A GitHub user opened a “License Violations Audit” issue on the Photopea repository alleging that the closed-source, commercially operated image editor distributes third-party open source code in minified JavaScript bundles, WebAssembly binaries, packed database assets and bundled fonts without the source, notices or attribution those licences require. The audit claims critical violations involving FriBiDi compiled to WASM under LGPL-2.1+ and Mediabunny under MPL-2.0, an Apache-2.0 violation for embedded PDF.js code with copyright and licence notices removed, notice stripping across MIT and BSD 3-Clause projects including Paper.js, Acorn, HarfBuzz, pako and Three.js loaders, and zstd and libwebp WASM binaries hidden in base64-encoded DEFLATE streams. The issue was filed as Photopea’s developer accuses the GPL-3.0 Photosuite editor of copying Photopea’s code.
License audit alleges Photopea strips notices from the open source code it bundles
A GitHub user opened a "License Violations Audit" issue on the Photopea repository alleging that the closed-source, commercially operated image editor distributes third-party open source code in minified JavaScript bundles, WebAssembly binaries, packed database assets and bundled fonts without the source, notices or attribution those licences require. The audit claims critical violations involving FriBiDi compiled to WASM under LGPL-2.1+ and Mediabunny under MPL-2.0, an Apache-2.0 violation for embedded PDF.js code with copyright and licence notices removed, notice stripping across MIT and BSD 3-Clause projects including Paper.js, Acorn, HarfBuzz, pako and Three.js loaders, and zstd and libwebp WASM binaries hidden in base64-encoded DEFLATE streams. The issue was filed as Photopea's developer accuses the GPL-3.0 Photosuite editor of copying Photopea's code.
Source: Github