# Third-party source availability

This page records third-party source-material availability. It is not a
determination that every component is compatible with the application's
proprietary distribution model. Applicable third-party licence rights remain
unaffected.

Verification note, 7 September 2026: the local 1.0.20.0 MSIX includes a
`pillow-heif 1.3.0` wheel with an x265 DLL and a bundled GPLv2 notice. The PE
import table confirms direct linking from its libheif DLL to x265. Its
compatibility with proprietary application distribution remains unresolved.
Publishing component sources alone does not resolve that question. Review the
dependency build and applicable licences before public distribution.

Source requests and retained material:

To request third-party source material, email blacksmith.forge.hub@gmail.com
with the subject "Nexus Arc third-party source request", the application
version (for example 1.0.20.0), and the component or components requested.
The publisher will identify the relevant retained materials and applicable
delivery requirements. Requests do not concern proprietary Nexus source.

A local, release-specific source collection is being retained by the publisher,
with source URLs, full revision IDs, SHA-256 hashes and verification status.
It includes upstream FFmpeg, pillow-heif and its Windows build recipe, libheif,
x265, Qt and PySide/Shiboken material. This collection is not yet certified as the
complete corresponding source of every binary and static dependency shipped.

Distribution method, pending licence review:

Keep the product website limited to lightweight notices and licence documents.
Where corresponding source is required, prefer a separate downloadable archive
containing only the applicable third-party material. Such archives must not be
loaded by the landing page, included in its JavaScript bundle, or contain the
proprietary Nexus application source. No archive host or public download has
been configured yet.

Before distribution, resolve the compatibility issue above and verify:

- the exact `THIRD_PARTY_NOTICES.txt` shipped with Nexus Arc 1.0.20;
- the license files in `Legal/Licenses`;
- corresponding source archives or durable download links for FFmpeg 7.1 and
  every GPL component included in that exact binary build;
- the exact source packages for the `pillow-heif 1.3.0` binary wheel components;
- Qt/PySide6 6.11.0 LGPL source and relinking information;
- a source-delivery method, availability period, notices, and build instructions
  meeting the exact licences and binary distribution method in use.

This request contact is not, by itself, a completed statutory or licence source offer.
Do not rely on a generic email promise as a substitute for the applicable
GPL/LGPL source-delivery requirements.

The exact corresponding-source archive set has not yet been verified for
public distribution. The links below identify upstream source projects;
they must not be read as a completed source offer for the shipped binary.
The legal page links to this document and the available licence materials.

Verified version/revision references from the binary and supplier audit:

- FFmpeg exact provider source commit:
  https://github.com/FFmpeg/FFmpeg/commit/b08d7969c5
- FFmpeg official provider archive and build inventory:
  https://github.com/GyanD/codexffmpeg/releases/tag/7.1
- pillow-heif 1.3.0 and its Windows recipe:
  https://github.com/bigcat88/pillow_heif/tree/v1.3.0
- libheif 1.21.2, also pinned by that Windows recipe:
  https://github.com/strukturag/libheif/releases/tag/v1.21.2
- x265 in the HEIC path, PE version 4.1+1-1d117be:
  https://github.com/Multicorewareinc/x265/commit/1d117be
- x265 in the FFmpeg provider build inventory, 4.0-6-ga009ec077:
  https://github.com/Multicorewareinc/x265/commit/a009ec077
- Qt/PySide6 6.11.0: https://code.qt.io/cgit/pyside/pyside-setup.git/

The old wheel notice links to libheif 1.18.1, x265 3.4 and other older versions.
Those links do not identify the actual libheif/x265 DLLs in this package. The
original notice is preserved as supplier evidence, not endorsed as an exact
binary inventory. The Windows recipe installs some dependencies without
pinning their package revisions; those dependencies and supplier patches still
need correspondence verification. No libaom DLL appears in this HEIC import
chain; the separate FFmpeg binary has its own external-library inventory.

The complete FFmpeg external-library version inventory is preserved in
`Licenses/FFmpeg-7.1-essentials-README.txt`. The public source set must cover
the precise static build, including applicable source and build material for
those external GPL/LGPL components. Upstream links alone are not marked as a
completed corresponding-source offer until the stable public source location
and retained archives are verified.
