# Third-party inventory for review

This review package preserves the installed dependency versions in `package-lock.json`, the application TypeScript source and compiled output. Image normalization uses Sharp; every image requires manual operator review. Install production dependencies with `npm ci --omit=dev`; keep their own license/notice files in the resulting installation.

- **Django common-password data:** `common-passwords.txt`; preserve `DJANGO-LICENSE.txt` (BSD). Django/Python is not needed to serve the Node application.
- **Noto Sans Thai:** local web/share font files; OFL notices in `models/LICENSE-noto.txt` and `static/fonts/LICENSE-noto*.txt`.
- **Tabler SVG icons:** preserve `static/icons/LICENSE-tabler.txt` (MIT).
- **Simple Icons LINE brand icon:** preserve `static/icons/LICENSE-simple-icons.md` (CC0-1.0); provider trademark terms still apply.
- **jose:** MIT; server-side JWT/JWKS verification and Apple client-secret signing. Preserve its installed license.
- **Google G mark:** `static/brand/google-g.png`, downloaded from Google's official identity assets; use for the Google login button under Google's branding guidelines, not as the site's own mark.
- **Node packages:** Express, Multer, mysql2, Nunjucks, cookie, QRCode, Satori, Sharp, plus their transitive dependencies. A generated lockfile-production inventory and copied license/notice files are in the package's `licenses/npm/` directory. The inventory includes all production optional platform packages, exact versions, npm registry URLs, integrity-verified tarballs and recursively collected license/notice files. Linux `npm ci` selects matching native Sharp/libvips packages. Embedded libvips third-party notices must remain with those binaries.
- **Node runtime:** select Node 24.21.0 LTS. The review archive contains no Node binary. Preserve the runtime's own third-party notices when installing it separately.
- **aws4fetch 1.0.20:** MIT; lightweight S3 Signature V4 client for the optional private R2 backend. Preserve its package LICENSE. R2 free monthly usage has limits and overages are billable; this SDK does not add a paid image-processing API.

Root `package.json`'s project license field does not replace the terms of bundled fonts, icons, password data, dependencies. No paid service was added. Optional Telegram transport stays inactive without explicit configuration; local tests use a mock sender.


Manual-only image candidate: automatic image approval is removed. Existing scan_result records remain historical data. This change does not certify public-launch readiness or resolve every third-party source obligation. See licenses/npm/INVENTORY.json for exact versions and notice evidence.

Non-npm assets and their hashes are listed in `licenses/ASSET-INVENTORY.json`. Upstream asset revisions are not inferred from unrelated dependency versions. The exact Sharp/libvips 1.3.4 README and `versions.json` are preserved for each target platform; its LGPL and other native-library notice/source obligations remain for release review. css-box-shadow 1.0.0-3 supplies an explicit MIT declaration and author metadata; its original README/package declaration and the unmodified SPDX standard MIT text are retained separately. No author-specific copyright or additional grant is invented. Yoga 3.2.1’s missing packaged license is supplemented from the official matching v3.2.1 tag, with URL and hash recorded.

**Native corresponding sources:** `third-party/sharp-libvips-1.3.4/SOURCE-AVAILABILITY.md` describes the delivered source companion, its SHA256, all 28 native sources/5 patches/357 checksum-verified Rust crates, authentic notices and the upstream platform build instructions. This is source-delivery evidence, not a claim that the managed host binary was rebuilt or that all launch gates passed.
