Open Source Licenses
Last updated August 28, 2026
The short version
Orbfile is closed-source software, but it's built on top of open-source libraries, and several of those licenses require us to disclose which packages we use and under what terms. None of the licenses below require Orbfile — or any closed-source product built the same way — to publish its own application source code. This page is that disclosure: a straightforward list of every runtime dependency, its license, and what that license does and doesn't ask of a company shipping a commercial product with it. Each row also links to the exact, unmodified license text shipped inside that package itself — not a paraphrase.
This is a helpful summary, not legal advice. If a license decision matters for your business, read the license text linked from each package's own repository and consult a lawyer.
Runtime dependencies
These are the packages — and, in one case, a directly-vendored font — that ship code or assets into the browser bundle: the ones that actually run or render when someone uses an Orbfile tool. Build-only tooling (TypeScript, Tailwind CSS, ESLint, and similar dev dependencies) is left out, since none of it is ever sent to a visitor's browser.
| Package | License | What it means for SaaS use | Full text |
|---|---|---|---|
| mediabunny^1.45.3 | MPL-2.0 | Weak copyleft, file-level. Safe to use in a closed-source or commercial SaaS product — you don't have to open source your own app. The only obligation is that if you modify Mediabunny's own source files and redistribute them, those specific modified files stay under MPL-2.0. | Full text |
| @mediabunny/mp3-encoder^1.45.3 | MPL-2.0 | Same terms as mediabunny above — safe for commercial/SaaS use, file-level copyleft only applies if you modify and redistribute the package's own source. | Full text |
| @mediabunny/aac-encoder^1.45.3 | MPL-2.0 | Same terms as mediabunny above. | Full text |
| @mediabunny/flac-encoder^1.45.3 | MPL-2.0 | Same terms as mediabunny above. | Full text |
| gifenc^1.0.3 | MIT | Permissive. Free to use, modify, and ship in a commercial product with no obligation beyond keeping the copyright notice in the source distribution. | Full text |
| @fontsource/ibm-plex-mono^5.3.0 | OFL-1.1 | The SIL Open Font License permits bundling and embedding the font in apps and websites, including commercial ones, at no cost. The one restriction: you can't sell the font file itself as a standalone product. | Full text |
| @fontsource/plus-jakarta-sans^5.2.6 | OFL-1.1 | Same terms as IBM Plex Mono above. | Full text |
| Noto Sans (Google)n/a — .ttf files vendored directly, not an npm package | OFL-1.1 | Same OFL terms as the two fonts above. Bundled as raw .ttf files in public/fonts/ (not through npm, so it doesn't appear in package.json) and embedded into PDFs generated by the Markdown/CSV-to-PDF tools, since jsPDF needs an embedded font with broad Unicode coverage to render non-Latin text correctly. | Full text |
| @imagemagick/magick-wasm^0.0.41 | Apache-2.0 | Permissive, with an explicit patent grant from contributors. Safe for commercial/SaaS use with no obligation to open source your own code. ImageMagick statically links roughly twenty third-party codec libraries (libpng, libwebp, libtiff, FreeType, and others — several LGPL-licensed at the library level, which does not affect ImageMagick's own Apache-2.0 terms). Apache-2.0 requires redistributing the attribution notices for those bundled libraries, which is why the row below links to both the license and the separate NOTICE file listing them. | Full text · NOTICE |
| clsx^2.1.1 | MIT | Permissive. Safe for any commercial use. | Full text |
| docx^9.7.1 | MIT | Permissive. Safe for any commercial use. Used to build real, editable .docx Word documents (Markdown/CSV/text → Word) client-side. | Full text |
| html2canvas^1.4.1 | MIT | Permissive. Safe for any commercial use. | Full text |
| jspdf^4.2.1 | MIT | Permissive. Safe for any commercial use. | Full text |
| jszip^3.10.1 | MIT OR GPL-3.0-or-later | Dual-licensed — you may choose either license. Orbfile relies on the MIT option, which is permissive with no obligation to open source your own code. | Full text |
| lucide-react^0.436.0 | ISC | Functionally equivalent to MIT — permissive, safe for commercial use. | Full text |
| mammoth^1.8.0 | BSD-2-Clause | Permissive. Safe for any commercial use, with no obligation to open source your own code. | Full text |
| next16.2.12 | MIT | Permissive. Safe for any commercial use. Orbfile only uses Next.js's static export mode, so no Next.js server code ships to production at all. | Full text |
| pdf-lib^1.17.1 | MIT | Permissive. Safe for any commercial use. | Full text |
| pdfjs-dist^4.8.69 | Apache-2.0 | Permissive, with a patent grant. Safe for commercial/SaaS use. | Full text |
| react^19.2.0 | MIT | Permissive. Safe for any commercial use. | Full text |
| react-dom^19.2.0 | MIT | Permissive. Safe for any commercial use. | Full text |
| xlsx^0.18.5 | Apache-2.0 | Permissive, with a patent grant. Safe for commercial/SaaS use with no obligation to open source your own code. | Full text |
A quick glossary
- Permissive (MIT, ISC, BSD-2-Clause, Apache-2.0): use, modify, and redistribute freely, including in closed-source commercial products. Apache-2.0 additionally includes an explicit patent grant from contributors.
- Weak, file-level copyleft (MPL-2.0):safe to use in a closed-source SaaS product. The copyleft only reaches back to the licensed files themselves — if you modify one of those specific files and redistribute it, that file stays under MPL-2.0. It doesn't extend to the rest of your codebase.
- Font license (OFL-1.1): free to embed and bundle in apps, sites, and commercial products. The one thing it disallows is selling the font file itself as a standalone product.
Bundled codec libraries inside ImageMagick
The @imagemagick/magick-wasmrow above deserves a closer look than the others, because ImageMagick isn't a single-license library — it's a WebAssembly build that statically links roughly twenty separate open-source image codec libraries (libpng, libwebp, libtiff, FreeType, OpenEXR, and others) to actually decode and encode all the formats Orbfile's converter supports. A handful of those — glib, libheif, lqr, and LibRaw — are LGPL-licensed at the individual library level.
That doesn't change what applies to Orbfile. ImageMagick itself, the thing Orbfile actually depends on and calls into, is Apache-2.0. The LGPL terms govern anyone distributing or modifying those specific libraries'own source; Orbfile never touches them directly; it links against the ImageMagick build that already compiled them in. What Apache-2.0 does require of Orbfile is straightforward and unrelated to the LGPL question: if a work carries a NOTICE file, as ImageMagick's does, any redistribution has to include a readable copy of it. The NOTICE file linked above is that copy — the real, unmodified attribution list for every bundled library, exactly as ImageMagick ships it.
Formats we deliberately don't support
A handful of formats are left out on purpose, rather than shipped in a broken or license-questionable state. HEIC/HEIF (the default iPhone photo format) is the current example: no permissively-licensed, production-ready WASM decoder exists for it — the only real option, libheif, is LGPL-licensed, which this page's permissive-only bar rules out. The same reasoning previously excluded AVI, FLV, 3GP, WMA, and AIFF from the video/audio tools. If a business-friendly, browser-ready encoder for one of these ever ships, we'll add support.
Questions
Questions about this page or Orbfile's dependencies can be sent to info@eternlab.com.