The drawio, excalidraw, and mermaid plugin packages redistribute
third-party material (the draw.io webapp, the Excalidraw editor and its
fonts, mermaid and its dependency tree) without the license texts their
licenses require. Every affected ZIP now carries a licenses/ directory:
- licenses/THIRD-PARTY-NOTICES.txt is generated from the esbuild
metafile (packages/plugins/third-party-licenses.mjs), so the notice
list is derived from what actually lands in plugin.js and cannot
drift the way a hand-maintained list would.
- drawio additionally extracts the upstream LICENSE from the pinned
release tarball (Apache-2.0 requires the text with redistribution);
the extraction guard also heals vendor/ caches from before this
change. The CI fast path (no vendor fetch, no ZIP) is unchanged.
- excalidraw additionally commits curated texts (MIT for Excalidraw,
per-font OFL-1.1/MIT with each font's own copyright statement, plus
a FONT-NOTICES.md attribution table), because neither the npm
package nor upstream ships any license files for them.
The api-side package validator accepts additional ZIP entries, so
installed plugins are unaffected beyond the new files.
Closes#345
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012aoPvnakfBP28nAfijgUY9