Third-party source and credits
Software Licences, Engine Source and Data Credits
LibreChess ships open-source engines, libraries, fonts and open chess data. This page identifies their exact versions, licence terms and source records without presenting the privately held LibreChess application source as open source.
On this page
LibreChess first-party source
Stockfish engine source and build provenance
The browser engine files are GPLv3 software. For each deployed artifact, the release manifest records its byte length and SHA-256, the exact npm package and integrity value, the pinned browser-port source, the pinned Stockfish source, the build variant and the applicable full licence text.
Stockfish 18
LibreChess records this as stockfish@18.0.8, variant lite-single. The pinned source records the build command node build.js --single-threaded --lite -f with Emscripten 3.1.7. The npm package is fixed by its SHA-512 integrity value and git commit 93c994592dcf3b4b21052ab925e9b534df9c0918.
/engines/stockfish-18.0.8-lite-single.js
npm pathbin/stockfish-18-lite-single.js· 21,429 bytes
SHA-2565243fd9b276cab7dfe3ad1d43ab9ead73568fac76468c614242977a210c4a391/engines/stockfish-18.0.8-lite-single.wasm
npm pathbin/stockfish-18-lite-single.wasm· 7,295,411 bytes
SHA-256a8fbc05ec6920b56d7485826dcb02c5ffd2826bcbf751cf973046f237a9096f1
Pinned browser-build source archive · Pinned engine source archive · GPLv3 text
Stockfish Multi-Variant 2019-08-15
LibreChess records this as stockfish.js@10.0.2, variant single-threaded multi-variant WASM and asm.js. The pinned source records the build command ./build.sh. The npm package is fixed by its SHA-512 integrity value and git commit e105072e84cf8ee5dd5219e2c5be29c3b8bf8a5a.
/engines/stockfish-10.0.2/stockfish.js
npm pathstockfish.js· 1,579,948 bytes
SHA-256723fda70117bfa8d5053a7bc4ae50cdc96dc9e3fd41b57627e4dfa0a0025957a/engines/stockfish-10.0.2/stockfish.wasm.js
npm pathstockfish.wasm.js· 96,597 bytes
SHA-256064175042d8b72eb9fba8311b730f6f5cebcfec736494698d675dc433f3bd275/engines/stockfish-10.0.2/stockfish.wasm
npm pathstockfish.wasm· 558,861 bytes
SHA-25645816b436eb8c180acb2c5b9fda0148101f411edbfa6bf919918e0a362eafca8
Pinned browser-build source archive · Pinned engine source archive · GPLv3 text
Libraries, Rust crates and fonts
The build inventories production npm packages, every external Rust crate in the WebAssembly validator’s resolved graph, the web-font packages, and the committed fonts used only to rasterise social cards. Unknown external licence identifiers or changed font hashes fail the compliance build.
- Complete third-party notices and licence texts
- SPDX 2.3 software bill of materials
- Compliance inventory summary
Chess data provenance
The release verifier hashes each generated dataset output. A changed corpus cannot pass until its source record and checksum are deliberately updated. Large upstream objects and exact selection manifests are pinned where the build depends on them.
- lichess chess-openings catalogue
Licence: CC0-1.0
Recorded snapshot: 51a55d956b7ed0b9cd7853893744b1ca39cd2a05
Verified outputs:scripts/data/openings-full.json(084d8608ed8ec483571cf7d7d7094de3868d0b4adafe04152984dcce22b4b3df)src/data/openings.json(5246ba9630a3b8414d98209376b04c6b3a913b823c9e32171d8080dc06916f30) - lichess open puzzle database
Licence: CC0-1.0
Recorded snapshot: 8e7ac6ec246b96ae3943c2c3a1e4dcb72262d6df
Source object: 288,424,217 bytes
Source object SHA-256:e754f2327229caff9880506dfc9541ec7ec7b79bf6d1a19f05c6d3e07e634b09
Canonical 80,000-row slice SHA-256:b01f8f987ba8ae9f0909e1e9afbaf953e52433fae423adcf03b3f9caf99c08f9
Generator revision:f056236667405de0b9455c47019b6999112e2701
Verified outputs:src/data/puzzles.json(b6bdd4ace6f3425d120cf6f28551dde32a6f895c199408a2f20e9367ef086287)src/data/mate-puzzles.json(829ddca7b3a05036299f0be947539e6a78b4df74491db3d3d5c6c4a1617584ac) - Chess Database — selected classic game scores
Licence: CC-BY-4.0
Attribution: Schaigorodsky, Ana (2016). Chess Database. figshare. Dataset. https://doi.org/10.6084/m9.figshare.4276523.v1
Recorded snapshot: 10.6084/m9.figshare.4276523.v1
Source object: 870,891,090 bytes · MD590bed9e33640e7eab354a40dfd1eddb8
Source object SHA-256:86732c0a23421da5985f5ba40d9db9bf2be1f6e2456b88629c35740ae71be54d
Exact selection manifest:scripts/data/classic-game-selection.json(567d00c0d53fbc8948da30f3f33403f2146a5c086c5110d593c6a454a5ef7224)
Provenance note: The importer verifies the complete source archive, streams its sole 3,076,796,490-byte PGN member, scans all 3,561,471 games and requires every selected score to occur exactly the recorded number of times before writing the byte-pinned corpus.
Verified outputs:src/data/classic-games.json(daf343883b5bed24308016f1a0dd8c94b12a5a68b4df036375fb8c6ab523cff0) - Bounded classic-game reference analysis
Licence: GPL-3.0
Recorded snapshot: 03e27488f3d21d8ff4dbf3065603afa21dbd0ef3
Provenance note: The complete evidence set was regenerated with the pinned official binary. The generator validated its SHA-256 and exact UCI identity, verified both NNUE defaults, re-hashed the executable after every search completed, and bound the output to the canonical score-corpus fingerprint.
Verified outputs:scripts/data/classic-analysis-provenance.json(872cc07a66418240fa1ad1c54a343a3c5d82f68b24707a0a52c35ebda28ef5b7)scripts/data/classic-game-analysis.json(0a75ffcb29653fe79a15e232a17334556b9dd41d993fc55eedfd6b6c5026a772)src/data/classic-game-training.json(d6c8aab875d538c4212276bb68165f1344ab5abdf9fca42284403864e52b2e03)
How releases are checked
- Every recorded engine artifact must exist with the exact byte length and SHA-256 in the engine manifest.
- Every engine distribution must link an exact npm git commit, a pinned browser-build source archive, a pinned engine-source archive and a complete deployed GPLv3 text.
- Production npm and resolved Cargo dependencies must declare a reviewed licence; notices and the SPDX SBOM are regenerated from installed package metadata and licence files.
- Committed font and generated chess-data hashes must match their reviewed manifests.
- The deployed copies of all generated compliance records must match the audited build outputs.
Corrections
A wrong version, checksum, source link, attribution or licence classification is a material correction. Use the correction route; if no monitored destination is configured, that page says so explicitly.