v0.3.1 — say what the licences are, and prove which source is running
Pre-releaseStill pre-release. No security review, no Czech eIDAS counsel review. The timestamps are real and independently verifiable; treat the app itself as unfinished.
Live at https://elkojo.github.io/xNotary/
No product behaviour changed in this release. What changed is what the app tells you about itself.
The licences are now stated, and generated from what actually shipped
There were no third-party notices anywhere before this — not in the app, not in the bundle. Now THIRD-PARTY.txt lists every package your browser downloaded with its full licence text, and it is generated at build time from the modules genuinely present in the bundle rather than from a hand-kept list, so it cannot drift from what was served.
The OpenTimestamps client is linked, not bundled
It is the one copyleft dependency that reaches the browser (LGPL-3.0-or-later; everything else is MIT or BSD). Serving a static page is distributing it, so it is no longer folded into the app's own code: it is built on its own into vendor/opentimestamps.js — unminified, not tree-shaken, at a stable path — and loaded as a separate module. Anyone can build their own version of the library, drop it in place of that file, and have the app run against theirs instead. Instructions ship alongside it at vendor/README.md.
Every build links the source it was built from
How it works now shows the exact revision this page was built from and links that commit. Whoever runs xNotary as a service owes its users the source of that version, not a link to the project in general — so the app points at it itself. A build made from uncommitted changes says so and links nothing, rather than pointing at a commit it does not match.
Contributions: DCO, no CLA
CONTRIBUTING.md asks for a Signed-off-by line and nothing else. There is no copyright assignment: xNotary is meant to stay open source, and the services planned around it — archiving, printed certificates, delivery — do not require taking the code proprietary.
Corrected: the README described a product this is not
The lead sentence promised you could "collect qualified electronic signatures", which reads as sending a document out and gathering signatures back. xNotary has no such workflow and cannot have one without a backend. You sign with your own tools; xNotary reads the signed file and names who signed.