Immutable notice version: owner-canary-third-party-notices-0.1.0-15
Target: Debian arm64, Raspberry Pi 5
Approved: 27 August 2026
This document is the complete human-readable notice for release 0.1.0-15. It uses the exact dependency inventory independently reproduced and verified in unsigned engineering rehearsal 0.1.0-15-rc1; that rehearsal is technical evidence only and must not be signed, published or promoted. Earlier technical candidate 0.1.0-14 remains permanently unsigned and must never be patched, signed or published. The native 0.1.0-15 build must reproduce and reconcile this inventory. The release checks fail if any bundled shared runtime is unattributed or if the actual built inventory differs. Any substantive licence or component drift requires fresh review before signing. Complete licence and copyright texts, the SPDX SBOM and the cryptography upstream CycloneDX SBOMs accompany the built package. If this summary and an included licence text differ, the included licence text controls for that third-party component.
No file described in this notice grants rights in Layer400's proprietary receiver application code.
1. Components distributed in the receiver package
Nuitka 4.1.3
- Purpose: compiles and assembles the source-free Layer400 Python application runtime.
- Licence: GNU Affero General Public License v3 or later with the Nuitka runtime exception.
- Supplied texts:
LICENSE.Nuitka,LICENSE-RUNTIME.Nuitka. - Note: Layer400 relies on the runtime exception for the compiled proprietary application. The Nuitka source itself is not modified or distributed as an application source component.
CPython 3.13
- Purpose: compiled interpreter and standard-library runtime modules used by the standalone executable.
- Licence: Python Software Foundation License Version 2 and the historical notices contained in Debian's complete CPython copyright file.
- Verified technical-build baseline and required 0.1.0-15 packages: Debian
libpython3.13-stdlibandlibpython3.13-minimal3.13.5-2+deb13u4. - Complete Debian notice and runtime mapping:
COPYRIGHT.Debian.libpython3.13-stdlib_arm64plusbundled-runtime-debian-packages.json.
cryptography 49.0.0
- Purpose: Ed25519, X.509, TLS and device-identity operations.
- Licence: Apache License 2.0 or BSD 3-Clause, at the recipient's option.
- Supplied texts:
LICENSE.cryptography,LICENSE.APACHE.cryptography,LICENSE.BSD.cryptography. - Transitive native inventory: the exact upstream CycloneDX documents shipped in the wheel are included as
SBOM-CycloneDX.cryptography.jsonandSBOM-CycloneDX.cryptography-rust.json.
cffi 2.1.1
- Purpose: foreign-function runtime used by the cryptography stack.
- Licence: MIT.
- Supplied text:
LICENSE.cffi.
pycparser 3.0
- Purpose: cffi dependency.
- Licence: BSD 3-Clause.
- Supplied text:
LICENSE.pycparser.
Eclipse Paho MQTT 2.1.0
- Purpose: MQTT 5 client with application-level acceptance receipt handling.
- Licence: Eclipse Public License 2.0 or BSD 3-Clause.
- Supplied text:
LICENSE.paho-mqtt.
Protocol Buffers 7.35.1
- Purpose: observation protocol runtime.
- Licence: BSD 3-Clause.
- Supplied text:
LICENSE.protobuf.
OpenDroneID core C
- Reviewed commit:
4b266c7c33e5299bfbe8427ed8518e869e3a7d7f. - Purpose: compiled into the native Wi-Fi Beacon Remote ID capture boundary.
- Licence: BSD 3-Clause.
- Supplied text:
LICENSE.opendroneid-core-c. - Reviewed upstream source archive SHA-256:
841e1c8cfdefe9c768787016be7673b65c6dc97fa9d496610d804ee9246e11d2.
FlightAware dump1090
- Reviewed commit:
74f9e6c4b0efe35c27e6806f8f0d9bbe49b8a6b1. - Purpose: optional Layer400-managed ADS-B decoder.
- Licence: GPL-2.0-or-later.
- Supplied text:
LICENSE.flightaware-dump1090. - Upstream source archive SHA-256:
1151849cd62533b4f73a4e16a6791d9dd6b3265dc2506986e62635cc6ba88afa. - Layer400 serial-selection patch SHA-256:
f46f6ba72edf348950e833dd3c1dc6084452d887488b0ea48b08b5f88f6a69e0. - Complete corresponding source:
THIRD_PARTY_SOURCE-layer400-receiver-0.1.0-15.tar.gz, containing the exact upstream archive, reviewed patch and build instructions. It contains no Layer400 proprietary application source. The release must not be signed unless this exact archive is generated and independently verified.
2. Debian shared runtimes copied into the standalone executable
The 0.1.0-15 notice carries forward the exact copied-runtime set independently reproduced and attributed in the successful native 0.1.0-15-rc1 engineering rehearsal. The 0.1.0-15 package inspector and SPDX SBOM must reproduce the exact set below before signing:
| Component | Exact Debian ARM64 package/version | Licence summary | Complete notice embedded as |
|---|---|---|---|
| bzip2 | libbz2-1.0 1.0.8-6 | bzip2 licence | COPYRIGHT.Debian.libbz2-1.0_arm64 |
| OpenSSL | libssl3t64 3.5.6-1~deb13u2+rpt1 | Apache-2.0 | COPYRIGHT.Debian.libssl3t64_arm64 |
| Expat | libexpat1 2.8.2-1~deb13u1 | MIT | COPYRIGHT.Debian.libexpat1_arm64 |
| XZ Utils/liblzma | liblzma5 5.8.1-1+deb13u1 | BSD Zero Clause (0BSD) for the copied liblzma runtime; the complete Debian source-package notice is included | COPYRIGHT.Debian.liblzma5_arm64 |
| SQLite | libsqlite3-0 3.46.1-7+deb13u1 | public-domain dedication and Debian packaging notices | COPYRIGHT.Debian.libsqlite3-0_arm64 |
| util-linux libuuid | libuuid1 2.41-5 | BSD 3-Clause for libuuid; see complete Debian notice | COPYRIGHT.Debian.libuuid1_arm64 |
| Zstandard | libzstd1 1.5.7+dfsg-1 | BSD 3-Clause or GPL-2.0-only; see complete Debian notice | COPYRIGHT.Debian.libzstd1_arm64 |
The generated bundled-runtime-debian-packages.json maps every copied ELF/shared-runtime filename to exactly one of the above components or to the cffi/cryptography wheel inventory. The release inspector requires the mapping to equal the actual packaged runtime set and verifies every ELF is AArch64.
3. Build-only tools not distributed as receiver application components
The pinned private build uses the following third-party tools. They are disclosed for provenance; their Python packages are not installed on the customer Pi as source or bytecode:
ordered-set 4.1.0— MIT; Nuitka build dependency;LICENSE.ordered-setis retained.patchelf 0.17.2.4— GPL-3.0-or-later; used during standalone assembly.setuptools 80.9.0— MIT; build tooling.wheel 0.45.1— MIT; build tooling.- Debian compiler, linker, debhelper and packaging tools — build-host tooling recorded in the private
.buildinfoevidence.
4. Dynamically linked distribution dependencies
The Debian package declares its runtime dependencies through ${shlibs:Depends} and explicit package dependencies. Libraries supplied by Raspberry Pi OS/Debian rather than copied into /usr/lib/layer400/receiver remain distribution packages and retain the copyright files installed by that distribution. This includes system facilities used by the native capture executables, such as glibc, libpcap, ncurses and rtl-sdr where installed. They are also recorded by Debian package metadata and the private build evidence.
5. Proprietary boundary
The following are not placed in the public corresponding-source archive, public release files, logs or support bundles:
- Layer400 application source or bytecode;
- source maps, tests, VCS data or private build paths;
- private debugging symbols or private build evidence;
- account, claim, signing, device or infrastructure secrets; and
- non-public infrastructure addresses.
Private debugging symbols and build evidence are retained only in the Licensor's access-restricted private release-evidence store.
Final approval checks
The exact 0.1.0-15-rc1 engineering rehearsal passed source-free inspection and SBOM reconciliation, verified all referenced notices inside the inspected .deb, attributed 8 bundled runtime components, and independently verified the three-member GPL corresponding-source archive and both reviewed source hashes. It remains unsigned technical evidence only. Earlier 0.1.0-14 remains permanently unsigned technical evidence only. Release 0.1.0-15 must pass the same checks with the approved legal texts before signing.