Files
Jungfraujoch/docs/THIRD_PARTY_NOTICES.md
T
leonarski_f 30b6800289
Build Packages / build:windows:nocuda (push) Successful in 17m20s
Build Packages / build:windows:cuda (push) Successful in 19m52s
Build Packages / build:viewer-tgz:cpu (push) Successful in 9m38s
Build Packages / build:viewer-tgz:cuda (push) Successful in 11m18s
Build Packages / build:rugnux-tgz (x86_64) (push) Successful in 9m34s
Build Packages / build:rugnux:aarch64 (cross) (push) Successful in 5m42s
Build Packages / HDF5 consumer tests (DIALS, XDS) (push) Successful in 20m33s
Build Packages / Create release (push) Successful in 33s
Build Packages / build:rugnux:windows (push) Successful in 12m0s
Build Packages / build:rpm (rocky8_nocuda) (push) Successful in 15m42s
Build Packages / build:rpm (ubuntu2204_nocuda) (push) Successful in 14m59s
Build Packages / build:rpm (rocky9_nocuda) (push) Successful in 16m8s
Build Packages / build:rpm (ubuntu2404_nocuda) (push) Successful in 14m35s
Build Packages / build:rpm (rocky8_sls9) (push) Successful in 16m55s
Build Packages / build:rpm (rocky9_sls9) (push) Successful in 16m58s
Build Packages / Generate python client (push) Successful in 16s
Build Packages / build:rpm (rocky8) (push) Successful in 15m21s
Build Packages / Build documentation (push) Successful in 54s
Build Packages / build:rpm (rocky9) (push) Successful in 16m23s
Build Packages / build:rpm (ubuntu2204) (push) Successful in 12m2s
Build Packages / build:rpm (ubuntu2404) (push) Successful in 10m6s
Build Packages / Unit tests (push) Successful in 1h10m26s
v1.0.0-rc.171 (#81)
* Rugnux: basic support for CCD images (marCCD, SMV) and for gzipped miniCBF.
* `jfjoch_viewer`: opens the CCD formats, and fixes to the dataset plots.
* Documentation updates.

Reviewed-on: #81
Co-authored-by: Filip Leonarski <filip.leonarski@psi.ch>
2026-09-17 14:42:52 +02:00

12 KiB

Third-party software notices

Jungfraujoch is licensed under GPL-3.0 (see LICENSE); the FPGA design is licensed under CERN-OHL-S-2.0 (see fpga/LICENSE). It builds on a number of third-party components, acknowledged below as required by their licenses.

This file is the human-readable manifest. The verbatim license texts live in the licenses/ directory (regenerate with bash licenses/COLLECT.sh). The frontend's bundled JavaScript dependencies are listed separately in frontend/dist/THIRD_PARTY_LICENSES.txt, generated at build time (npm run licenses).

All licenses below are GPL-3.0-compatible, with one exception: the NVIDIA CUDA Toolkit is used under its own EULA (see the notes at the end of this file).

Fetched at build time and statically linked into the C++ binaries

These are downloaded by CMake (FetchContent / ExternalProject) during the first configure and linked into the Jungfraujoch executables.

Component Version Copyright License (SPDX) License text
spdlog 1.17.0 Gabi Melman MIT spdlog.txt
Zstandard 1.5.7 Meta Platforms, Inc. BSD-3-Clause zstd.txt
HDF5 2.2.0 The HDF Group; UIUC BSD-3-Clause-style + Apache-2.0 hdf5.txt
slsDetectorPackage 8.0.2 / 9.2.0 PSI LGPL-3.0-or-later LGPL, GPL
cpp-httplib 0.56.0 Yuji Hirose MIT cpp-httplib.txt
libzmq (ZeroMQ) 4.3.5 iMatix and contributors MPL-2.0 libzmq.txt
libtiff 4.7.2 Sam Leffler; SGI libtiff (BSD-like) libtiff.txt
FFTW 3.3.10 Matteo Frigo; MIT GPL-2.0-or-later fftw.txt
Ceres Solver (pinned) Google Inc. and contributors BSD-3-Clause ceres-solver.txt
Abseil 20250127 (required by Ceres) Google Inc. Apache-2.0 abseil.txt
fast-feedback-indexer (pinned) PSI BSD-3-Clause fast-feedback-indexer.txt
libjpeg-turbo 3.2.0 D. R. Commander and others; IJG IJG + BSD-3-Clause + Zlib libjpeg-turbo.txt
curl 8.22.0 Daniel Stenberg and contributors curl (MIT-like) curl.txt
Catch2 3.16.0 Catch2 Authors BSL-1.0 catch2.txt
zlib-ng 2.3.3 Jean-loup Gailly and Mark Adler; the zlib-ng contributors Zlib zlib.txt
Eigen 3.4.1 Benoit Jacob, Gael Guennebaud and contributors MPL-2.0 (+ BSD parts) eigen.txt, README

libcurl is fetched and statically linked only for viewer builds (JFJOCH_VIEWER_BUILD / JFJOCH_VIEWER_ONLY), where it is jfjoch_viewer's HTTP client; the broker and writer never link it. Its TLS and Kerberos backends are the OS-native ones (Schannel/SSPI on Windows, OpenSSL and system krb5 on Linux), so no TLS stack is vendored with it.

