What each artifact is licensed under
The runtime binary redistributes third-party components under their own licenses. The
NOTICE file at the repository root reproduces each one, and the desktop app ships that file with the application.
May a proprietary app ship the runtime binary?
Yes, on three conditions:- The binary is unmodified. Take it byte for byte from a GitHub release of
arul28/ADEor from an@ade-dev/runtime-*npm package. - Your application consumes it through the documented
@ade-dev/sdkinterface. - You keep the runtime’s own license and notices with it.
What stays AGPL-3.0-only
- The runtime binary itself. The exception adds a permission around it; it does not relicense it.
- ADE desktop, the
adeCLI, and every part of this repository outside the two MIT packages. - Any modified runtime. Patching, recompiling, or building from changed ADE source produces a modified work, and the AGPL applies to it in full.
- Any product that links ADE source code, or that drives internal interfaces
@ade-dev/sdkdoes not document.
How the repository keeps this honest
scripts/check-package-licenses.mjs runs in CI for every published package. It asserts that the SPDX identifier in the package metadata, the LICENSE file in the package directory, the file list of the published tarball, and the ## License section of the package README all agree. A relicense that misses any one of those four places fails the build.
The six @ade-dev/runtime-* packages are built by apps/ade-cli/scripts/build-runtime-npm-packages.mjs, which copies both the root LICENSE and RUNTIME-EMBEDDING-EXCEPTION.md into each one and refuses to publish a tarball that carries either file short.