve/5359861c739e955e79d9a303bcbc70fb988958b1/ggml-tiny.en.bin` (**repo**, pinned revision) - ggml conversion of OpenAI's Whisper tiny.en | **MIT** (same repo card as the other Whisper models: **upstream** HF API `cardData.license = "mit"`); copyright OpenAI (**UNVERIFIED** wording). The model file carries no notice of its own, so the licence text is in this file. | Verified (licence, hash); shipping it is the owner's 2026-09-20 preview decision | | Whisper tiny.en (also downloadable), base.en, small.en, medium.en, large-v3 | Downloaded at run time (user picks) | `ggml-tiny.en.bin` 75 MB, `ggml-base.en.bin` 142 MB, `ggml-small.en.bin` 466 MB, `ggml-medium.en.bin` 1533 MB, `ggml-large-v3.bin` 3100 MB | Same `ggerganov/whisper.cpp` repo | MIT (same repo card) | Verified (repo card) | | **wav2vec2-base-960h** (forced alignment) | Downloaded at run time | `wav2vec2-base-960h.onnx`, ~361 MB | `https://huggingface.co/Xenova/wav2vec2-base-960h/resolve/main/onnx/model.onnx` (**repo**). ONNX conversion by "Xenova" (Transformers.js project) of `facebook/wav2vec2-base-960h` | Base model: **Apache-2.0** (**upstream**: `facebook/wav2vec2-base-960h` card lists `apache-2.0`; trained on LibriSpeech 960 h). The `Xenova/wav2vec2-base-960h` repo declares NO licence in its metadata (**upstream** HF API: no `cardData.license`, no license tag). Effective licence is inherited Apache-2.0 - **UNVERIFIED** for the conversion. LibriSpeech corpus licence (CC-BY-4.0) - UNVERIFIED. | Gap: conversion repo has no licence statement | | **Qwen2.5-1.5B-Instruct Q4_K_M** (transcript cleanup / metadata / translation) | Downloaded at run time | `qwen2.5-1.5b-instruct-q4_k_m.gguf`, 1,117,320,736 bytes, SHA-256 `6a1a2eb6d15622bf3c96857206351ba97e1af16c30d7a74ee38970e434e9407e` (checked by the app, `polish.rs`) | `https://huggingface.co/Qwen/Qwen2.5-1.5B-Instruct-GGUF/resolve/main/qwen2.5-1.5b-instruct-q4_k_m.gguf` (**repo**) | **Apache-2.0** (**upstream**: model card lists `apache-2.0`; base chain Qwen/Qwen2.5-1.5B -> Qwen2.5-1.5B-Instruct -> GGUF). Copyright: Qwen Team / Alibaba Cloud (UNVERIFIED wording). | Verified | | ~~Qwen2.5-3B-Instruct~~ (retired) | Not shipped or downloaded any more | - | - | **`qwen-research` licence, non-commercial** (**upstream**: HF API for `Qwen/Qwen2.5-3B-Instruct` returns `license: other`, `license_name: qwen-research`). Only appears now as a JSON test fixture string in `polish.rs` (**repo**) and possibly as orphaned files on the developer's / early users' disks. | Retired; make sure no build or doc points at it | | **pyannote segmentation 3.0** (speaker turns) | **Bundled** in installer | `sherpa-pyannote-segmentation.onnx`, 5,992,913 bytes, SHA-256 `220ad67ca923bef2fa91f2390c786097bf305bceb5e261d4af67b38e938e1079` | Downloaded by `get-sidecars.ps1` from `https://github.com/k2-fsa/sherpa-onnx/releases/download/speaker-segmentation-models/sherpa-onnx-pyannote-segmentation-3-0.tar.bz2` (**repo**); k2-fsa's ONNX export of `pyannote/segmentation-3.0` | **MIT** (**upstream**: HF card `pyannote/segmentation-3.0` lists MIT). The HF repo is **gated** (users must accept conditions and share contact info) and the card says the maintainers "will occasionally email you about premium models". Training data listed on the card: AISHELL, AliMeeting, AMI, AVA-AVD, DIHARD, Ego4D, MSDWild, REPERE, VoxConverse - the licences of those datasets were not checked (**UNVERIFIED**; some corpora carry research-only terms). The k2-fsa release itself carries no licence file that I could load (the page says "Each model has its own license"). | Licence MIT verified; training-data question open | | **NeMo TitaNet-small** (speaker embedding) | **Bundled** in installer | `sherpa-embedding.onnx` (= `nemo_en_titanet_small.onnx`), 40,257,283 bytes, SHA-256 `ad4a1802485d8b34c722d2a9d04249662f2ece5d28a7a039063ca22f515a789e` | `https://github.com/k2-fsa/sherpa-onnx/releases/download/speaker-recongition-models/nemo_en_titanet_small.onnx` (**repo**); k2-fsa's ONNX export of NVIDIA NeMo `titanet_small` | **RESOLVED 2026-09-25: CC-BY-4.0.** **upstream** NVIDIA's own Hugging Face model card for the TitaNet family, `nvidia/speakerverification_en_titanet_large`, is tagged `cc-by-4.0` (fetched 2026-09-25, https://huggingface.co/nvidia/speakerverification_en_titanet_large). NVIDIA does not publish a separate Hugging Face card for `titanet_small`; the NGC catalog page for `titanet_small` only says "License to use this model is covered by the license of the NeMo Toolkit" and does not itself name CC-BY-4.0 (fetched 2026-09-25, https://catalog.ngc.nvidia.com/orgs/nvidia/teams/nemo/models/titanet_small), so this is the TitaNet-large card's licence applied to its same-family sibling, not a small-model-specific statement; treat CC-BY-4.0 as the safer, attribution-requiring choice either way. Training-data licences (reportedly VoxCeleb/Fisher/Switchboard/LibriSpeech/SRE mixes) - UNVERIFIED. | CC-BY-4.0 attribution below | > **CC-BY-4.0 attribution (NeMo TitaNet-small):** "TitaNet-small" model card by NVIDIA, licensed under > CC-BY-4.0 (https://creativecommons.org/licenses/by/4.0/), from > https://huggingface.co/nvidia/speakerverification_en_titanet_large and > https://catalog.ngc.nvidia.com/orgs/nvidia/teams/nemo/models/titanet_small. Substrike ships an ONNX > export of this model, converted by the k2-fsa/sherpa-onnx project > (https://github.com/k2-fsa/sherpa-onnx/releases/tag/speaker-recongition-models); no other changes > were made. This model is used only for local, on-device speaker matching inside a user's own clips; > it is not used to identify real-world people and Substrike does not publish or share the resulting > voice fingerprints. | **Zipformer small audio tagging** (experimental laughter pass, `audio_events.rs`) | **Bundled** in installer (added 2026-09-24; the pass is skipped when the file is missing) | `sherpa-audio-tagging.onnx` (= the