# Third-party notices

AskFolio distributes the following browser-side libraries in
`assets/js/vendor/`. They are included locally; the plugin does not load these
scripts from a third-party CDN. Both files are unmodified upstream release
builds, taken from the published npm packages.

| Component | Distributed version | Licence | File | Upstream source |
| --- | --- | --- | --- | --- |
| Marked | 18.0.14 | MIT | `marked.js` (unminified upstream `lib/marked.umd.js`) | https://github.com/markedjs/marked/tree/v18.0.14 |
| DOMPurify | 3.4.16 | MPL-2.0 OR Apache-2.0 (dual-licensed) | `purify.min.js` (upstream `dist/purify.min.js`) | https://github.com/cure53/DOMPurify/tree/3.4.16 |

Both licences are GPL-compatible. DOMPurify's licence texts are at
https://github.com/cure53/DOMPurify/blob/3.4.16/LICENSE and
https://github.com/cure53/DOMPurify/blob/3.4.16/LICENSE-MPL. The Marked MIT
notice is retained at the top of `marked.js`; the DOMPurify licence notice is
retained at the top of `purify.min.js`.

## Human-readable source for the minified file

`purify.min.js` is the upstream minified build. Its unminified source and build
instructions are in the DOMPurify repository at the tag above (`src/`, built
with Rollup via `npm run build`). `marked.js` is shipped unminified.

## Maintenance

Before every public release, check each library's current upstream version,
licence and security advisories, replace the file with the matching upstream
build, update this table, and re-run the rendering checks.

## Branding

`assets/images/niche-clever-logo.png` is the Niche Clever wordmark, included with the
publisher's permission. It is a brand asset and is not licensed for reuse under
the plugin's GPL terms.
