# Third-Party Notices — SZL Holdings Flagships **Doctrine v11 LOCKED 749/14/163 | SLSA L1 honest | Generated: 2026-06-03** This file contains notices for third-party libraries used by SZL Holdings flagships. ## Python Dependencies ### FastAPI - **License:** MIT - **Source:** https://github.com/tiangolo/fastapi - **Usage:** API framework for all 5 flagships ### Gradio - **License:** Apache-2.0 - **Source:** https://github.com/gradio-app/gradio - **Usage:** UI framework for HuggingFace Spaces ### Uvicorn - **License:** BSD-3-Clause - **Source:** https://github.com/encode/uvicorn - **Usage:** ASGI server ### httpx - **License:** BSD-3-Clause - **Source:** https://github.com/encode/httpx - **Usage:** HTTP client for inter-flagship calls ### huggingface_hub - **License:** Apache-2.0 - **Source:** https://github.com/huggingface/huggingface_hub - **Usage:** HuggingFace API access ## Infrastructure Components ### UDS Core (Defense Unicorns) - **License:** Apache-2.0 - **Source:** https://github.com/defenseunicorns/uds-core - **Usage:** Kubernetes security baseline (UDS deployment) ### Zarf (Defense Unicorns) - **License:** Apache-2.0 - **Source:** https://github.com/zarf-dev/zarf - **Usage:** Airgap packaging ### Pepr (Defense Unicorns) - **License:** Apache-2.0 - **Source:** https://github.com/defenseunicorns/pepr - **Usage:** Kubernetes admission webhook ## Mathematical Libraries ### Lean 4 (Lean FRO / Microsoft Research) - **License:** Apache-2.0 - **Source:** https://github.com/leanprover/lean4 - **Usage:** Formal verification substrate (lutar-lean) ### Mathlib4 - **License:** Apache-2.0 - **Source:** https://github.com/leanprover-community/mathlib4 - **Usage:** Mathematical library for Lean 4 ## Section 889 Declaration SZL Holdings does NOT use equipment or services from: - Huawei Technologies Company - ZTE Corporation - Hytera Communications - Hangzhou Hikvision Digital Technology Company - Dahua Technology Company This notice is provided in compliance with Section 889 of the 2019 NDAA. **Signed-off-by: Yachay ** **Co-Authored-By: Perplexity Computer Agent ** --- ## Frontier Tabs (3D · Live) — Vendored Visualization Libraries The killinchu operator console (`/elite`) vendors the following open-source visualization libraries locally (served from `/vendor/*`, **no CDN — sovereign / offline**). killinchu adopts their interaction **patterns** and reimplements all tab logic as its own original code; the libraries themselves are used unmodified under their own licenses. No GPL/AGPL code is copied. ### 3d-force-graph / three-forcegraph - **License:** MIT - **Copyright:** (c) Vasco Asturiano (vasturiano) - **Source:** https://github.com/vasturiano/3d-force-graph - **Usage:** Field Net, Autonomy Oversight, MELT, Dark-Vessel Threat Graph 3D entity-link graphs ### globe.gl - **License:** MIT - **Copyright:** (c) Vasco Asturiano (vasturiano) - **Source:** https://github.com/vasturiano/globe.gl - **Usage:** Single-Operating-Picture globe (Live Picture / field view) ### force-graph - **License:** MIT - **Copyright:** (c) Vasco Asturiano (vasturiano) - **Source:** https://github.com/vasturiano/force-graph - **Usage:** 2D force-graph fallback ### Apache ECharts - **License:** Apache-2.0 - **Copyright:** The Apache Software Foundation - **Source:** https://github.com/apache/echarts - **Usage:** MELT golden-metric + Deploy posture charts ### echarts-gl - **License:** Apache-2.0 - **Copyright:** The Apache Software Foundation - **Source:** https://github.com/ecomfe/echarts-gl - **Usage:** GL-accelerated chart rendering ### Cytoscape.js - **License:** MIT - **Copyright:** (c) The Cytoscape Consortium - **Source:** https://github.com/cytoscape/cytoscape.js - **Usage:** 2D graph rendering (existing tabs) ### D3 (d3-force et al.) - **License:** ISC / BSD-3-Clause - **Copyright:** (c) Mike Bostock - **Source:** https://github.com/d3/d3 - **Usage:** Force-layout primitives used by the graph libraries ### Chart.js - **License:** MIT - **Copyright:** (c) Chart.js Contributors - **Source:** https://github.com/chartjs/Chart.js - **Usage:** Sparklines / gauges (existing tabs) ### KaTeX - **License:** MIT - **Copyright:** (c) Khan Academy and contributors - **Source:** https://github.com/KaTeX/KaTeX - **Usage:** Formula rendering ### Three.js - **License:** MIT - **Copyright:** (c) three.js authors - **Source:** https://github.com/mrdoob/three.js - **Usage:** Live 3D Vessel/Drone Health Twin (subsystem digital twin) — `static/vendor/three.min.js` (r160) ### deck.gl - **License:** MIT - **Copyright:** (c) vis.gl contributors / OpenJS Foundation - **Source:** https://github.com/visgl/deck.gl - **Usage:** Live Picture entity scatter+trails, Maritime WEZ threat-ring layers — `static/vendor/deck.min.js` ### Konva - **License:** MIT - **Copyright:** (c) Anton Lavrenov - **Source:** https://github.com/konvajs/konva - **Usage:** Byzantine-consensus 4-node schematic (bft tab) — `static/vendor/konva.min.js` ### sigma.js - **License:** MIT - **Copyright:** (c) Alexis Jacomy, Guillaume Plique (sigma.js authors) - **Source:** https://github.com/jacomyal/sigma.js - **Usage:** Receipt-chain layered DAG (chain tab) WebGL renderer — `static/vendor/sigma.min.js` ### graphology - **License:** MIT - **Copyright:** (c) Guillaume Plique (Yomguithereal) - **Source:** https://github.com/graphology/graphology - **Usage:** Graph model backing the sigma.js DAG — `static/vendor/graphology.min.js` ### dagre - **License:** MIT - **Copyright:** (c) Chris Pettitt - **Source:** https://github.com/dagrejs/dagre - **Usage:** Layered (Sugiyama) layout for the receipt-chain DAG — `static/vendor/dagre.min.js` ### regl - **License:** MIT - **Copyright:** (c) 2016 Mikola Lysenko & regl contributors - **Source:** https://github.com/regl-project/regl - **Usage:** WebGL command compiler underlying regl-scatterplot (sensor-fusion covariance scatter, fused estimate star) — `static/vendor/regl.min.js` ### pub-sub-es - **License:** MIT - **Copyright:** (c) 2018 Fritz Lekschas - **Source:** https://github.com/flekschas/pub-sub-es - **Usage:** Event pub/sub dependency of regl-scatterplot — `static/vendor/pub-sub-es.min.js` ### regl-scatterplot - **License:** MIT - **Copyright:** (c) 2019 Fritz Lekschas - **Source:** https://github.com/flekschas/regl-scatterplot - **Usage:** GPU sensor-fusion covariance-ellipse scatter (fusion tab): multi-sensor detections + Kalman P-covariance eigendecomposition ellipse + fused BLUE estimate (C17) — `static/vendor/regl-scatterplot.min.js` ### @observablehq/plot - **License:** ISC - **Copyright:** (c) 2020-2023 Observable, Inc. - **Source:** https://github.com/observablehq/plot - **Usage:** Maintenance/compliance state timeline (fleetmaint tab): Plot.barX intervals per vessel per maintenance/cert/PSC item (overdue=red) — `static/vendor/plot.umd.min.js` ### d3-sankey - **License:** BSD-3-Clause - **Copyright:** (c) 2015-2019 Mike Bostock - **Source:** https://github.com/d3/d3-sankey - **Usage:** Voyage cargo flow (fleetvoyages tab: port→route→destination, link width=tonnage) and engagement-audit decision flow (audit tab: sensor report→fusion→ROE→engage/deny). Attaches `d3.sankey` to the existing vendored d3 bundle — `static/vendor/d3-sankey.min.js` ### Space Grotesk (self-hosted webfont) - **License:** SIL Open Font License 1.1 (OFL-1.1) - **Copyright:** (c) Florian Karsten - **Source:** https://github.com/floriankarsten/space-grotesk - **Usage:** Display typeface, self-hosted at `static/vendor/fonts/` (no Google Fonts CDN — sovereign) ### JetBrains Mono (self-hosted webfont) - **License:** SIL Open Font License 1.1 (OFL-1.1) - **Copyright:** (c) 2020 The JetBrains Mono Project Authors - **Source:** https://github.com/JetBrains/JetBrainsMono - **Usage:** Monospace typeface, self-hosted at `static/vendor/fonts/` (no Google Fonts CDN — sovereign) ### MINED operational upgrades — adopted PATTERNS + permissive code, EVOLVED clean-room (2026-06-07) The following four upgrades follow the "fashion thinking" doctrine: a permissive (MIT/Apache) open-source project's *pattern* was adopted **WITH attribution**, then reimplemented from scratch (pure-Python, clean-room) and evolved into a killinchu maritime/drone capability. **No upstream source code is copied.** Wired in `killinchu_mined_ops.py` under `/api/killinchu/v1/mined/*`. #### al-jshen/compute - **License:** MIT - **Copyright:** (c) 2020 Jeff Shen - **Source:** https://github.com/al-jshen/compute - **Adopted pattern (evolved clean-room):** small scientific-computing surface — Cholesky/linear solver, Romberg/trapezoid numerical integration, AR(1) Yule-Walker, OLS fit. Reimplemented as the killinchu sensor-fusion/orbital math module: least-squares track fit, Cholesky-gated information-form covariance fusion, Kepler-III orbital period, Romberg energy integral (Sci-Compute tab · `/mined/scicompute`). #### lwaekfjlk/gpu-bartender - **License:** MIT - **Copyright:** (c) 2024 Haofei Yu - **Source:** https://github.com/lwaekfjlk/gpu-bartender - **Adopted pattern (evolved clean-room):** component-sum VRAM model (runtime floor + weights + transformer activations + gradients + Adam moments; bytes/param by precision). Reimplemented and evolved into an EDGE deployment feasibility estimator (drone SoC / field-Mac VRAM