CODABLE 1.0.0 — THIRD-PARTY LICENSE NOTICE Prepared: 2026-08-09 Codable first-party application code, runner code, documentation, and the code-native SVG brand mark are proprietary product material distributed under the applicable Envato license selected at purchase. Interface icons are credited separately below. Codable also distributes or compiles open-source software. Those components remain under their respective licenses. Copyright notices belong to the component authors and contributors. AUTHORITATIVE COMPONENT RECORDS 1. dependency-inventory.json Complete locked inventory for production Composer packages, compiled frontend runtime packages, and the runner build toolchain. Package names, versions, license expressions, and available project links are taken from composer.lock and package-lock files. 2. asset-inventory.json Hash-level inventory of every distributed image, icon, and font file; its source, rights status, use references, and the recoverable record for excluded unused files. 3. LICENSE_COMPATIBILITY.md Family-level redistribution review, including the OSL-3.0 condition and the BSD-3-Clause option selected for Nette's alternative license expression. 4. sbom/application.cdx.json Machine-readable CycloneDX application SBOM generated during the final release build. 5. ../runner/sbom/runner.cdx.json Machine-readable CycloneDX runner runtime SBOM. 6. ../runner/sbom/toolchain.cdx.json Machine-readable CycloneDX runner toolchain SBOM. 7. ../application/vendor/ The final prepared package retains Composer-installed package files, including their distributed LICENSE, COPYING, NOTICE, and README files where supplied upstream. Those package-specific files are the controlling text for each installed Composer component. 8. notices/frontend-runtime-notice.txt MIT and ISC notices covering the license families used by the compiled npm frontend runtime graph. Package-specific copyright information remains attributable to each upstream project listed in dependency-inventory.json and its locked package metadata. 9. notices/runner-toolchain-notice.txt License references for the exact Node.js type declarations, undici types, and TypeScript compiler used to prepare/check the runner. Runner node_modules is not included in the buyer package; npm ci obtains the locked toolchain. 10. notices/lucide-icons-notice.txt Complete Lucide ISC and Feather MIT notice for lucide-react imports, the three standalone public SVG icons, and the conservatively attributed embedded admin line-icon surface. LICENSE EXPRESSIONS PRESENT IN THE LOCKED PRODUCTION GRAPH - MIT - ISC - BSD-2-Clause - BSD-3-Clause - Apache-2.0 - OSL-3.0 - GPL-2.0-only / GPL-3.0-only as upstream alternative expressions for Nette packages; the same packages also declare BSD-3-Clause. The inventory preserves upstream expressions instead of silently rewriting them. Codable selects the BSD-3-Clause option offered by the Nette packages. Consult each installed package's license file and LICENSE_COMPATIBILITY.md for the option and text that applies. FEATURE BOUNDARY The presence of a third-party package or SDK is not a statement that a product integration is enabled. Codable 1.0.0 is free-only. Payment gateways, paid checkout, public API tokens, and deployment connectors are not release-enabled or advertised. Codable's outbound webhooks are a first-party signed delivery protocol; they do not activate any third-party connector or SDK. ASSET AND FONT BOUNDARY The only distributed standalone visual assets are the original code-native Codable SVG mark and three attributed Lucide/Feather SVG interface icons. No font files or remote web fonts are bundled. Exact hashes and use references are in asset-inventory.json. NO STOCK-ASSET CLAIM No third-party stock photograph, music, video, web font, or benchmark asset is identified as included in this buyer download. Separately produced marketplace preview media is outside this package and must be licensed, credited, and disclosed by the Envato author. NO ENDORSEMENT Names and trademarks are used only to identify interoperable services or credited projects. Their owners do not endorse Codable. If a notice appears incomplete, contact the author through the support channel on the Codable CodeCanyon item page with the package name and locked version. Do not send secrets or private data.