archive's `model.int8.onnx`), 27,038,066 bytes, SHA-256 `69304b8a1b96bbe6b7d16c24079f0732c65faf3568a14cb82a8238c709afe76c` | Downloaded by `get-sidecars.ps1` from `https://github.com/k2-fsa/sherpa-onnx/releases/download/audio-tagging-models/sherpa-onnx-zipformer-small-audio-tagging-2024-04-15.tar.bz2` (archive SHA-256 `07e2fafcdcbc461f2816188d9b0bbafced12584030cf67d5652e549ef256a2c6`, **repo**); k2-fsa's icefall zipformer trained on AudioSet (icefall PR 1421) | **Apache-2.0** (**binary**: the archive's own `README.md` front matter says `license: apache-2.0`). Copyright: the k2-fsa / icefall authors (**UNVERIFIED** wording). Training data: AudioSet, whose labels are CC-BY-4.0 and whose audio comes from YouTube videos under their uploaders' terms (**UNVERIFIED**, not checked). Only the Apache-2.0 model weights ship, no AudioSet audio. | Licence from the archive's README; training-data question open | Not models but downloaded at run time: nothing else. (The updater fetches `https://github.com/Chronox2290/substrike-releases/releases/latest/download/latest.json` (the public releases-only repository's latest published release, since 2026-09-26), **repo**; the optional Discord feature posts to a user-supplied `discord.com/api/webhooks/...` URL. Those are service terms, not licence items.) --- ## 3. Rust crates (compiled into `substrike.exe`) 313 crates from `cargo metadata` (see the top of this file). Every declared licence is a permissive one (MIT, Apache-2.0, BSD-2/3-Clause, ISC, Zlib, Unicode-3.0, 0BSD, Unlicense, CC0-1.0, BSL-1.0, CDLA-Permissive-2.0) **except five weak-copyleft MPL-2.0 crates**: `cssparser`, `cssparser-macros`, `dtoa-short`, `option-ext`, `selectors` (all pulled in transitively by the Tauri/wry stack). MPL-2.0 is file-level copyleft: unmodified use in a proprietary binary is fine as long as the notice is kept and the source of those crates (unmodified, on crates.io) can be obtained; no GPL, LGPL, AGPL or non-commercial licence appears among the declared crate licences (**repo**/Cargo metadata; not independently checked against each crate's LICENSE file). Direct dependencies (from `src-tauri/Cargo.toml`, **repo**): `tauri` 2.11.5, `tauri-plugin-dialog` 2.7.2, `tauri-plugin-updater` 2.10.1, `tauri-plugin-process` 2.3.1, `serde` 1.0.229, `serde_json`, `reqwest` 0.12.28 (rustls-tls), `ort` 2.0.0-rc.13 (MIT OR Apache-2.0; bindings, see 1.5), `sha2` 0.10.9, `tauri-build` (build only). The Cargo package name is still `clipcaption` version 0.1.0 (stale; kept internal-only on purpose - `tauri.conf.json`'s `mainBinaryName` renames the shipped binary to `substrike.exe` without touching the crate name). Note two versions of `reqwest` (0.12.28 direct, 0.13.4 via the updater plugin) and TLS is `rustls` + `ring` (Apache-2.0 AND ISC) with `webpki-roots` (CDLA-Permissive-2.0). **Added 2026-09-23, not yet in the table below** (regenerate it before release): `rusty-leveldb` 4.0.1 (MIT, https://github.com/dermesser/leveldb-rs), direct, reads the pre-rename WebView2 localStorage once. It brings in `snap` 1.1.2 (BSD-3-Clause), `crc32c` 0.6.8 (Apache-2.0/MIT), `integer-encoding` 3.0.4 (MIT), `fs2` 0.4.3 and `errno` 0.2.8 (MIT/Apache-2.0), `rand` 0.8.8, `rand_chacha` 0.3.1, `rand_core` 0.6.4, `ppv-lite86` 0.2.21 (MIT OR Apache-2.0) and `zerocopy` 0.8.57 (BSD-2-Clause OR Apache-2.0 OR MIT), all permissive (**repo**: `cargo tree -f "{p} | {l}"`). ### 3.1 Full list (compiled into the app) Snapshot of 2026-09-20, superseded by the generated `src-tauri/resources/licenses/THIRD-PARTY-LICENSES.txt` (see the note at the top); kept for the record. | Crate | Version | Licence (SPDX expression from crate metadata) | Upstream | |---|---|---|---| | adler2 | 2.0.1 | 0BSD OR MIT OR Apache-2.0 | https://github.com/oyvindln/adler2 | | aho-corasick | 1.1.5 | Unlicense OR MIT | https://github.com/BurntSushi/aho-corasick | | alloc-no-stdlib | 2.0.4 | BSD-3-Clause | https://github.com/dropbox/rust-alloc-no-stdlib | | alloc-stdlib | 0.2.4 | BSD-3-Clause | https://github.com/dropbox/rust-alloc-no-stdlib | | anyhow | 1.0.104 | MIT OR Apache-2.0 | https://github.com/dtolnay/anyhow | | atomic-waker | 1.1.2 | Apache-2.0 OR MIT | https://github.com/smol-rs/atomic-waker | | base64 | 0.22.1 | MIT OR Apache-2.0 | https://github.com/marshallpierce/rust-base64 | | base64 | 0.23.1 | MIT OR Apache-2.0 | https://github.com/marshallpierce/rust-base64 | | bit-set | 0.8.0 | Apache-2.0 OR MIT | https://github.com/contain-rs/bit-set | | bit-vec | 0.8.0 | Apache-2.0 OR MIT | https://github.com/contain-rs/bit-vec | | bitflags | 1.3.2 | MIT/Apache-2.0 | https://github.com/bitflags/bitflags | | bitflags | 2.13.1 | MIT OR Apache-2.0 | https://github.com/bitflags/bitflags | | block-buffer | 0.10.4 | MIT OR Apache-2.0 | https://github.com/RustCrypto/utils | | brotli | 8.0.4 | BSD-3-Clause AND MIT | https://github.com/dropbox/rust-brotli | | brotli-decompressor | 5.0.3 | BSD-3-Clause/MIT | https://github.com/dropbox/rust-brotli-decompressor | | bs58 | 0.5.1 | MIT/Apache-2.0 | https://github.com/Nullus157/bs58-rs | | byteorder | 1.5.0 | Unlicense OR MIT | https://github.com/BurntSushi/byteorder | | bytes | 1.12.1 | MIT | https://github.com/tokio-rs/bytes | | camino | 1.2.5 | MIT OR Apache-2.0 | https://github.com/camino-rs/camino | | cargo-platform | 0.1.9 | MIT OR Apache-2.0 | https://github.com/rust-lang/cargo | | cargo_metadata | 0.19.2 | MIT | https://github.com/oli-obk/cargo_metadata | | cfb | 0.7.3 | MIT | https://github.com/mdsteele/rust-cfb | | cfg-if | 1.0.4 | MIT OR Apache-2.0 | https://github.com/rust-lang/cfg-if | | chacha20 | 0.10.1 | MIT OR Apache-2.0 | https://github.com/RustCrypto/stream-ciphers | | chrono | 0.4.45 | MIT OR Apache-2.0 | https://github.com/chronotope/chrono | | cookie | 0.18.2 | MIT OR Apache-2.0 | https://github.com/SergioBenitez/cookie-rs | | cpufeatures | 0.2.17 | MIT OR Apache-2.0 | https://github.com/RustCrypto/utils | | cpufeatures | 0.3.0 | MIT OR Apache-2.0 | https://github.com/RustCrypto/utils | | crc32fast | 1.5.1 | MIT OR Apache-2.0 | https://github.com/srijs/rust-crc32fast | | crossbeam-channel | 0.5.16 | MIT OR Apache-2.0 | https://github.com/crossbeam-rs/crossbeam | | crossbeam-utils | 0.8.22 | MIT OR Apache-2.0 | https://github.com/crossbeam-rs/crossbeam | | crypto-common | 0.1.7 | MIT OR Apache-2.0 | https://github.com/RustCrypto/traits | | cssparser | 0.36.0 | MPL-2.0 | https://github.com/servo/rust-cssparser | | cssparser-macros | 0.6.1 | MPL-2.0 | https://github.com/servo/rust-cssparser | | ctor | 0.8.0 | Apache-2.0 OR MIT | https://github.com/mmastrac/rust-ctor | | ctor-proc-macro | 0.0.7 | Apache-2.0 OR MIT | https://github.com/mmastrac/rust-ctor | | darling | 0.23.0 | MIT | https://github.com/TedDriggs/darling | | darling_core | 0.23.0 | MIT | https://github.com/TedDriggs/darling | | darling_macro | 0.23.0 | MIT | https://github.com/TedDriggs/darling | | defmt | 1.1.1 | MIT OR Apache-2.0 | https://github.com/knurling-rs/defmt | | defmt-macros | 1.1.1 | MIT OR Apache-2.0 | https://github.com/knurling-rs/defmt | | defmt-parser | 1.0.0 | MIT OR Apache-2.0 | https://github.com/knurling-rs/defmt | | deranged | 0.5.8 | MIT OR Apache-2.0 | https://github.com/jhpratt/deranged | | derive_more | 2.1.1 | MIT | https://github.com/JelteF/derive_more | | derive_more-impl | 2.1.1 | MIT | https://github.com/JelteF/derive_more | | digest | 0.10.7 | MIT OR Apache-2.0 | https://github.com/RustCrypto/traits | | dirs | 6.0.0 | MIT OR Apache-2.0 | https://github.com/soc/dirs-rs | | dirs-sys | 0.5.0 | MIT OR Apache-2.0 | https://github.com/dirs-dev/dirs-sys-rs | | displaydoc | 0.2.7 | MIT OR Apache-2.0 | https://github.com/yaahc/displaydoc | | dom_query | 0.27.0 | MIT | https://github.com/niklak/dom_query | | dpi | 0.1.2 | Apache-2.0 AND MIT | https://github.com/rust-windowing/winit | | dtoa | 1.0.11 | MIT OR Apache-2.0 | https://github.com/dtolnay/dtoa | | dtoa-short | 0.3.5 | MPL-2.0 | https://github.com/upsuper/dtoa-short | | dtor | 0.3.0 | Apache-2.0 OR MIT | https://github.com/mmastrac/rust-ctor | | dtor-proc-macro | 0.0.6 | Apache-2.0 OR MIT | https://github.com/mmastrac/rust-ctor | | dunce | 1.0.5 | CC0-1.0 OR MIT-0 OR Apache-2.0 | https://gitlab.com/kornelski/dunce | | dyn-clone | 1.0.20 | MIT OR Apache-2.0 | https://github.com/dtolnay/dyn-clone | | equivalent | 1.0.2 | Apache-2.0 OR MIT | https://github.com/indexmap-rs/equivalent | | erased-serde | 0.4.10 | MIT OR Apache-2.0 | https://github.com/dtolnay/erased-serde | | fastrand | 2.5.0 | Apache-2.0 OR MIT | https://github.com/smol-rs/fastrand | | fdeflate | 0.3.7 | MIT OR Apache-2.0 | https://github.com/image-rs/fdeflate | | flate2 | 1.1.9 | MIT OR Apache-2.0 | https://github.com/rust-lang/flate2-rs | | fnv | 1.0.7 | Apache-2.0 / MIT | https://github.com/servo/rust-fnv | | foldhash | 0.2.0 | Zlib | https://github.com/orlp/foldhash | | form_urlencoded | 1.2.2 | MIT OR Apache-2.0 | https://github.com/servo/rust-url | | futures-channel | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-core | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-io | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-macro | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-sink | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-task | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | futures-util | 0.3.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/futures-rs | | generic-array | 0.14.7 | MIT | https://github.com/fizyk20/generic-array.git | | getrandom | 0.2.17 | MIT OR Apache-2.0 | https://github.com/rust-random/getrandom | | getrandom | 0.3.4 | MIT OR Apache-2.0 | https://github.com/rust-random/getrandom | | getrandom | 0.4.3 | MIT OR Apache-2.0 | https://github.com/rust-random/getrandom | | glob | 0.3.4 | MIT OR Apache-2.0 | https://github.com/rust-lang/glob | | hashbrown | 0.12.3 | MIT OR Apache-2.0 | https://github.com/rust-lang/hashbrown | | hashbrown | 0.17.1 | MIT OR Apache-2.0 | https://github.com/rust-lang/hashbrown | | heck | 0.5.0 | MIT OR Apache-2.0 | https://github.com/withoutboats/heck | | hex | 0.4.3 | MIT OR Apache-2.0 | https://github.com/KokaKiwi/rust-hex | | html5ever | 0.38.0 | MIT OR Apache-2.0 | https://github.com/servo/html5ever | | http | 1.5.0 | MIT OR Apache-2.0 | https://github.com/hyperium/http | | http-body | 1.1.0 | MIT | https://github.com/hyperium/http-body | | http-body-util | 0.1.5 | MIT | https://github.com/hyperium/http-body | | http-range | 0.1.5 | MIT | https://github.com/bancek/rust-http-range.git | | httparse | 1.10.1 | MIT OR Apache-2.0 | https://github.com/seanmonstar/httparse | | hyper | 1.11.0 | MIT | https://github.com/hyperium/hyper | | hyper-rustls | 0.27.9 | Apache-2.0 OR ISC OR MIT | https://github.com/rustls/hyper-rustls | | hyper-util | 0.1.20 | MIT | https://github.com/hyperium/hyper-util | | ico | 0.5.0 | MIT | https://github.com/mdsteele/rust-ico | | icu_collections | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_locale_core | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_normalizer | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_normalizer_data | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_properties | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_properties_data | 2.3.0 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | icu_provider | 2.3.1 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | ident_case | 1.0.1 | MIT/Apache-2.0 | https://github.com/TedDriggs/ident_case | | idna | 1.1.0 | MIT OR Apache-2.0 | https://github.com/servo/rust-url/ | | idna_adapter | 1.2.2 | Apache-2.0 OR MIT | https://github.com/hsivonen/idna_adapter | | indexmap | 1.9.3 | Apache-2.0 OR MIT | https://github.com/bluss/indexmap | | indexmap | 2.14.0 | Apache-2.0 OR MIT | https://github.com/indexmap-rs/indexmap | | infer | 0.19.0 | MIT | https://github.com/bojand/infer | | ipnet | 2.12.1 | MIT OR Apache-2.0 | https://github.com/krisprice/ipnet | | itoa | 1.0.18 | MIT OR Apache-2.0 | https://github.com/dtolnay/itoa | | jiff | 0.2.35 | Unlicense OR MIT | https://github.com/BurntSushi/jiff | | jiff-core | 0.1.0 | Unlicense OR MIT | https://github.com/BurntSushi/jiff | | jiff-tzdb | 0.1.8 | Unlicense OR MIT | https://github.com/BurntSushi/jiff | | jiff-tzdb-platform | 0.1.3 | Unlicense OR MIT | https://github.com/BurntSushi/jiff | | json-patch | 3.0.1 | MIT/Apache-2.0 | https://github.com/idubrov/json-patch | | jsonptr | 0.6.3 | MIT OR Apache-2.0 | https://github.com/chanced/jsonptr | | keyboard-types | 0.7.0 | MIT OR Apache-2.0 | https://github.com/pyfisch/keyboard-types | | libc | 0.2.189 | MIT OR Apache-2.0 | https://github.com/rust-lang/libc | | litemap | 0.8.3 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | lock_api | 0.4.14 | MIT OR Apache-2.0 | https://github.com/Amanieu/parking_lot | | log | 0.4.34 | MIT OR Apache-2.0 | https://github.com/rust-lang/log | | lru-slab | 0.1.2 | MIT OR Apache-2.0 OR Zlib | https://github.com/Ralith/lru-slab | | markup5ever | 0.38.0 | MIT OR Apache-2.0 | https://github.com/servo/html5ever | | matrixmultiply | 0.3.11 | MIT/Apache-2.0 | https://github.com/bluss/matrixmultiply/ | | memchr | 2.8.3 | Unlicense OR MIT | https://github.com/BurntSushi/memchr | | mime | 0.3.17 | MIT OR Apache-2.0 | https://github.com/hyperium/mime | | mime_guess | 2.0.5 | MIT | https://github.com/abonander/mime_guess | | minisign-verify | 0.2.5 | MIT | https://github.com/jedisct1/rust-minisign-verify | | miniz_oxide | 0.8.9 | MIT OR Zlib OR Apache-2.0 | https://github.com/Frommi/miniz_oxide/tree/master/miniz_oxide | | mio | 1.2.2 | MIT | https://github.com/tokio-rs/mio | | muda | 0.19.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/muda | | ndarray | 0.17.2 | MIT OR Apache-2.0 | https://github.com/rust-ndarray/ndarray | | new_debug_unreachable | 1.0.6 | MIT | https://github.com/mbrubeck/rust-debug-unreachable | | num-complex | 0.4.6 | MIT OR Apache-2.0 | https://github.com/rust-num/num-complex | | num-conv | 0.2.2 | MIT OR Apache-2.0 | https://github.com/jhpratt/num-conv | | num-integer | 0.1.47 | MIT OR Apache-2.0 | https://github.com/rust-num/num-integer | | num-traits | 0.2.19 | MIT OR Apache-2.0 | https://github.com/rust-num/num-traits | | once_cell | 1.21.4 | MIT OR Apache-2.0 | https://github.com/matklad/once_cell | | option-ext | 0.2.0 | MPL-2.0 | https://github.com/soc/option-ext.git | | ort | 2.0.0-rc.13 | MIT OR Apache-2.0 | https://github.com/pykeio/ort | | ort-sys | 2.0.0-rc.13 | MIT OR Apache-2.0 | https://github.com/pykeio/ort | | parking_lot | 0.12.5 | MIT OR Apache-2.0 | https://github.com/Amanieu/parking_lot | | parking_lot_core | 0.9.12 | MIT OR Apache-2.0 | https://github.com/Amanieu/parking_lot | | percent-encoding | 2.3.2 | MIT OR Apache-2.0 | https://github.com/servo/rust-url/ | | phf | 0.13.1 | MIT | https://github.com/rust-phf/rust-phf | | phf_generator | 0.13.1 | MIT | https://github.com/rust-phf/rust-phf | | phf_macros | 0.13.1 | MIT | https://github.com/rust-phf/rust-phf | | phf_shared | 0.13.1 | MIT | https://github.com/rust-phf/rust-phf | | pin-project-lite | 0.2.17 | Apache-2.0 OR MIT | https://github.com/taiki-e/pin-project-lite | | plist | 1.10.0 | MIT | https://github.com/ebarnard/rust-plist/ | | png | 0.17.16 | MIT OR Apache-2.0 | https://github.com/image-rs/image-png | | potential_utf | 0.1.6 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | powerfmt | 0.2.0 | MIT OR Apache-2.0 | https://github.com/jhpratt/powerfmt | | precomputed-hash | 0.1.1 | MIT | https://github.com/emilio/precomputed-hash | | proc-macro2 | 1.0.107 | MIT OR Apache-2.0 | https://github.com/dtolnay/proc-macro2 | | quick-xml | 0.41.0 | MIT | https://github.com/tafia/quick-xml | | quinn | 0.11.11 | MIT OR Apache-2.0 | https://github.com/quinn-rs/quinn | | quinn-proto | 0.11.17 | MIT OR Apache-2.0 | https://github.com/quinn-rs/quinn | | quinn-udp | 0.5.15 | MIT OR Apache-2.0 | https://github.com/quinn-rs/quinn | | quote | 1.0.47 | MIT OR Apache-2.0 | https://github.com/dtolnay/quote | | rand | 0.10.2 | MIT OR Apache-2.0 | https://github.com/rust-random/rand | | rand_core | 0.10.1 | MIT OR Apache-2.0 | https://github.com/rust-random/rand_core | | rand_pcg | 0.10.2 | MIT OR Apache-2.0 | https://github.com/rust-random/rngs | | raw-window-handle | 0.6.2 | MIT OR Apache-2.0 OR Zlib | https://github.com/rust-windowing/raw-window-handle | | rawpointer | 0.2.1 | MIT/Apache-2.0 | https://github.com/bluss/rawpointer/ | | ref-cast | 1.0.27 | MIT OR Apache-2.0 | https://github.com/dtolnay/ref-cast | | ref-cast-impl | 1.0.27 | MIT OR Apache-2.0 | https://github.com/dtolnay/ref-cast | | regex | 1.13.1 | MIT OR Apache-2.0 | https://github.com/rust-lang/regex | | regex-automata | 0.4.18 | MIT OR Apache-2.0 | https://github.com/rust-lang/regex | | regex-syntax | 0.8.11 | MIT OR Apache-2.0 | https://github.com/rust-lang/regex | | reqwest | 0.12.28 | MIT OR Apache-2.0 | https://github.com/seanmonstar/reqwest | | reqwest | 0.13.4 | MIT OR Apache-2.0 | https://github.com/seanmonstar/reqwest | | rfd | 0.16.0 | MIT | https://github.com/PolyMeilex/rfd | | ring | 0.17.14 | Apache-2.0 AND ISC | https://github.com/briansmith/ring | | rustc-hash | 2.1.3 | Apache-2.0 OR MIT | https://github.com/rust-lang/rustc-hash | | rustls | 0.23.43 | Apache-2.0 OR ISC OR MIT | https://github.com/rustls/rustls | | rustls-pki-types | 1.15.1 | MIT OR Apache-2.0 | https://github.com/rustls/pki-types | | rustls-platform-verifier | 0.7.0 | MIT OR Apache-2.0 | https://github.com/rustls/rustls-platform-verifier | | rustls-webpki | 0.103.15 | ISC | https://github.com/rustls/webpki | | ryu | 1.0.23 | Apache-2.0 OR BSL-1.0 | https://github.com/dtolnay/ryu | | same-file | 1.0.6 | Unlicense/MIT | https://github.com/BurntSushi/same-file | | schemars | 0.8.22 | MIT | https://github.com/GREsau/schemars | | schemars | 0.9.0 | MIT | https://github.com/GREsau/schemars | | schemars | 1.2.2 | MIT | https://github.com/GREsau/schemars | | schemars_derive | 0.8.22 | MIT | https://github.com/GREsau/schemars | | scopeguard | 1.2.0 | MIT OR Apache-2.0 | https://github.com/bluss/scopeguard | | selectors | 0.36.1 | MPL-2.0 | https://github.com/servo/stylo | | semver | 1.0.28 | MIT OR Apache-2.0 | https://github.com/dtolnay/semver | | serde | 1.0.229 | MIT OR Apache-2.0 | https://github.com/serde-rs/serde | | serde-untagged | 0.1.9 | MIT OR Apache-2.0 | https://github.com/dtolnay/serde-untagged | | serde_core | 1.0.229 | MIT OR Apache-2.0 | https://github.com/serde-rs/serde | | serde_derive | 1.0.229 | MIT OR Apache-2.0 | https://github.com/serde-rs/serde | | serde_derive_internals | 0.29.1 | MIT OR Apache-2.0 | https://github.com/serde-rs/serde | | serde_json | 1.0.151 | MIT OR Apache-2.0 | https://github.com/serde-rs/json | | serde_repr | 0.1.21 | MIT OR Apache-2.0 | https://github.com/dtolnay/serde-repr | | serde_spanned | 1.1.1 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | serde_urlencoded | 0.7.1 | MIT/Apache-2.0 | https://github.com/nox/serde_urlencoded | | serde_with | 3.22.0 | MIT OR Apache-2.0 | https://github.com/jonasbb/serde_with/ | | serde_with_macros | 3.22.0 | MIT OR Apache-2.0 | https://github.com/jonasbb/serde_with/ | | serialize-to-javascript | 0.1.2 | MIT OR Apache-2.0 | https://github.com/chippers/serialize-to-javascript | | serialize-to-javascript-impl | 0.1.2 | MIT OR Apache-2.0 | https://github.com/chippers/serialize-to-javascript | | servo_arc | 0.4.3 | MIT OR Apache-2.0 | https://github.com/servo/stylo | | sha2 | 0.10.9 | MIT OR Apache-2.0 | https://github.com/RustCrypto/hashes | | simd-adler32 | 0.3.10 | MIT | https://github.com/mcountryman/simd-adler32 | | siphasher | 1.0.3 | MIT/Apache-2.0 | https://github.com/jedisct1/rust-siphash | | slab | 0.4.12 | MIT | https://github.com/tokio-rs/slab | | smallvec | 1.15.2 | MIT OR Apache-2.0 | https://github.com/servo/rust-smallvec | | socket2 | 0.6.5 | MIT OR Apache-2.0 | https://github.com/rust-lang/socket2 | | socks | 0.3.4 | MIT/Apache-2.0 | https://github.com/sfackler/rust-socks | | softbuffer | 0.4.8 | MIT OR Apache-2.0 | https://github.com/rust-windowing/softbuffer | | stable_deref_trait | 1.2.1 | MIT OR Apache-2.0 | https://github.com/storyyeller/stable_deref_trait | | string_cache | 0.9.0 | MIT OR Apache-2.0 | https://github.com/servo/string-cache | | strsim | 0.11.1 | MIT | https://github.com/rapidfuzz/strsim-rs | | subtle | 2.6.1 | BSD-3-Clause | https://github.com/dalek-cryptography/subtle | | syn | 2.0.119 | MIT OR Apache-2.0 | https://github.com/dtolnay/syn | | syn | 3.0.3 | MIT OR Apache-2.0 | https://github.com/dtolnay/syn | | sync_wrapper | 1.0.2 | Apache-2.0 | https://github.com/Actyx/sync_wrapper | | synstructure | 0.13.2 | MIT | https://github.com/mystor/synstructure | | tao | 0.35.3 | Apache-2.0 | https://github.com/tauri-apps/tao | | tauri | 2.11.5 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-codegen | 2.6.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-macros | 2.6.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-plugin-dialog | 2.7.2 | Apache-2.0 OR MIT | https://github.com/tauri-apps/plugins-workspace | | tauri-plugin-fs | 2.5.1 | Apache-2.0 OR MIT | https://github.com/tauri-apps/plugins-workspace | | tauri-plugin-process | 2.3.1 | Apache-2.0 OR MIT | https://github.com/tauri-apps/plugins-workspace | | tauri-plugin-updater | 2.10.1 | Apache-2.0 OR MIT | https://github.com/tauri-apps/plugins-workspace | | tauri-runtime | 2.11.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-runtime-wry | 2.11.4 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-utils | 2.9.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tempfile | 3.27.0 | MIT OR Apache-2.0 | https://github.com/Stebalien/tempfile | | tendril | 0.5.1 | MIT OR Apache-2.0 | https://github.com/servo/html5ever | | thiserror | 1.0.69 | MIT OR Apache-2.0 | https://github.com/dtolnay/thiserror | | thiserror | 2.0.20 | MIT OR Apache-2.0 | https://github.com/dtolnay/thiserror | | thiserror-impl | 1.0.69 | MIT OR Apache-2.0 | https://github.com/dtolnay/thiserror | | thiserror-impl | 2.0.20 | MIT OR Apache-2.0 | https://github.com/dtolnay/thiserror | | time | 0.3.55 | MIT OR Apache-2.0 | https://github.com/time-rs/time | | time-core | 0.1.9 | MIT OR Apache-2.0 | https://github.com/time-rs/time | | time-macros | 0.2.32 | MIT OR Apache-2.0 | https://github.com/time-rs/time | | tinystr | 0.8.4 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | tinyvec | 1.12.0 | Zlib OR Apache-2.0 OR MIT | https://github.com/Lokathor/tinyvec | | tinyvec_macros | 0.1.1 | MIT OR Apache-2.0 OR Zlib | https://github.com/Soveu/tinyvec_macros | | tokio | 1.53.1 | MIT | https://github.com/tokio-rs/tokio | | tokio-rustls | 0.26.4 | MIT OR Apache-2.0 | https://github.com/rustls/tokio-rustls | | tokio-util | 0.7.19 | MIT | https://github.com/tokio-rs/tokio | | toml | 1.1.4+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | toml_datetime | 1.1.1+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | toml_parser | 1.1.3+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | toml_writer | 1.1.2+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | tower | 0.5.3 | MIT | https://github.com/tower-rs/tower | | tower-http | 0.6.11 | MIT | https://github.com/tower-rs/tower-http | | tower-layer | 0.3.3 | MIT | https://github.com/tower-rs/tower | | tower-service | 0.3.3 | MIT | https://github.com/tower-rs/tower | | tracing | 0.1.44 | MIT | https://github.com/tokio-rs/tracing | | tracing-core | 0.1.36 | MIT | https://github.com/tokio-rs/tracing | | tray-icon | 0.24.2 | MIT OR Apache-2.0 | https://github.com/tauri-apps/tray-icon | | try-lock | 0.2.5 | MIT | https://github.com/seanmonstar/try-lock | | typeid | 1.0.3 | MIT OR Apache-2.0 | https://github.com/dtolnay/typeid | | typenum | 1.20.1 | MIT OR Apache-2.0 | https://github.com/paholg/typenum | | unic-char-property | 0.9.0 | MIT/Apache-2.0 | https://github.com/open-i18n/rust-unic/ | | unic-char-range | 0.9.0 | MIT/Apache-2.0 | https://github.com/open-i18n/rust-unic/ | | unic-common | 0.9.0 | MIT/Apache-2.0 | https://github.com/open-i18n/rust-unic/ | | unic-ucd-ident | 0.9.0 | MIT/Apache-2.0 | https://github.com/open-i18n/rust-unic/ | | unic-ucd-version | 0.9.0 | MIT/Apache-2.0 | https://github.com/open-i18n/rust-unic/ | | unicase | 2.9.0 | MIT OR Apache-2.0 | https://github.com/seanmonstar/unicase | | unicode-ident | 1.0.24 | (MIT OR Apache-2.0) AND Unicode-3.0 | https://github.com/dtolnay/unicode-ident | | unicode-segmentation | 1.13.3 | MIT OR Apache-2.0 | https://github.com/unicode-rs/unicode-segmentation | | untrusted | 0.9.0 | ISC | https://github.com/briansmith/untrusted | | ureq | 3.4.0 | MIT OR Apache-2.0 | https://github.com/algesten/ureq | | ureq-proto | 0.6.1 | MIT OR Apache-2.0 | https://github.com/algesten/ureq-proto | | url | 2.5.8 | MIT OR Apache-2.0 | https://github.com/servo/rust-url | | urlpattern | 0.3.0 | MIT | https://github.com/denoland/rust-urlpattern | | utf8-zero | 0.8.1 | MIT OR Apache-2.0 | https://github.com/algesten/utf8-zero | | utf8_iter | 1.0.4 | Apache-2.0 OR MIT | https://github.com/hsivonen/utf8_iter | | uuid | 1.25.0 | Apache-2.0 OR MIT | https://github.com/uuid-rs/uuid | | walkdir | 2.5.0 | Unlicense/MIT | https://github.com/BurntSushi/walkdir | | want | 0.3.1 | MIT | https://github.com/seanmonstar/want | | web_atoms | 0.2.6 | MIT OR Apache-2.0 | https://github.com/servo/html5ever | | webpki-roots | 1.0.9 | CDLA-Permissive-2.0 | https://github.com/rustls/webpki-roots | | webview2-com | 0.38.2 | MIT | https://github.com/wravery/webview2-rs | | webview2-com-macros | 0.8.1 | MIT | https://github.com/wravery/webview2-rs | | webview2-com-sys | 0.38.2 | MIT | https://github.com/wravery/webview2-rs | | winapi | 0.3.9 | MIT/Apache-2.0 | https://github.com/retep998/winapi-rs | | winapi-util | 0.1.11 | Unlicense OR MIT | https://github.com/BurntSushi/winapi-util | | window-vibrancy | 0.6.0 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri-plugin-vibrancy | | windows | 0.61.3 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-collections | 0.2.0 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-core | 0.61.2 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-future | 0.2.1 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-implement | 0.60.2 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-interface | 0.59.3 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-link | 0.1.3 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-link | 0.2.1 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-numerics | 0.2.0 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-result | 0.3.4 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-strings | 0.4.2 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-sys | 0.59.0 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-sys | 0.60.2 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-sys | 0.61.2 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-targets | 0.52.6 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-targets | 0.53.5 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-threading | 0.1.0 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows-version | 0.1.7 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows_x86_64_msvc | 0.52.6 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | windows_x86_64_msvc | 0.53.1 | MIT OR Apache-2.0 | https://github.com/microsoft/windows-rs | | winnow | 1.0.4 | MIT | https://github.com/winnow-rs/winnow | | writeable | 0.6.4 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | wry | 0.55.1 | Apache-2.0 OR MIT | https://github.com/tauri-apps/wry | | yoke | 0.8.3 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | yoke-derive | 0.8.2 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zerofrom | 0.1.8 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zerofrom-derive | 0.1.7 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zeroize | 1.9.0 | Apache-2.0 OR MIT | https://github.com/RustCrypto/utils | | zerotrie | 0.2.5 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zerovec | 0.11.8 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zerovec-derive | 0.11.6 | Unicode-3.0 | https://github.com/unicode-org/icu4x | | zip | 4.6.1 | MIT | https://github.com/zip-rs/zip2.git | | zmij | 1.0.23 | MIT | https://github.com/dtolnay/zmij | ### 3.2 Build-only crates (22, NOT shipped in the binary) Build scripts and code generators (`tauri-build`, `cc`, `toml`, `winnow`, ...). Listed for completeness. | Crate | Version | Licence | Upstream | |---|---|---|---| | autocfg | 1.5.1 | Apache-2.0 OR MIT | https://github.com/cuviper/autocfg | | cargo_toml | 0.22.3 | Apache-2.0 OR MIT | https://gitlab.com/lib.rs/cargo_toml | | cc | 1.4.4 | MIT OR Apache-2.0 | https://github.com/rust-lang/cc-rs | | cfg_aliases | 0.2.2 | MIT | https://github.com/katharostech/cfg_aliases | | embed-resource | 3.0.11 | MIT | https://github.com/nabijaczleweli/rust-embed-resource | | find-msvc-tools | 0.1.11 | MIT OR Apache-2.0 | https://github.com/rust-lang/cc-rs | | hmac-sha256 | 1.1.14 | ISC | https://github.com/jedisct1/rust-hmac-sha256 | | lzma-rust2 | 0.15.8 | Apache-2.0 | https://github.com/hasenbanck/lzma-rust2/ | | phf_codegen | 0.13.1 | MIT | https://github.com/rust-phf/rust-phf | | rustc_version | 0.4.1 | MIT OR Apache-2.0 | https://github.com/djc/rustc-version-rs | | shlex | 2.0.1 | MIT OR Apache-2.0 | https://github.com/comex/rust-shlex | | string_cache_codegen | 0.6.1 | MIT OR Apache-2.0 | https://github.com/servo/string-cache | | tauri-build | 2.6.