# Third-Party Notices MUSII Storefront is proprietary software. It includes or serves the following third-party software and font assets under their respective licenses. These notices do not change the license of MUSII's own code or brand content. ## Cormorant Garamond Copyright 2015 the Cormorant Project Authors (https://github.com/CatharsisFonts/Cormorant). Licensed under the SIL Open Font License, Version 1.1. The complete license is distributed at `/licenses/cormorant-garamond-OFL.txt`. Source: https://github.com/google/fonts/tree/main/ofl/cormorantgaramond Distributed font files: - `cormorant-garamond-latin-400-600.woff2` — SHA-256 `5d618c462b7a5b74f442e1548880086af71764d9cc7d35c16ab45353da934621` - `cormorant-garamond-latin-ext-400-600.woff2` — SHA-256 `9dc38267bdee93a653200ef3c1e8060e3f1399073432c415c683b419d3b50464` - `cormorant-garamond-latin-italic-400-600.woff2` — SHA-256 `e6d6d1d73858aa9b66f3a3539f9dec22faab2276e61ad1d813bc04dd59c9c122` - `cormorant-garamond-latin-ext-italic-400-600.woff2` — SHA-256 `06bc9a8c179afaf7dd5d3b4987ad2f4a82ca85a542c9e498b18bf32ad0257d8e` ## Manrope Copyright 2018 The Manrope Project Authors (https://github.com/sharanda/manrope). Licensed under the SIL Open Font License, Version 1.1. The complete license is distributed at `/licenses/manrope-OFL.txt`. Source: https://github.com/google/fonts/tree/main/ofl/manrope Distributed font files: - `manrope-latin-300-700.woff2` — SHA-256 `e310b55a7fd9677f5e3555e6c6c4d064fa1f1d24393f0ddbe217cea12a8c432f` - `manrope-latin-ext-300-700.woff2` — SHA-256 `ce093b341d9c10658ee1eaa85c5f8042ff3307bc6ccfc5f405616eb437f0009e` ## Lucide Icons and Feather Icons `lucide-react` is licensed under the ISC License. Some Lucide icons are derived from Feather Icons and are licensed under the MIT License. The complete copyright and license notices supplied by Lucide are distributed at `/licenses/lucide-react-LICENSE.txt`. Source: https://github.com/lucide-icons/lucide ## Sharp and libvips Sharp is licensed under the Apache License 2.0. Its complete license is distributed at `/licenses/sharp-LICENSE.txt`. Sharp can use platform-specific libvips binaries in the server build. libvips is licensed under LGPL-3.0-or-later. Source and license information are available from https://github.com/libvips/libvips and https://www.libvips.org/. ## caniuse-lite Browser compatibility data from `caniuse-lite` is licensed under Creative Commons Attribution 4.0 International. The complete license distributed by the package is available at `/licenses/caniuse-lite-LICENSE.txt`. Source: https://github.com/browserslist/caniuse-lite ## Remaining packages The exact dependency versions, integrity hashes and SPDX license identifiers for the remaining npm packages are recorded in `package-lock.json`. The release license audit must fail if a package lacks a declared license or introduces a GPL, AGPL or SSPL dependency without separate approval.