THIRD-PARTY NOTICES FOR THE CL-BUN BINARY

This file maps copyright notices to the third-party components identified by
the upstream Bun licence inventory. Standard licence terms are installed once
in the adjacent licenses directory; component-specific multi-licence
inventories remain separate. The version-specific SOURCE-MANIFEST.txt
identifies the exact Bun, WebKit, and TinyCC source commits.

Copyright notices have been checked against the stated source revision;
entries without a copyright notice are inventory items only, not synthesized
holder claims. The embedded JavaScript fallback package closure and its exact
notices are recorded in
NODE-FALLBACK-NOTICES.txt. Its header binds the generated attribution to the
exact Bun source revision and lock digest.

Bun source and build system (MIT)
See the upstream LICENSE inventory and exact Bun source identified by
SOURCE-MANIFEST.txt.

WebKit, JavaScriptCore, and WebCore (LGPL-2.0-or-later)
See licenses/LGPL-2.0.txt and the exact source identified by
SOURCE-MANIFEST.txt.

TinyCC, from the oven-sh/tinycc fork and patched by Bun (LGPL-2.1-or-later)
See licenses/LGPL-2.1.txt and the exact source identified by
SOURCE-MANIFEST.txt.

uSockets and the uWebSockets fork (Apache-2.0)
Vendored in the exact Bun source revision recorded by SOURCE-MANIFEST.txt under
packages/bun-usockets. Full terms: licenses/Apache-2.0.txt. That source tree
contains no NOTICE file.

simdutf, under its MIT alternative
The exact WebKit source revision recorded by SOURCE-MANIFEST.txt vendors the
simdutf implementation under Source/WTF/wtf/simdutf. Full selected terms:
licenses/MIT.txt. Copyright notice from that source:
Copyright 2021 The simdutf authors

highway (upstream licence inventory)
Pinned by Bun at google/highway@2607d3b5b0113992fe84d3848859eae13b3b52c1.
Verbatim upstream licence inventory: licenses/highway-LICENSE.txt. That
revision contains no NOTICE file.
Copyright (c) The Highway Project Authors. All rights reserved.

TigerBeetle IO portions (Apache-2.0)
The Bun inventory identifies TigerBeetle revision
532c8b70b9142c17e07737ab6d3da68d7500cbca. Full terms:
licenses/Apache-2.0.txt. That revision contains no NOTICE file.

LLVM libc++abi __cxa_thread_atexit fallback
(Apache-2.0 WITH LLVM-exception)
The Bun inventory identifies LLVM tag llvmorg-19.1.0. The exact upstream
libc++abi licence inventory, including the LLVM exception and legacy terms, is
installed once as licenses/libcxxabi-LICENSE.txt. That revision contains no
NOTICE.TXT file.

lol-html (BSD-3-Clause)
Pinned by Bun at oven-sh/lol-html@725ce499aa9b71e38b7a2d0a9fbb6d7294a4079e.
Full terms: licenses/BSD-3-Clause.txt. Copyright notice from that revision:
Copyright (C) 2019, Cloudflare, Inc.

libwebp (BSD-3-Clause)
Pinned by Bun at webmproject/libwebp@b7e29b9d75bd31422b00c2a446d49d7af06c328d.
Verbatim terms: licenses/libwebp-COPYING.txt. Copyright notice from that revision:
Copyright (c) 2010, Google Inc. All rights reserved.

libjpeg-turbo TurboJPEG API and build system (BSD-3-Clause)
Pinned by Bun at
libjpeg-turbo/libjpeg-turbo@e352b02f794f701407b39af08576035ba3360d60.
Verbatim upstream licence inventory:
licenses/libjpeg-turbo-LICENSE.txt. The complete verbatim IJG source notice is
licenses/libjpeg-turbo-README.ijg.txt.
Copyright (C) 2009-2026 D. R. Commander. All Rights Reserved.
Copyright (C) 2015 Viktor Szathmáry. All Rights Reserved.

libjpeg-derived code in libjpeg-turbo (IJG)
Copyright (C) 1991-2020 Thomas G. Lane and Guido Vollbeding.
This software is based in part on the work of the Independent JPEG Group.