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-plugin | 2.6.3 | Apache-2.0 OR MIT | https://github.com/tauri-apps/tauri | | tauri-winres | 0.3.6 | MIT | https://github.com/tauri-apps/winres | | toml | 0.9.12+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | toml_datetime | 0.7.5+spec-1.1.0 | MIT OR Apache-2.0 | https://github.com/toml-rs/toml | | version_check | 0.9.5 | MIT/Apache-2.0 | https://github.com/SergioBenitez/version_check | | vswhom | 0.1.0 | MIT | https://github.com/nabijaczleweli/vswhom.rs | | vswhom-sys | 0.1.3 | MIT | https://github.com/nabijaczleweli/vswhom-sys.rs | | winnow | 0.7.15 | MIT | https://github.com/winnow-rs/winnow | | winreg | 0.55.0 | MIT | https://github.com/gentoo90/winreg-rs | --- ## 4. JavaScript packages (production dependencies) Snapshot of 2026-09-20; the generated `src-tauri/resources/licenses/THIRD-PARTY-LICENSES.txt` is current and carries each package's licence text. 13 production packages from `package-lock.json`. All are MIT or MIT/Apache-2.0 dual-licensed. | Package | Version | Licence (from package-lock.json) | Notes | |---|---|---|---| | @tauri-apps/api | 2.11.1 | Apache-2.0 OR MIT | bundled into the frontend | | @tauri-apps/plugin-dialog | 2.7.2 | MIT OR Apache-2.0 | bundled into the frontend | | @tauri-apps/plugin-process | 2.3.1 | MIT OR Apache-2.0 | bundled into the frontend | | @tauri-apps/plugin-updater | 2.10.1 | MIT OR Apache-2.0 | bundled into the frontend | | @types/prop-types | 15.7.15 | MIT | type declarations only; not in the runtime bundle | | @types/react | 18.3.31 | MIT | type declarations only; not in the runtime bundle | | csstype | 3.2.3 | MIT | type declarations only; not in the runtime bundle | | js-tokens | 4.0.0 | MIT | dependency of loose-envify; not in the production Vite bundle (UNVERIFIED - not inspected in dist/) | | loose-envify | 1.4.0 | MIT | dependency of react/react-dom CommonJS entry; not in the production Vite bundle (UNVERIFIED - not inspected in dist/) | | react | 18.3.1 | MIT | bundled into the frontend | | react-dom | 18.3.1 | MIT | bundled into the frontend | | scheduler | 0.23.2 | MIT | bundled into the frontend | | zustand | 5.0.15 | MIT | bundled into the frontend | Everything above is what `package.json` + `package-lock.json` (**repo**) resolve for production dependencies: `@tauri-apps/api`, `@tauri-apps/plugin-dialog`, `@tauri-apps/plugin-updater`, `@tauri-apps/plugin-process`, `react`, `react-dom`, `zustand` and their dependencies. React 18.3.1 and react-dom are MIT, "Copyright (c) Meta Platforms, Inc. and affiliates" (UNVERIFIED wording; not fetched). Vite bundles these into `dist/`, which Tauri embeds in the executable. Development-only npm packages (119 in the lockfile: Vite 5, TypeScript, `@vitejs/plugin-react`, `@tauri-apps/cli` and its platform binaries, esbuild, rollup, Babel, ...) are not shipped. Their declared licences: MIT (98), Apache-2.0 OR MIT (12), ISC (5), Apache-2.0 (2), BSD-3-Clause (1), CC-BY-4.0 (1: `caniuse-lite`, a data file used only by the build tools). If the Vite production build inlines any of these into `dist/`, they would need notices; this was not checked (**UNVERIFIED**; inspect `dist/assets/*.js` for the licence comments Vite keeps). --- ## 5. Fonts, icons and other assets **Updated 2026-09-23: the five core caption-preset fonts are now bundled.** Previously this section said no font files were bundled anywhere and that every caption style named a proprietary Windows font (Arial Black, Bahnschrift, Segoe UI, Impact, Comic Sans MS), which meant preview/export mismatched whenever a machine lacked one of them and raised the unreviewed-Microsoft-licence question below. Fixed by replacing each proprietary pick with an openly-licensed Google Fonts equivalent and shipping the actual font files instead of naming a system font (**repo**: `src/lib/fonts.ts` is the single source of truth for the mapping; `src-tauri/resources/fonts/` holds the canonical files, mirrored into `public/fonts/` for the browser preview). | Bundled family | SIL OFL 1.1 | Replaces (Windows font it used to name) | Files | |---|---|---|---| | Archivo Black | Yes | Arial Black | `ArchivoBlack-Regular.ttf` | | Anton | Yes | Impact | `Anton-Regular.ttf` | | Barlow | Yes | Segoe UI | `Barlow-Regular.ttf`, `Barlow-Bold.ttf` | | Barlow Condensed | Yes | Bahnschrift | `BarlowCondensed-Regular.ttf`, `BarlowCondensed-Bold.ttf` | | Comic Neue | Yes | Comic Sans MS | `ComicNeue-Regular.ttf`, `ComicNeue-Bold.ttf` | Source: `github.com/google/fonts` (the `ofl/` directory), each with its own `OFL.txt` copied next to its TTF files in both `src-tauri/resources/fonts//` and `public/fonts//`. SIL Open Font License 1.1 permits embedding, redistribution and modification, including for a commercial proprietary application, with no royalty; the only obligation is keeping the licence text with the font and not selling the font *by itself* under the Substrike name. Static Regular/Bold weight files were used throughout (never a variable font) so both the CSS `font-weight` in the preview and the ASS `Bold` flag in the ffmpeg/libass burn-in (`src/lib/ass.ts`'s `boldFlag`) resolve to an unambiguous face rather than needing weight-axis/named-instance support. How preview and export now both resolve a font, so they can never mismatch again: `resolveFontFamily` (`src/lib/fonts.ts`) maps a style's `font` field through the table above - a NEW preset already names the bundled family directly (e.g. `"Anton"`), and an OLD saved/imported `.ccstyle` naming the original Windows font (e.g. `"Impact"`) is mapped onto its replacement rather than falling back to whatever happens to be installed. The preview's `@font-face` rules (`src/styles.css`) load the same files from `public/fonts/` that ffmpeg is pointed at: `src-tauri/src/export.rs`'s `bundled_fonts_dir` resolves the installed app's resource folder (or `src-tauri/resources/fonts` in a dev build) and passes it to libass's `subtitles=...:fontsdir=...