tirith
Copyright 2026 tirith contributors

This product includes software and data from third parties:

---

Unicode Consortium — confusables.txt
  Source: https://www.unicode.org/Public/security/latest/confusables.txt
  License: Unicode License v3 (https://www.unicode.org/license.txt)
  Used for: Homoglyph / confusable domain detection

---

Mozilla Foundation — Public Suffix List
  Source: https://publicsuffix.org/
  License: Mozilla Public License 2.0 (MPL-2.0)
  Used for: Registrable domain extraction (eTLD+1)

---

OpenSSF — malicious-packages
  Source: https://github.com/ossf/malicious-packages
  Pinned revision: 54642f7ee96e780b046660519b028fefb635375a
  License: Creative Commons Attribution 4.0 (CC-BY-4.0)
  Used for: Confirmed malicious package, artifact, and network records

---

Datadog Security Labs — malicious-software-packages-dataset
  Source: https://github.com/DataDog/malicious-software-packages-dataset
  Pinned revision: 2d09839012cedc387ce438debeb77884ac2a242c
  License: Apache License 2.0 (Apache-2.0)
  Used for: Human-triaged npm and PyPI malicious package manifests

---

ecosyste.ms — typosquatting-dataset
  Source: https://github.com/ecosyste-ms/typosquatting-dataset
  Pinned revision: fd0bde98d200efe5c282a07edc4c68fba13252c6
  License: CC0 1.0 Universal (CC0-1.0)
  Used for: Confirmed package-to-target typosquat mappings

---

abuse.ch — Feodo Tracker IP Blocklist
  Source: https://feodotracker.abuse.ch/downloads/ipblocklist.txt
  License basis: abuse.ch Terms of Service (LicenseRef-abuse-ch-terms)
  Used for: Runtime-fetched botnet command-and-control IPv4 indicators

---

Cybersecurity and Infrastructure Security Agency — Known Exploited Vulnerabilities
  Source: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
  License basis: United States Government work (LicenseRef-US-Government-Work)
  Used for: Runtime-fetched exploited-vulnerability correlation metadata

---

npm Registry and Python Package Index — package version metadata
  Sources: https://registry.npmjs.org/ and https://pypi.org/pypi/
  License basis: factual registry metadata (LicenseRef-Registry-Metadata)
  Used for: Build-time exact-version materialization of bounded OpenSSF ranges

---

Tirith Web3 package comparison anchors
  Sources: exact registry URLs recorded in
           crates/tirith/assets/data/web3_package_anchors.SOURCE.md
  License basis: factual package identifiers (LicenseRef-Package-Name-Facts)
  Used for: Non-authoritative package-name similarity comparison

---

npm Registry: captured `npm audit signatures` output
  Source: registry.npmjs.org, via `npm audit signatures --json
           --include-attestations` on npm 11.17.0
  Local files: crates/tirith/tests/fixtures/npm_audit_signatures/
               npm11_clean.json and npm11_clean_package-lock.json
  License basis: factual registry metadata (LicenseRef-Registry-Metadata)
  Used for: The single fixture that backs the closed `npm audit signatures`
            contract table. It carries registry-produced integrity digests,
            key IDs, and Sigstore bundles for the published releases
            chalk@5.4.1 and semver@7.8.5. Every other file in that directory is
            synthesized from npm's own source and is original to this
            repository; see the directory README for the split.

---

Bitcoin BIPs contributors — BIP-0039 English wordlist
  Copyright: Bitcoin BIPs contributors
  Source: https://github.com/bitcoin/bips/blob/ed4ffcb6a48d4dc4fdfc11cdba783c233db8c66e/bip-0039/english.txt
  Upstream revision: ed4ffcb6a48d4dc4fdfc11cdba783c233db8c66e
  Local SHA-256: 2f5eed53a4727b4bf8880d8f3f199efc90e58503646d9ff8eff3a2ed3b24dbda
  License: MIT (SPDX-License-Identifier: MIT)
  Used for: BIP-39 English word membership and checksum validation