budget → FITS/EXCEEDS verdict) (Edge VRAM Estimator tab · `/mined/edge-estimator`). #### mcleish7/MLRC-deep-thinking - **License:** MIT - **Copyright:** (c) 2021 Avi Schwarzschild - **Source:** https://github.com/mcleish7/MLRC-deep-thinking - **Adopted pattern (evolved clean-room):** perturbation-recovery test + Asymptotic-Alignment (AA) score for iterative/recurrent processes. Reimplemented over a mass-conserving swarm averaging-consensus model as a comms/sensor-disruption resilience monitor: recovery-iterations-to-tolerance + AA-style alignment score (Swarm Resilience Monitor tab · `/mined/swarm-resilience`). #### mcleish7/kvpress - **License:** Apache-2.0 (fork of NVIDIA/kvpress) - **Copyright:** (c) NVIDIA Corporation and kvpress contributors - **Source:** https://github.com/mcleish7/kvpress - **Adopted pattern (evolved clean-room):** the "press" idea — score cache entries by expected future attention, prune the lowest-value (SnapKV / ExpectedAttention family). Reimplemented as a priority-weighted telemetry-retention filter (magnitude-spike × source-trust × recency) so the drone retains critical sensor spikes and prunes noise (Telemetry Memory tab · `/mined/telemetry-press`). ### RE-SWEEP wave-2 operational upgrades (PATTERNS adopted WITH NOTICE, evolved clean-room) The following three operational surfaces live in `killinchu_resweep_ops.py` (registered under `/api/killinchu/v1/resweep/*`). Each adopts a permissive (MIT) open-source PATTERN and reimplements it clean-room in pure Python (no upstream code copied; no numpy/torch). All advisory; Λ stays **Conjecture 1**; sample inputs are labelled "not a live feed." #### anvaka/ngraph.path - **License:** MIT - **Copyright:** (c) 2017 Andrei Kashcha - **Source:** https://github.com/anvaka/ngraph.path - **Adopted pattern (evolved clean-room):** the A* / NBA* (bi-directional A*) heuristic graph-search shape. Reimplemented as a maritime tactical router: A*/NBA* over a sea-state cost grid (per-cell current + wind-drift penalty; exclusion zones hard-blocked) with an admissible octile heuristic (Tactical Routing tab · `/resweep/route` modes `grid-astar`, `grid-nba`). #### rowanwins/visibility-graph - **License:** MIT - **Copyright:** (c) 2018 Rowan Winsemius - **Source:** https://github.com/rowanwins/visibility-graph - **Adopted pattern (evolved clean-room):** the polygon-obstacle "visibility graph → shortest path" shape. Reimplemented to route a vessel/drone AROUND landmass / exclusion-zone polygons by building a visibility graph over polygon corners + endpoints and running A* on it (Tactical Routing tab · `/resweep/route` mode `obstacle-avoid`). #### ft2023/IRanker-demo - **License:** MIT - **Copyright:** (c) 2025 Tao Feng - **Source:** https://github.com/ft2023/IRanker-demo - **Adopted pattern (evolved clean-room):** the iterative ranking-foundation-model shape — repeatedly extract the current top item and re-rank the remainder so pairwise context informs the order. Reimplemented as a transparent, auditable vessel "strategic threat score" ranker over the consolidated maritime picture (proximity + closing speed + AIS-gap + sanctioned/dark-vessel + identity-mismatch). **Advisory, NOT a targeting product** (Vessel Threat Ranking tab · `/resweep/threat-rank`). #### al-jshen/adaptive - **License:** MIT - **Copyright:** (c) 2021 Jeff Shen - **Source:** https://github.com/al-jshen/adaptive - **Adopted pattern (evolved clean-room):** the adaptive-sampling shape — concentrate evaluation points where the signal has the most curvature/structure (loss-driven refinement) plus peak detection. Reimplemented as a sensor-fusion efficiency panel: given a constrained sampling budget over a sensor sweep, decide WHERE to spend samples and surface detected contacts (Adaptive Sensor Sampling tab · `/resweep/adaptive-sample`). ### Interaction-model inspirations (PATTERNS only — no code copied) - vasturiano force-graph explorable entity-link model (MIT-compatible) — Field Net tab - GraphRouter / RouteProfile, Tao Feng et al. (arXiv:2605.00180) — Model Atlas routing graph - New Relic / Datadog MELT + service-map — MELT Observability tab - Wiz / CrowdStrike security-graph "toxic path" — Dark-Vessel Threat Graph tab - Defense Unicorns UDS deploy-posture — Deploy Posture tab (uds-core is AGPL: **PATTERN ONLY, NO code copied**) - Governed-run oversight pattern — Autonomy Oversight tab (the proven non-interference kernel is killinchu's own) Copyright (c) of each library belongs to its respective authors. Full license texts ship with each minified bundle's upstream distribution under `static/vendor/`. **Signed-off-by: stephenlutar2-hash **