NOTICE attribution for Cordova.xcframework.zip in Capacitor SPM 8.5.0 #8626
|
Hello, I am preparing third-party attributions for an app using the Cordova compatibility components distributed with Capacitor SPM 8.5.0. The official Cordova.xcframework.zip SHA-256 is a3dc72b5a559948d548f0ee2926b989492acc1023a0c86a1bf85477587f83a10, matching Package.swift at commit 4f71d0b979f2f957326f04353eca7604ee937e1e. CDV.h references a NOTICE file, but I could not find one in that archive or the pinned Swift package tree. Could you point me to the NOTICE/attribution text applicable to this exact binary, or its corresponding upstream provenance? I am not assuming a historical Cordova NOTICE applies unchanged. Official artifact: https://github.com/ionic-team/capacitor-swift-pm/releases/download/8.5.0/Cordova.xcframework.zip Thank you. |
Replies: 2 comments 1 reply
|
I went through the artifact and its build, since that's the only way to tie this exact binary to a NOTICE. What the zip contains I get the same SHA-256 ( Where the binary comes from
Those sources are adapted copies of The NOTICE text The NOTICE those headers refer to is cordova-ios's. It hasn't changed since 2014 (the last commit touching it is A complete attribution for this binary is therefore:
Apache-2.0 §4(d) is what carries the NOTICE forward into derivative works, which is why it applies even though Capacitor's artifact doesn't include the file. If you want the Capacitor team to confirm it in writing, an issue asking them to add the NOTICE to |
|
Thank you for taking the time to trace the artifact to its source and
explain the NOTICE attribution so clearly. The build details and references
are very helpful for our attribution review. We appreciate your thorough
assistance. Best regards, Eduardo
…On Thu, Oct 1, 2026 at 5:28 PM João Vitor Andrade ***@***.***> wrote:
I went through the artifact and its build, since that's the only way to
tie this exact binary to a NOTICE.
*What the zip contains*
I get the same SHA-256 (a3dc72b5…). There's no NOTICE or LICENSE anywhere
in it. There are only headers such as CDV.h with the standard ASF header
("See the NOTICE file distributed with this work…").
*Where the binary comes from*
capacitor-swift-pm's build-cap script clones ionic-team/capacitor, checks
out the requested version, archives ios/CapacitorCordova as
Cordova.framework and wraps it with xcodebuild -create-xcframework. So
the corresponding source of the 8.5.0 artifact is ionic-team/capacitor at
tag 8.5.0, directory ios/CapacitorCordova.
Those sources are adapted copies of apache/cordova-ios's CordovaLib. Most
classes have been there since early 2018 (the directory's history starts
with a rename in January 2018), and more were copied later, e.g.
CDVWebViewProcessPoolFactory, taken from cordova-ios master in #7096
<#7096> (2023). The Capacitor
repo itself is MIT (ios/LICENSE, "Copyright (c) 2017-present Drifty Co.")
and has no NOTICE file either.
*The NOTICE text*
The NOTICE those headers refer to is cordova-ios's. It hasn't changed
since 2014 (the last commit touching it is 6662fffe, 2014-02-27), so it's
the same for every cordova-ios version Capacitor could have copied from:
Apache Cordova
Copyright 2012 The Apache Software Foundation
This product includes software developed at
The Apache Software Foundation (http://www.apache.org/).
A complete attribution for this binary is therefore:
- the Apache License 2.0 text plus that NOTICE, for the
Cordova-derived code;
- the MIT license (Drifty Co.), for Capacitor's modifications.
Apache-2.0 §4(d) is what carries the NOTICE forward into derivative works,
which is why it applies even though Capacitor's artifact doesn't include
the file.
If you want the Capacitor team to confirm it in writing, an issue asking
them to add the NOTICE to ios/CapacitorCordova (and to the release zip)
would also make the artifact self-describing for the next person.
—
Reply to this email directly, view it on GitHub
<#8626?email_source=notifications&email_token=CPPH6IXUES3UH32EDCGDPD35R3EBLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBXGA2TMNRSUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-18705662>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/CPPH6ISJFSGP2X4YDI65IWL5R3EBLAVCNFSNUABIKJSXA33TNF2G64TZHMYTCMJSGQYTGNZQHNCGS43DOVZXG2LPNY5TCMBYG43TKNBSUF3AE>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/CPPH6IWJDEZUMGTJ6Q4ATDL5R3EBLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBXGA2TMNRSUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVJTG633UMVZF62LPOM>
and Android
<https://github.com/notifications/mobile/android/CPPH6IUUUL4ZQ5XDRVMHFNT5R3EBLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBXGA2TMNRSUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE>.
Download it today!
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
Glad it helped, @crossmathchallenge-hash! If it covers what you needed, could you mark it as the answer (the ⋯ menu on the reply → Mark as answer)? That way the next person looking for the Cordova NOTICE finds it right away.