# Credits Everything under `vendor/` is unmodified upstream code, kept here so the lab runs offline against a pinned copy of the real library rather than against whatever a CDN is serving today. This file is the inventory. **Generated by `scripts/credits.py`. Do not edit by hand.** Licences are read from the registry per pinned version, not assumed. Re-run the script after changing `scripts/vendor.sh`. 80 vendored items across 12 licences. ## Read this first Most of `vendor/` is permissively licensed and needs nothing but the attribution below. These are the exceptions, and they are the ones that constrain what this project may do: - **react-bits** (5 files) — MIT + Commons Clause. Source-available, not open source. Commons Clause removes the right to sell the software. Hosting a study is not selling it. - **gsap** (3.15.0) — Standard 'no charge' license: https://gsap.com/standard-license. Proprietary. GreenSock's standard licence permits use on a site that does not charge for access, which is what this lab is, but it is not an open-source licence and it does not permit redistributing the source as part of a toolkit. - **aceternity** (3 files) — unstated (source-available). NO LICENCE IS STATED by upstream. The files are published for copying and the registry serves them for that purpose, but nothing grants any rights in writing. ## By licence ### MIT (54) - **7.css** 0.16.0 — - **98.css** 0.1.20 — - **@arwes/animator** 1.0.0-next.25020502 — - **@arwes/bgs** 1.0.0-next.25020502 — - **@arwes/bleeps** 1.0.0-next.25020502 — - **@arwes/frames** 1.0.0-next.25020502 — - **@babel/standalone** 7.28.4 — - **@picocss/pico** 2.1.1 — - **@sakun/system.css** 0.1.11 — - **@tailwindcss/browser** 4.1.13 — - **@webtui/css** 0.1.10 - **@xterm/xterm** 5.5.0 — - **animejs** 4.5.0 — - **ansi_up** 6.0.2 — - **canvas-gauges** 2.1.7 — - **clsx** 2.1.1 — - **crt-fx** 1.0.0 — - **cybercore-css** 0.3.0 — - **dom-accessibility-api** 0.7.1 — - **focus-trap** 8.2.2 — - **framer-motion** 11.18.2 — - **glitch-canvas** 1.1.12 — - **glitched-writer** 2.0.29 — - **hotkeys-js** 4.0.7 — - **interactjs** 1.10.28 — - **jquery** 3.7.1 — Fetched from code.jquery.com. - **jquery.terminal** 2.44.1 — - **latex.css** 1.14.0 — - **lcars.css** main@2026-08 — Vendored from raw.githubusercontent at branch main, so it is pinned to a fetch date rather than a version. - **litegraph.js** 0.7.18 — - **magicui** 3 files — Copy-paste React components, taken from upstream's own distribution point unmodified. - **mos6502** 1.1.1 — - **motion** 13.1.1 — - **motion-primitives** 3 files — Copy-paste React components, taken from upstream's own distribution point unmodified. - **nes.css** 2.3.0 — - **nexusui** 2.1.5 — - **pagedjs** 0.4.3 — - **react** 18.3.1 — - **react-dom** 18.3.1 — - **simple.css** 0.1.3 — - **split.js** 1.6.5 — - **splitting** 1.1.0 — - **tabbable** 6.5.0 — - **tabulator-tables** 6.5.2 — - **tailwind-merge** 2.6.0 — - **terminal.css** 0.7.5 — - **three** 0.185.1 — - **tone** 15.1.22 — - **tufte-css** 1.9.0 — - **tuicss** 2.1.2 — - **uplot** 1.6.32 — - **water.css** 2.1.1 — - **xp.css** 0.2.6 — - **zzfx** 1.3.2 — ### OFL-1.1 (11) - **@fontsource-variable/recursive** 5.3.0 — - **@fontsource/dotgothic16** 5.3.0 — DotGothic16. 29 of 123 upstream subsets, 155 kB. - **@fontsource/ibm-plex-mono** 5.3.0 — - **@fontsource/ibm-plex-sans** 5.3.0 — - **@fontsource/noto-sans-arabic** 5.3.0 — - **@fontsource/noto-sans-kr** 5.3.0 — Noto Sans KR. 7 of 124 upstream subsets, 64 kB. - **@fontsource/noto-sans-thai** 5.3.0 — Noto Sans Thai. 2 of 3 upstream subsets, 19 kB. - **@fontsource/press-start-2p** 5.2.5 — - **@fontsource/rampart-one** 5.3.0 — Rampart One. 20 of 123 upstream subsets, 277 kB. - **@fontsource/reggae-one** 5.3.0 — Reggae One. 20 of 123 upstream subsets, 148 kB. - **@fontsource/stick** 5.3.0 — Stick. 29 of 123 upstream subsets, 228 kB. ### Apache-2.0 (4) - **@paper-design/shaders** 0.0.80 - **asciinema-player** 3.8.1 — - **cyberpunk2077-hacking-solver** da7af2a — Four TypeScript files pinned to a commit, not a release. Upstream LICENSE is kept at vendor/solver/LICENSE. - **winbox** 0.2.82 — ### BSD-3-Clause (2) - **maplibre-gl** 5.6.1 — - **wavesurfer.js** 7.12.11 — ### ISC (2) - **topojson-client** 3.1.0 — - **world-atlas** 2.0.2 — ### BSD-2-Clause (1) - **augmented-ui** 2.0.0 — ### MIT + Commons Clause (1) - **react-bits** 5 files — Copy-paste React components, taken from upstream's own distribution point unmodified. ### MPL-2.0 (1) - **axe-core** 4.10.2 — ### Standard 'no charge' license: https://gsap.com/standard-license. (1) - **gsap** 3.15.0 — ### Unlicense (1) - **ogl** 1.0.11 — ### bsd (1) - **glsl-ntsc-video** 2.0.2 ### unstated (source-available) (1) - **aceternity** 3 files — Copy-paste React components, taken from upstream's own distribution point unmodified. ## The lab's own code Everything outside `vendor/` is MIT, see LICENSE. That covers `lab/`, `examples/`, `scripts/`, the tool pages and the written survey. ## Licence texts `vendor/licenses/` holds each package's own LICENSE file, fetched from the pinned version. MIT, BSD and ISC all require the copyright notice to travel with the code, and publishing a site distributes it, so an SPDX id in a table is not enough on its own. 62 of 67 packages publish a licence file that could be fetched this way. Publishing no licence file at their pinned version, so the SPDX id above and the notice in the vendored file header are all there is: - @webtui/css - gsap - nexusui - ogl - simple.css