Skip to content

v0.3.1 — say what the licences are, and prove which source is running

Pre-release
Pre-release

Choose a tag to compare

@elkojo elkojo released this 26 Aug 09:26
· 100 commits to main since this release

Still pre-release. No security review, no Czech eIDAS counsel review. The timestamps are real and independently verifiable; treat the app itself as unfinished.

Live at https://elkojo.github.io/xNotary/

No product behaviour changed in this release. What changed is what the app tells you about itself.

The licences are now stated, and generated from what actually shipped

There were no third-party notices anywhere before this — not in the app, not in the bundle. Now THIRD-PARTY.txt lists every package your browser downloaded with its full licence text, and it is generated at build time from the modules genuinely present in the bundle rather than from a hand-kept list, so it cannot drift from what was served.

The OpenTimestamps client is linked, not bundled

It is the one copyleft dependency that reaches the browser (LGPL-3.0-or-later; everything else is MIT or BSD). Serving a static page is distributing it, so it is no longer folded into the app's own code: it is built on its own into vendor/opentimestamps.js — unminified, not tree-shaken, at a stable path — and loaded as a separate module. Anyone can build their own version of the library, drop it in place of that file, and have the app run against theirs instead. Instructions ship alongside it at vendor/README.md.

Every build links the source it was built from

How it works now shows the exact revision this page was built from and links that commit. Whoever runs xNotary as a service owes its users the source of that version, not a link to the project in general — so the app points at it itself. A build made from uncommitted changes says so and links nothing, rather than pointing at a commit it does not match.

Contributions: DCO, no CLA

CONTRIBUTING.md asks for a Signed-off-by line and nothing else. There is no copyright assignment: xNotary is meant to stay open source, and the services planned around it — archiving, printed certificates, delivery — do not require taking the code proprietary.

Corrected: the README described a product this is not

The lead sentence promised you could "collect qualified electronic signatures", which reads as sending a document out and gathering signatures back. xNotary has no such workflow and cannot have one without a backend. You sign with your own tools; xNotary reads the signed file and names who signed.