` filter option, with the path escaped through the same two-layer filtergraph escaping as the `.ass` file itself so a `Program Files`-style path with spaces, a drive colon or backslashes cannot break the export (`escape_filter_path`/`filter_path_arg`, unit tested). Sticker text (a separate decorative overlay feature, `src/lib/stickerStyles.ts`, `src/lib/stickerAss.ts`) still names proprietary Windows fonts directly (Comic Sans MS, Segoe UI, Impact, Segoe Script, Segoe Print, Courier New, Consolas, Georgia, Trebuchet MS, Arial Black, Bahnschrift) and is **not** covered by this fix - same preview/export-mismatch risk as before, scoped out here as a separate follow-up (see `docs/known-limitations.md`). It is not redistributing those fonts, so no font licence attaches to the installer for that part. Open question, still unresolved for the bundled fonts too, just to be complete: the exported videos contain glyph shapes rendered from font files. OFL 1.1 explicitly permits embedding rendered output in documents/media produced with the font (this is the normal, intended use of an OFL webfont), so this is not the same open legal question the old Microsoft-font wording raised - flagged here only for completeness, not as an open item. Emoji are still drawn by the OS emoji font (Segoe UI Emoji), not shipped. Icons and marks: `src-tauri/icons/*` and `substrike-*.svg` appear to be original Substrike artwork (a violet rounded square with a "T" glyph; the SVGs carry no third-party attribution). Provenance and copyright are the repository owner's (**UNVERIFIED**: no design source file in the repo). The Tauri default icon set was not used (visual check of `128x128.png`). English word list (`src/assets/wordlist-en.txt`, added 2026-09-21, ships inside the app's JavaScript bundle as a text asset loaded on first use of the right-click spelling suggestions): derived from **SCOWL** (Spell Checker Oriented Word Lists), Copyright 2000-2018 by Kevin Atkinson, from the 2020.12.07 release, with additional public-domain material credited in the SCOWL Copyright file (12Dicts by Alan Beale, Moby Words II, ENABLE and others). We kept the lower-case words at size levels 10-60 of the English, American, Australian and British lists (about 82,000 words, 0.78 MB), dropped proper names, abbreviations and possessives, and added about 45 spoken and gaming words of our own (public domain). `scripts/build-wordlist.py` regenerates it. The SCOWL licence is reproduced here as it requires: > Copyright 2000-2018 by Kevin Atkinson > > Permission to use, copy, modify, distribute and sell these word lists, the associated scripts, the output created from the scripts, and > its documentation for any purpose is hereby granted without fee, provided that the above copyright notice appears in all copies and that > both that copyright notice and this permission notice appear in supporting documentation. Kevin Atkinson makes no representations about > the suitability of this array for any purpose. It is provided "as is" without express or implied warranty. --- ## 6. Open items in this file (see `docs/license-compliance.md` for the plan) 1. RESOLVED 2026-09-28: FFmpeg is now our own LGPL-2.1-or-later static build (s2, section 1.1), with no libx264 and no software H.264/HEVC/AV1 encoder. Source offer and exact corresponding source are written (`SOURCE-OFFER.txt`, `scripts/bundle-licences.json`); the s2 release is published at https://github.com/Chronox2290/substrike-releases/releases/tag/ffmpeg-9.0.1-s2 (`docs/ffmpeg-build.md` section 6). The earlier internal test build s1 (section 1.1a) was never distributed and is withdrawn; the Gyan Doshi stopgap (section 1.1b) is history. 2. RESOLVED 2026-09-20: `extract-embedding.exe` used to contain GPL-3.0-or-later eSpeak NG code; it was rebuilt without it and the build now refuses to ship it. 3. RESOLVED 2026-09-25: NeMo TitaNet-small licence is CC-BY-4.0 (NVIDIA's Hugging Face card for the TitaNet family, https://huggingface.co/nvidia/speakerverification_en_titanet_large); the required attribution line is in section 2 and in `THIRD-PARTY-LICENSES.txt`. 4. `Xenova/wav2vec2-base-960h` conversion repo has no licence declaration (base model is Apache-2.0). 5. Pyannote segmentation model: MIT, but gated on Hugging Face and trained on datasets whose own licences were not checked. 6. PARTLY RESOLVED: an About & licences screen ships and includes this file's text; the installer's own licence page is still to do. 7. RESOLVED 2026-09-20: `parakeet.dll`, `SDL2.dll`, top-level `llama.dll` and the llama.cpp tool DLLs are no longer shipped (section 1.2, 1.3). 7a. NEW 2026-09-20: `vcomp140.dll` is bundled (section 1.2a) on the strength of Microsoft's Visual Studio Redist.txt; confirm with the licensing consult that this covers a build made with the Community/Build Tools edition on GitHub's runners. The Visual C++ runtime DLLs the app itself imports were not bundled up to 0.3.3; from the release after 0.3.3 they ship app-local on the same terms (section 1.6). 7b. NEW 2026-09-20: the tiny.en model is bundled (MIT); add its licence text/attribution to the installer's licence page together with the others. 8. RESOLVED 2026-09-20: downloaded models are pinned to exact Hugging Face commits and verified by SHA-256. 8a. NEW 2026-09-24: the zipformer small audio tagging model (Apache-2.0) is bundled for the experimental laughter pass; add its licence text/attribution to the installer's licence page with the others (7b). AudioSet's own terms were not checked. 9. NEW 2026-09-23: the five core caption-preset fonts are bundled OFL (section 5) - add their `OFL.txt` texts to the installer's own licence page alongside the model licences (7b). Sticker text still names proprietary Windows fonts directly and was deliberately left out of this fix (section 5); the same preview/export mismatch risk still applies there and is a follow-up, not resolved.