Catch2 is used only to build the test binary (jfjoch_test) and is not part of any shipped artifact; it is listed here for completeness.

zlib is supplied by zlib-ng built in its zlib-compatible mode (same zlib.h, same API and symbol names), so it is the zlib that HDF5, libtiff, cpp-httplib, libcurl and GEMMI all link. It is built during the configure rather than added as a subproject; the licence is the zlib licence either way. Eigen is header-only: only its headers reach the binaries, and no Eigen CMake runs.

Vendored directly in the repository

These live in the source tree (see the path) rather than being fetched; traccc is the exception - code adapted into first-party files rather than a vendored directory, see the note at the end of this file.

Component Path Copyright License (SPDX) License text
nlohmann/json include/nlohmann/ Niels Lohmann MIT nlohmann-json.txt
Macaron Base64 include/base64/ tomykaira MIT base64-macaron.txt
TinyCBOR frame_serialize/tinycbor/ Intel Corporation MIT tinycbor.txt
Bitshuffle compression/bitshuffle/ Kiyoshi Masui MIT bitshuffle.txt
Bitshuffle (h-perf) compression/bitshuffle_hperf/ Kal Cutter (DECTRIS) Apache-2.0 bitshuffle-hperf.txt
LZ4 compression/lz4/ Yann Collet BSD-2-Clause lz4.txt
HLS arbitrary-precision types fpga/include/ Xilinx, Inc. Apache-2.0 xilinx-hls-headers.txt
GEMMI gemmi_gph/ Global Phasing Ltd. MPL-2.0 gemmi.txt
PEGTL gemmi_gph/gemmi/third_party/tao/ Dr. Colin Hirsch and Daniel Frey MIT pegtl.txt
sajson gemmi_gph/gemmi/third_party/sajson.h Chad Austin MIT sajson.txt
fast_float gemmi_gph/gemmi/third_party/fast_float.h The fast_float authors (Daniel Lemire et al.) Apache-2.0 OR MIT OR BSL-1.0 fast-float.txt
half gemmi_gph/gemmi/third_party/half.hpp Christian Rau MIT half.txt
pocketfft gemmi_gph/gemmi/third_party/pocketfft_hdronly.h Max-Planck-Society; Peter Bell; MIT (FFTW-derived parts) BSD-3-Clause pocketfft.txt
tinydir gemmi_gph/gemmi/third_party/tinydir.h Cong Xu, Lautis Sun, Baudouin Feildel, Andargor BSD-2-Clause tinydir.txt
traccc (ACTS) image_analysis/spot_finding/StrongPixelSet.cpp, SpotExtractorGPU.cu CERN, for the benefit of the ACTS project MPL-2.0 traccc.txt
xbflash.qspi tools/xbflash.qspi/ Xilinx / AMD Apache-2.0 xbflash-qspi.txt
wingetopt tools/wingetopt/ Todd C. Miller; The NetBSD Foundation ISC AND BSD-2-Clause wingetopt.txt

Runtime libraries and SDKs (shipped in binaries, not in the source tree)

Component Used by License Notice
Qt 6 jfjoch_viewer LGPL-3.0 notice, LGPL-3.0
NVIDIA CUDA Toolkit (cudart, cuFFT) CUDA builds NVIDIA CUDA EULA notice, EULA

Frontend (npm) dependencies

The React/TypeScript frontend (frontend/) bundles a large transitive tree of npm packages, overwhelmingly MIT/ISC/BSD/Apache-2.0 licensed. Their full notices are generated automatically:

cd frontend && npm run licenses     # writes dist/THIRD_PARTY_LICENSES.txt

The generated file is produced as part of the frontend build target and installed alongside the served frontend, so the shipped web UI carries its own attribution.

Notes on weak-copyleft and attribution-sensitive components

  • MPL-2.0 (Eigen, GEMMI, libzmq, traccc): file-level copyleft. GEMMI is vendored in gemmi_gph/ in trimmed form; libzmq and Eigen are fetched at build time (Eigen is header-only). The corresponding source is available from each project upstream.
  • GEMMI's own bundled third-party headers — PEGTL, sajson, fast_float, half, pocketfft and tinydir, all under gemmi_gph/gemmi/third_party/ — are listed separately above rather than being absorbed into GEMMI's row: they are other authors' code under other licences (MIT, BSD and Apache/MIT/BSL), and GEMMI's MPL-2.0 does not speak for them. Their terms are carried in the headers themselves rather than in LICENSE files, so the licenses/*.txt copies are kept by hand; only PEGTL ships a LICENSE, which COLLECT.sh copies.
  • traccc is the one entry that is not a vendored directory. Its sparse connected-component labelling enters two otherwise first-party files: StrongPixelSet.cpp adapts the SparseCCL source, and SpotExtractorGPU.cu follows the design of its GPU counterpart. MPL-2.0 is file-level, so both files name the origin at the top and are covered by licenses/traccc.txt. See ACKNOWLEDGEMENT.md for the citation.
  • FFTW is GPL-2.0-or-later — compatible with, and absorbed by, this project's GPL-3.0 license.
  • Apache-2.0 components: where upstream ships a NOTICE file, it is reproduced in the corresponding licenses/ text.
  • Qt (LGPL-3.0) and NVIDIA CUDA (EULA) carry redistribution conditions beyond a copyright notice; see their dedicated notice files. The verbatim LGPL-3.0 and CUDA EULA texts are bundled (licenses/Qt6-LGPL-3.0.txt, licenses/NVIDIA-CUDA-EULA.txt); the CUDA EULA is the one shipped with CUDA Toolkit 12.8 — replace it if you build against a different toolkit version.