# Third-party notices

Last generated and reviewed: 2026-08-02 using pnpm 11.9.0 on macOS arm64.

The Lagerman Labs Site contains proprietary first-party software; applicable
ownership follows the signed company records. The packages below are separate
third-party works used under their own licenses; their presence does not
relicense or transfer ownership of the applicable rights holder's original
code, text, design, or product assets.

`pnpm-lock.yaml` is the authoritative resolved dependency record. Platform-
specific optional packages can differ on Linux build hosts, so regenerate this
notice whenever the lockfile, build platform, or deployment contents change.
The companion `THIRD_PARTY_LICENSES.md` contains the exact locally installed
production license and NOTICE texts and is shipped beside this file.

## Direct runtime and build dependencies

| Package | Version | License | Upstream source |
| --- | --- | --- | --- |
| `next` | `16.2.12` | MIT | [vercel/next.js](https://github.com/vercel/next.js) |
| `react` | `19.2.8` | MIT | [facebook/react](https://github.com/facebook/react) |
| `react-dom` | `19.2.8` | MIT | [facebook/react](https://github.com/facebook/react) |
| `@cloudflare/vite-plugin` | `1.50.0` | MIT | [cloudflare/workers-sdk](https://github.com/cloudflare/workers-sdk) |
| `@tailwindcss/postcss` | `4.3.3` | MIT | [tailwindlabs/tailwindcss](https://github.com/tailwindlabs/tailwindcss) |
| `@types/node` | `22.19.19` | MIT | [DefinitelyTyped](https://github.com/DefinitelyTyped/DefinitelyTyped) |
| `@types/react` | `19.2.18` | MIT | [DefinitelyTyped](https://github.com/DefinitelyTyped/DefinitelyTyped) |
| `@types/react-dom` | `19.2.4` | MIT | [DefinitelyTyped](https://github.com/DefinitelyTyped/DefinitelyTyped) |
| `@vitejs/plugin-react` | `6.0.5` | MIT | [vitejs/vite-plugin-react](https://github.com/vitejs/vite-plugin-react) |
| `@vitejs/plugin-rsc` | `0.5.32` | MIT | [vitejs/vite-plugin-react](https://github.com/vitejs/vite-plugin-react) |
| `eslint` | `9.39.4` | MIT | [eslint/eslint](https://github.com/eslint/eslint) |
| `eslint-config-next` | `16.2.12` | MIT | [vercel/next.js](https://github.com/vercel/next.js) |
| `react-server-dom-webpack` | `19.2.8` | MIT | [facebook/react](https://github.com/facebook/react) |
| `tailwindcss` | `4.3.3` | MIT | [tailwindlabs/tailwindcss](https://github.com/tailwindlabs/tailwindcss) |
| `typescript` | `5.9.3` | Apache-2.0 | [microsoft/TypeScript](https://github.com/microsoft/TypeScript) |
| `vinext` | `0.0.50` | MIT | [cloudflare/vinext](https://github.com/cloudflare/vinext) |
| `vite` | `8.2.0` | MIT | [vitejs/vite](https://github.com/vitejs/vite) |
| `wrangler` | `4.118.0` | MIT OR Apache-2.0 | [cloudflare/workers-sdk](https://github.com/cloudflare/workers-sdk) |

## Attribution-sensitive and reciprocal licenses

These packages deserve explicit tracking even when they are only used during a
build or are installed as optional native tooling.

| Package | Resolved version(s) | License | Attribution or corresponding source |
| --- | --- | --- | --- |
| `@img/sharp-libvips-darwin-arm64` | `1.3.2` | LGPL-3.0-or-later | Prebuilt libvips distribution by Lovell Fuller; [source and bundled-library license map](https://github.com/lovell/sharp-libvips) |
| `@resvg/resvg-wasm` | `2.4.0` | MPL-2.0 | [yisibl/resvg-js](https://github.com/yisibl/resvg-js) |
| `@vercel/og` | `0.8.6` | MPL-2.0 | [published package and license](https://www.npmjs.com/package/@vercel/og/v/0.8.6) |
| `axe-core` | `4.12.1` | MPL-2.0 | [dequelabs/axe-core](https://github.com/dequelabs/axe-core) |
| `lightningcss` and native package | `1.32.0`, `1.33.0` | MPL-2.0 | [parcel-bundler/lightningcss](https://github.com/parcel-bundler/lightningcss) |
| `satori` | `0.16.0` | MPL-2.0 | [vercel/satori](https://github.com/vercel/satori) |
| `caniuse-lite` | `1.0.30001806` | CC-BY-4.0 | Ben Briggs and contributors; [browserslist/caniuse-lite](https://github.com/browserslist/caniuse-lite) |

License texts and terms:

- [GNU Lesser General Public License 3.0](https://www.gnu.org/licenses/lgpl-3.0.html)
- [Mozilla Public License 2.0](https://www.mozilla.org/MPL/2.0/)
- [Creative Commons Attribution 4.0 International](https://creativecommons.org/licenses/by/4.0/legalcode)
- [MIT License](https://spdx.org/licenses/MIT.html)
- [Apache License 2.0](https://www.apache.org/licenses/LICENSE-2.0)
- [ISC License](https://spdx.org/licenses/ISC.html)
- [BSD 3-Clause License](https://spdx.org/licenses/BSD-3-Clause.html)
- [Zero-Clause BSD License](https://spdx.org/licenses/0BSD.html)

The sharp/libvips native payload is an optional package selected by operating
system and architecture. It is not present in the current Cloudflare Worker
bundle. If a native package is redistributed in a future desktop, server, or
archive deliverable, include its package README and all corresponding LGPL and
component-license materials with that deliverable. MPL-covered package files
are used unmodified; their source is available at the exact upstream locations
above. No first-party source file is intentionally offered under MPL or LGPL.

