# Source, license, attribution and modification materials to ship

This private unit contains the materials below. The webowner must arrange public, versioned corresponding-source/notice availability linked through its approved source/notice page and keep those materials available with the deployed version. Version0.3.7 retains a browsable local index, exact manifest and individual ordinary complete component archives/notices/files, avoiding the previous monolithic ZIP. No hosting route is selected or changed by this task. Serve the materials without login, payment or upload requirements. This is a required release action, not an already published URL or legal certification. Do not use the broader app's license as a substitute for component terms.

Required materials:

- Full original Perl5.42.0 distribution `inputs/perl-5.42.0.tar.gz`, including Artistic/GPL COPYING and bundled extension sources; complete ExifTool13.42 distribution `inputs/exiftool-13.42.tar.gz`, its Phil Harvey attribution and terms (same as Perl). Retain original comments/notices. Supply the exact modified `artifacts/exiftool.min.pl` source and recorded signal-handler changes.
- Full original `inputs/zeroperl-source.tar.gz` at commit c28db5dd4fc9660e67117dfdb9f18a43623f5f3d, MIT terms; zlib1.3.1 and bzip2.1.0.8 original source archives and terms. Recipe patches, offline build script, source/input locks, exact compiler/source versions, manifests and reproduction instructions. Official compiler executables and cached Debian .debs need not be part of the source download; exact publisher URLs/hashes and package closure are retained for restoration.
- `notices/` complete component-specific license/attribution files for Perl, ExifTool, zeroperl, compression libraries and linked WASI/musl/cloudlibc/fts/LLVM compiler-builtins exceptions. Retain the SDK exact source commit references and license receipts. Do not flatten all components to Apache2.
- Exact original `vendor/6over3-zeroperl-ts`1.0.10 and `vendor/uswriting-exiftool`1.0.9 JS/TypeScript/package metadata, declared Apache2 terms, upstream identities and author6over3 attribution; the latter package's original LICENSE. The former upstream commit metadata declares Apache2; missing separate LICENSE/NOTICE alone does not prove absent permission. Include the supplied full declared Apache2 text and exact attribution disposition, without inventing upstream copyright/NOTICE text.
- Modified `zeroperl-worker-adapter.js` and `bounded-exiftool-adapter.js` with their prominent modification notices and component attribution. Both original wrappers remain available for comparison. Retain pinned zip.js2.23.0 original BSD3 source/package/LICENSE and any existing original notices.
- Current engine-owned readable module sources, current contract and component inventory. Test-only Playwright may remain private; if redistributed, preserve its original Apache2 materials. No claim is made that these terms apply to unrelated user app code.

The separate local source-notice distribution directory, browsable index and file/hash manifest make this material reviewable before publication. Its presence here does not establish public availability. The webowner must publish the reviewed complete material through the approved source/notice arrangement, verify the actual URL and link the correct version before public beta. Runtime code identity changes require a new unit; notice-only packaging is covered by the outer FILE-MANIFEST.