Chromium proto-quic portions in lsquic (BSD-3-Clause)
Pinned with lsquic at
litespeedtech/lsquic@3181911301b1aa4f54c1ed690901abc674ee08fb.
Verbatim terms: licenses/lsquic-LICENSE.chrome.txt. Copyright notice from that
revision:
Copyright 2015 The Chromium Authors. All rights reserved.

zstd, under its BSD-3-Clause alternative
Pinned by Bun at facebook/zstd@f8745da6ff1ad1e7bab384bd1f9d742439278e99.
Verbatim terms: licenses/zstd-LICENSE.txt. Copyright notice from that revision:
Copyright (c) Meta Platforms, Inc. and affiliates. All rights reserved.

libbase64-derived base64 decode lookup table (BSD-2-Clause)
Bun 1.4.0 does not link the libbase64 library or vendor its source tree. Its
src/jsc/bindings/highway_sourcemap.cpp instead states that a base64 decode
lookup table is derived from the simdutf/aklomp decoders and reproduced
verbatim. The table bytes match aklomp/base64 revision
3a5add8652076612a8407627a42c768736a4263f, the last libbase64 revision that
Bun itself pinned before replacing that dependency with simdutf in commit
a0032d1b5c3333c6751525b658a106ed3fdb0fa1. Bun commit
c1da139f093cf7d876844518067fd490a3cf47c7 introduced the later table. The 2026
Bun commit does not record an external source revision. This record therefore
describes the verified byte match and former Bun pin; it does not assert that
revision as a recorded source pin for the later copy.
Verbatim terms and notice: licenses/libbase64-LICENSE.txt. The upstream notice
at aklomp/base64
revision 3a5add8652076612a8407627a42c768736a4263f has SHA-256
42871ad9f4e5e9255a4ec80b6c5ec9989bab6964693cf5fee6bb33f3afe39220 and
records:
Copyright (c) 2005-2007, Nick Galbreath
Copyright (c) 2015-2018, Wojciech Muła
Copyright (c) 2016-2017, Matthieu Darbois
Copyright (c) 2013-2022, Alfred Klomp

libspng portions (BSD-2-Clause and zlib)
Pinned by Bun at randy408/libspng@fb768002d4288590083a476af628e51c3f1d47cd.
Full terms: licenses/BSD-2-Clause.txt and licenses/zlib.txt. Copyright notice
from that revision:
Copyright (c) 2018-2023, Randy <randy408@protonmail.com>

HdrHistogram_c, under its BSD-2-Clause alternative
Pinned by Bun at
HdrHistogram/HdrHistogram_c@be60a9987ee48d0abf0d7b6a175bad8d6c1585d1.
Verbatim upstream licence inventory: licenses/hdrhistogram-LICENSE.txt.
Copyright notices from that revision:
Copyright (c) 2012, 2013, 2014 Gil Tene
Copyright (c) 2014 Michael Barker
Copyright (c) 2014 Matt Warren
Copyright (c) 2015 Philip Orwig

brotli (MIT)
Pinned by Bun at google/brotli@v1.1.0.
Full terms: licenses/MIT.txt. Copyright notice from that revision:
Copyright (c) 2009, 2010, 2013-2016 by the Brotli Authors.

mimalloc (MIT)
Pinned by Bun at oven-sh/mimalloc@6a14aee24315e503fa295a1fa90fe8b24ad91774.
Full terms: licenses/MIT.txt. Copyright notice from that revision:
Copyright (c) 2018-2025 Microsoft Corporation, Daan Leijen

c-ares (MIT)
Pinned by Bun at c-ares/c-ares@c7a3138dcfe3bb0eaaf10c0c24c36dc66dc790ab.
Verbatim terms: licenses/c-ares-LICENSE.txt. Copyright notices from that
revision:
Copyright (c) 1998 Massachusetts Institute of Technology
Copyright (c) 2007 - 2023 Daniel Stenberg with many contributors, see AUTHORS
file.

libuv (MIT)
Pinned by Bun at oven-sh/libuv@8023581113b276e7c1aee3f82da57ca0893faab1.
Full terms: licenses/MIT.txt. Copyright notice from that revision:
Copyright (c) 2015-present libuv project contributors.

libdeflate (MIT)
Pinned by Bun at ebiggers/libdeflate@c8c56a20f8f621e6a966b716b31f1dedab6a41e3.
Full terms: licenses/MIT.txt. Copyright notices from that revision:
Copyright 2016 Eric Biggers
Copyright 2024 Google LLC

ls-hpack (MIT)
Pinned by Bun at
litespeedtech/ls-hpack@8905c024b6d052f083a3d11d0a169b3c2735c8a1.
Full terms: licenses/MIT.txt. Copyright notice from that revision:
Copyright (c) 2018 - 2023 LiteSpeed Technologies Inc

ls-qpack (MIT)
Pinned by Bun at
litespeedtech/ls-qpack@1e9c5b8e59f8161c54f168a570c8bfdc59ded0c3.
Full terms: licenses/MIT.txt. Copyright notice from that revision:
Copyright (c) 2018 - 2022 LiteSpeed Technologies Inc

