Skip to content

[Bug]: pdfjs-dist ships the QuickJS sandbox (wasm/quickjs-eval.*) without its license file #22143

Description

@AlexAndBear

Attach (recommended) or Link to PDF file

Not applicable, this is about the contents of the pdfjs-dist package.

Web browser and its version

Not applicable

Operating system and its version

Not applicable

PDF.js version

6.4.299 (pdfjs-dist on npm)

Is the bug present in the latest PDF.js version?

Yes

Is a browser extension

No

Steps to reproduce the problem

npm pack pdfjs-dist@6.4.299 && tar -tzf pdfjs-dist-6.4.299.tgz | grep -i -e license -e quickjs

What is the expected behavior?

Like the other bundled third-party code in wasm/ (LICENSE_JBIG2, LICENSE_OPENJPEG, LICENSE_QCMS and their LICENSE_PDFJS_* counterparts) and in standard_fonts/ (LICENSE_FOXIT, LICENSE_LIBERATION), the QuickJS sandbox files come with their license text, so that applications that serve these files (the sandbox has to be served for form scripts) can meet the MIT notice requirement by copying the folder.

What went wrong?

wasm/quickjs-eval.js and wasm/quickjs-eval.wasm are shipped without a license file. external/quickjs/README.md states that QuickJS and pdf.js.quickjs are MIT licensed, but the gulp task that copies the files ("external/quickjs/quickjs-eval.js", "external/quickjs/quickjs-eval.wasm", base external/quickjs) doesn't include a LICENSE_* file, unlike the openjpeg, qcms, jbig2 and standard font tasks next to it.

A LICENSE_QUICKJS (QuickJS, Fabrice Bellard and Charlie Gordon) plus a LICENSE_PDFJS_QUICKJS (pdf.js.quickjs) in external/quickjs/, copied by the same task, would match the existing pattern.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions