veil — third-party components and licenses
==========================================

The veil project AS DISTRIBUTED is licensed under the GNU General Public License
v3.0 (see LICENSE). This is required by its use of the circom / snarkjs toolchain,
which is GPL-3.0. This file records the license of each bundled or depended-on
component. It is informational, not legal advice.

Dependencies (runtime / build)
------------------------------
  snarkjs                  GPL-3.0    proving & verification; bundled in veil-app/vendor/
  circomlibjs              GPL-3.0    BabyJubJub / curve ops; bundled in veil-app/vendor/
  circomlib                GPL-3.0    circuit templates; compiled into circuits + verifiers
  ffjavascript             GPL-3.0    finite-field library; transitive, bundled
  ethers                   MIT        Ethereum JS library; bundled in veil-app/vendor/
  @openzeppelin/contracts  MIT        Solidity base contracts; imported by contracts/

Generated code
--------------
  contracts/verifiers/*    GPL-3.0    snarkjs-generated Groth16 verifiers
                                      (Copyright 2021 0KIMS association)

First-party code
----------------
  circuits/*, sdk/*                          GPL-3.0
      derive from / link circomlib + circomlibjs (marked SPDX GPL-3.0-only)
  contracts/core/*, contracts/interfaces/*   MIT (per-file SPDX)
      original work; MIT is GPL-compatible, so these files may be reused under
      MIT in isolation, while veil as distributed remains GPL-3.0
  veil-app/index.html, scripts/*             part of the GPL-3.0 distribution

License texts
-------------
  GPL-3.0 : LICENSE
  MIT     : LICENSE-MIT

Open question for counsel before public launch
----------------------------------------------
  Whether to keep first-party contracts under MIT (as above) or relabel the entire
  tree GPL-3.0 for uniformity. Both are internally consistent; this is a policy
  choice, not a correctness issue.
