okf-loom offline assets: third-party notices
=============================================

Output built with `okf-loom build|render --assets offline` contains unmodified
copies of the third-party libraries below (plus two derived files described at
the end). They are the same exact versions the default CDN mode loads from
cdn.jsdelivr.net. Each library's own LICENSE file ships next to it
(`__static/vendor/<package>/LICENSE`) or, in a single-file export, inside the
`okf-third-party-notices` block. Licence banners inside the minified files are
left untouched.

Library                     Version   Licence        Vendored from (npm)
--------------------------  --------  -------------  -------------------------------
mermaid                     11.17.2   MIT            mermaid (dist/mermaid.min.js)
KaTeX                       0.16.47   MIT            katex (dist/katex.min.js, katex.min.css, fonts/*.woff2)
highlight.js                11.12.0   BSD-3-Clause   @highlightjs/cdn-assets (highlight.min.js, languages/*.min.js, styles)
Cytoscape.js                3.34.3    MIT            cytoscape (dist/cytoscape.min.js)
layout-base                 2.0.1     MIT            layout-base (layout-base.js)
cose-base                   2.2.0     MIT            cose-base (cose-base.js)
cytoscape-fcose             2.2.0     MIT            cytoscape-fcose (cytoscape-fcose.js)
dagre                       0.8.5     MIT            dagre (dist/dagre.min.js)
cytoscape-dagre             2.5.0     MIT            cytoscape-dagre (cytoscape-dagre.js)

KaTeX fonts: the KaTeX_* font files are licensed under the SIL Open Font
License, Version 1.1 (Copyright (c) 2009-2010 Design Science, Inc.; Copyright
(c) 2014-2018 Khan Academy), as stated in each font's own name table -- not
under the package's MIT licence. Their notices and the full OFL-1.1 text are in
BUNDLED-DEPENDENCY-NOTICES.txt.

Third-party code bundled inside the vendored files
--------------------------------------------------

Several vendored files are single-file builds that contain further third-party
code: mermaid.min.js bundles its dependency tree (d3, dompurify, langium,
cytoscape, roughjs, ...), Cytoscape.js inlines heap, lodash and gl-matrix,
dagre.min.js inlines graphlib and lodash, and a few adapted snippets carry
their own attribution. BUNDLED-DEPENDENCY-NOTICES.txt, shipped next to this
file (`__static/vendor/BUNDLED-DEPENDENCY-NOTICES.txt`, or inside the
single-file export's notices block), lists every such component with its exact
version, where it is included and how that was established, followed by its
full licence text. It is generated by scripts/generate_bundled_notices.py.

DOMPurify (inside mermaid.min.js) is offered under MPL-2.0 OR Apache-2.0;
okf-loom redistributes it under the Apache License, Version 2.0.

Derived files (built from the verified files above at build time)
------------------------------------------------------------------

highlightjs-11.12.0/highlight.offline.min.js
    highlight.min.js followed by the separately compiled language files, so
    the offline build registers the same languages as the CDN mode's full
    highlight.js build. No file is modified.
katex-0.16.47/katex.offline.min.css
    katex.min.css with each font face's sources replaced by the same face's
    woff2 file as a data: URL. No other change.