lsquic (MIT, except the Chromium portions above)
Pinned by Bun at
litespeedtech/lsquic@3181911301b1aa4f54c1ed690901abc674ee08fb.
Verbatim terms: licenses/lsquic-LICENSE.txt. Copyright notice from that revision:
Copyright (c) 2017 - 2026 LiteSpeed Technologies Inc

uucode-derived grapheme breaking implementation (MIT)
Bun incorporation commit 86d4d87beb1703f220ffba776f10f383841aaeb0
contains the exact uucode snapshot that Bun imported and its licence. Current
Bun source identifies its grapheme algorithm and generated tables as ported
from or derived from uucode. No external uucode revision is claimed.
Full terms: licenses/MIT.txt. The notice from that exact Bun incorporation
snapshot has SHA-256
75b52b07e8f6ed6b1700ca6e4bcff93a59258624d4fd1ab7eae4c071c860b69b and
records:
Copyright (c) 2025 Jacob Sandlund
The imported licence refers to separate Bjoern Hoehrmann and Unicode licence
files in the uucode project. They are installed separately rather than treated
as covered by the generic MIT text or the independently packaged ICU terms.

Bjoern Hoehrmann UTF-8 decoder table (MIT)
The exact Bun incorporation snapshot includes the decoder table and identifies
https://bjoern.hoehrmann.de/utf-8/decoder/dfa/ and the uucode file
licenses/LICENSE_Bjoern_Hoehrmann as its terms. The referenced upstream file
was introduced by uucode commit 731c2c0da439e71b9125cae2315e621f1e61deb4
and has SHA-256
de219cece932aad5a817bf763393d8d149d378a15d2ad5320e3331eac07626dd.
Its verbatim notice and terms are installed as
licenses/uucode-LICENSE-Bjoern-Hoehrmann.txt and record:
Copyright (c) 2008-2009 Bjoern Hoehrmann <bjoern@hoehrmann.de>

Unicode data used by uucode (Unicode-3.0)
The uucode licence imported by Bun identifies licenses/LICENSE_unicode for the
Unicode data used to generate its tables. That referenced file was added by
uucode commit 90a5dfa34a1da9d59b96417d73843c3c658f4816 and has
SHA-256
1eda5a3b026870c737b22e8bcd4954338612c790db688242e003f41a4fa95175.
Its verbatim notice and terms are installed as
licenses/uucode-LICENSE-Unicode.txt and record:
Copyright © 1991-2025 Unicode, Inc.

Those two commits establish the provenance of the referenced licence files;
they are not asserted as a source pin for the complete external uucode tree.
No external uucode revision is claimed.

picohttpparser, under its MIT alternative
Pinned by Bun at
h2o/picohttpparser@066d2b1e9ab820703db0837a7255d92d30f0c9f5.
Verbatim dual-licence terms: licenses/picohttpparser-LICENSE.txt. Copyright
notice from the upstream source header:
Copyright (c) 2009-2014 Kazuho Oku, Tokuhiro Matsuno, Daisuke Murase,
Shigeo Mitsunari

zlib-ng (zlib)
Pinned by Bun at zlib-ng/zlib-ng@12731092979c6d07f42da27da673a9f6c7b13586.
Full terms: licenses/zlib.txt. Copyright notice from that revision:
(C) 1995-2024 Jean-loup Gailly and Mark Adler

zlib-licensed portions of libjpeg-turbo and libspng
See licenses/libjpeg-turbo-LICENSE.txt and the libspng record above; full zlib
terms are installed once as licenses/zlib.txt.

ICU (Unicode-DFS-2016)
The exact WebKit source revision recorded by SOURCE-MANIFEST.txt vendors ICU
under Source/WTF/icu. Its verbatim licence is licenses/ICU.txt.
Copyright © 1991-2020 Unicode, Inc. All rights reserved.

BoringSSL (multiple permissive licences)
Pinned by Bun at
oven-sh/boringssl@2288897e2e716330490893d226b4f079f9da9e0c.
See the verbatim upstream inventory in licenses/boringssl-LICENSE.txt.

libarchive (multiple BSD-style and other permissive licences)
Pinned by Bun at
libarchive/libarchive@ded82291ab41d5e355831b96b0e1ff49e24d8939.
See the verbatim upstream inventory in licenses/libarchive-COPYING.txt.

SQLite (public domain)
SQLite is dedicated to the public domain by its author, D. Richard Hipp.

Embedded JavaScript polyfills (multiple permissive licences)
NODE-FALLBACK-NOTICES.txt records every lock key, unique package/version, npm
tarball URL and integrity, declared licence, and verbatim licence or notice
material shipped in each integrity-verified package archive.