## Locally resolved production and optional closure

This table records the packages reported by `pnpm licenses list --prod` for the
reviewed macOS arm64 installation. It is deliberately more inclusive than the
code served to a browser.

| Package | Version | License |
| --- | --- | --- |
| `@babel/code-frame` | `7.29.7` | `MIT` |
| `@babel/compat-data` | `7.29.7` | `MIT` |
| `@babel/core` | `7.29.7` | `MIT` |
| `@babel/generator` | `7.29.7` | `MIT` |
| `@babel/helper-compilation-targets` | `7.29.7` | `MIT` |
| `@babel/helper-globals` | `7.29.7` | `MIT` |
| `@babel/helper-module-imports` | `7.29.7` | `MIT` |
| `@babel/helper-module-transforms` | `7.29.7` | `MIT` |
| `@babel/helper-string-parser` | `7.29.7` | `MIT` |
| `@babel/helper-validator-identifier` | `7.29.7` | `MIT` |
| `@babel/helper-validator-option` | `7.29.7` | `MIT` |
| `@babel/helpers` | `7.29.7` | `MIT` |
| `@babel/parser` | `7.29.7` | `MIT` |
| `@babel/template` | `7.29.7` | `MIT` |
| `@babel/traverse` | `7.29.7` | `MIT` |
| `@babel/types` | `7.29.7` | `MIT` |
| `@img/colour` | `1.1.0` | `MIT` |
| `@img/sharp-darwin-arm64` | `0.35.3` | `Apache-2.0` |
| `@img/sharp-libvips-darwin-arm64` | `1.3.2` | `LGPL-3.0-or-later` |
| `@jridgewell/gen-mapping` | `0.3.13` | `MIT` |
| `@jridgewell/remapping` | `2.3.5` | `MIT` |
| `@jridgewell/resolve-uri` | `3.1.2` | `MIT` |
| `@jridgewell/sourcemap-codec` | `1.5.5` | `MIT` |
| `@jridgewell/trace-mapping` | `0.3.31` | `MIT` |
| `@next/env` | `16.2.12` | `MIT` |
| `@next/swc-darwin-arm64` | `16.2.12` | `MIT` |
| `@swc/helpers` | `0.5.15` | `Apache-2.0` |
| `@types/node` | `22.19.19` | `MIT` |
| `baseline-browser-mapping` | `2.11.0` | `Apache-2.0` |
| `browserslist` | `4.28.7` | `MIT` |
| `caniuse-lite` | `1.0.30001806` | `CC-BY-4.0` |
| `client-only` | `0.0.1` | `MIT` |
| `convert-source-map` | `2.0.0` | `MIT` |
| `debug` | `4.4.3` | `MIT` |
| `detect-libc` | `2.1.2` | `Apache-2.0` |
| `electron-to-chromium` | `1.5.395` | `ISC` |
| `escalade` | `3.2.0` | `MIT` |
| `gensync` | `1.0.0-beta.2` | `MIT` |
| `js-tokens` | `4.0.0` | `MIT` |
| `jsesc` | `3.1.0` | `MIT` |
| `json5` | `2.2.3` | `MIT` |
| `lru-cache` | `5.1.1` | `ISC` |
| `ms` | `2.1.3` | `MIT` |
| `nanoid` | `3.3.16` | `MIT` |
| `next` | `16.2.12` | `MIT` |
| `node-releases` | `2.0.51` | `MIT` |
| `picocolors` | `1.1.1` | `ISC` |
| `postcss` | `8.5.25` | `MIT` |
| `react` | `19.2.8` | `MIT` |
| `react-dom` | `19.2.8` | `MIT` |
| `scheduler` | `0.27.0` | `MIT` |
| `semver` | `6.3.1` | `ISC` |
| `semver` | `7.8.5` | `ISC` |
| `sharp` | `0.35.3` | `Apache-2.0` |
| `source-map-js` | `1.2.1` | `BSD-3-Clause` |
| `styled-jsx` | `5.1.6` | `MIT` |
| `tslib` | `2.8.1` | `0BSD` |
| `undici-types` | `6.21.0` | `MIT` |
| `update-browserslist-db` | `1.2.3` | `MIT` |
| `yallist` | `3.1.1` | `ISC` |

## Build and release maintenance

Before each release:

1. Run `pnpm install --frozen-lockfile` on the target build platform.
2. Run `pnpm licenses list --prod --json` and compare it with this notice.
3. Run `pnpm licenses list --json` and review any license outside the current
   permissive, MPL-2.0, LGPL-3.0-or-later, and CC-BY-4.0 set.
4. Run both the production and full `pnpm audit` checks.
5. Run `pnpm licenses:generate` and review its exception list.
6. Confirm both legal files exist unchanged in `dist/client/`.
