# Native library notices and corresponding sources

The private review recipient receives `source-companion-20261004.zip` alongside the application candidate. This companion is 202699752 bytes, SHA256 `db1e4d14c975ca9fe28bca5808cf8fade3ca09754ba5f50d5435ad83095cbdab`. Keep both files together when redistributing this review package. This is an actual delivered source collection, not a promise that the operator will obtain sources later.

The companion contains all 28 native source archives and 5 patches downloaded from the exact URLs in sharp-libvips v1.3.4's POSIX recipe, its full build/packaging scripts and platform Dockerfiles, Sharp 0.35.5's published source tarball, librsvg 2.63.2's original Cargo.lock, and all 357 registry crates pinned there. Every Cargo crate matched its Cargo.lock SHA256. `native-source-index.json` and `rust-source-index.json` list original download URLs, versions and SHA256 values. The official HTTPS source URLs also allow recipients to retrieve each archive and patch directly. License/copyright files are preserved in `native-notices/`, `rust-notices/`, and inside the source archives; LGPLv3 and GPLv3 standard texts are included without modifying their wording.

## Building or replacing the libraries

Use the source companion's `upstream/sharp-libvips-1.3.4/` tree. Its README documents prerequisites and platform selection. For Linux glibc x64, install Docker and run `./build.sh linux-x64` from that directory. The platform Dockerfile specifies toolchain/build prerequisites; `build/posix.sh` specifies configure/Meson/CMake options, patches and source downloads; `versions.properties` pins the native component versions. Choose the matching platform for a different installation. The collected archives and patches are retained for offline access; the original recipe downloads the corresponding official URLs. No build scripts from upstream were executed during this review.

The managed-host installation obtains its native binaries through `npm ci --omit=dev`, rather than from this application ZIP. Native npm package READMEs and versions.json must remain with those binaries. To use a separately rebuilt, compatible libvips, follow Sharp's official installation instructions at https://sharp.pixelplumbing.com/install/ and its documented global-libvips build option. Application source is included in the application ZIP. Do not remove notices or prevent users exercising applicable modification/debugging/replacement rights.

## Evidence and limits

The Linux-x64 npm libvips versions.json and recipe versions.properties match all 28 native components. Sources/patches are retained with checksums and authentic notices. No locally rebuilt binary, managed-host binary equivalence, or legal compliance verdict is asserted. The Rust source set covers every crate from the release Cargo.lock, including optional/build/test entries; the exact enabled subset is not invented. The upstream build recipe regenerates workspace locking after feature edits, so it does not itself provide a deterministic build guarantee. Preserve the corresponding build-time lock and toolchain record if the operator distributes a rebuilt binary.

Before any wider distribution, make the companion available with the artifact through the same recipient-access channel, or provide equivalent source access with these exact sources and notices. The currently private site remains behind its review gate; this task does not authorize public publication. Public deployment readiness and any operator obligations remain separate from this source-delivery evidence.
