MIT License Copyright (c) 2026 Sythos (https://www.sythos.net) Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ================================================================================ APPENDIX — INFORMATIONAL INVENTORY OF NON-MIT LICENSES, PATENTS AND TRADEMARKS ================================================================================ READ THIS FIRST --------------- **Nothing in this appendix applies to, encumbers, or imposes any obligation on the software distributed under the MIT License above.** The implementation and integration work in this package is original work by Sythos. It has ZERO runtime dependencies. No third-party barcode source code is copied into or shipped by the distributed artifact. Public or normative format values may be represented in original Sythos data structures with provenance and legal-review status recorded where required. This appendix exists only because barcode symbologies carry a history of specification copyrights, expired patents and live trademarks, and it is useful to have that history inventoried in one place. It is an ENGINEERING INVENTORY, NOT LEGAL ADVICE. Scoped review labels identify items that need current legal or registry confirmation. If your use case is commercially sensitive, consult a qualified attorney. 1. THE DISTRIBUTED PACKAGE -------------------------- Runtime dependencies ............ none Third-party code included ....... none Third-party licenses that apply . none Effective license ............... MIT, in full, as stated above 2. DEVELOPMENT-TIME TOOLS (NOT DISTRIBUTED OR LINKED) ------------------------------------------------------------------- Tool License Role -------------------------------- ----------- --------------------------- independent barcode various differential encode and implementations decode oracles typescript (tsc) Apache-2.0 runtime compilation and public type checks THE PROJECT RULE, STATED PRECISELY: These tools and public technical materials may be consulted during implementation or testing. No third-party barcode source code is copied into this project's output. Their outputs may be compared against ours as testing evidence. Public or normative values are represented in original Sythos structures with provenance and legal review where required. None of this is a legal conclusion about derivative works or license obligations. typescript (tsc) is not a barcode library and carries no symbology logic at all. It is a development-only compiler and validator: it compiles this project's own TypeScript runtime source into JavaScript and checks its public declarations. TypeScript is not a runtime dependency and does not contribute barcode data or algorithms. No barcode library is a dependency of this package. None of the tools above is a runtime dependency, none ships in the published package, and running or not running any of them changes nothing about the distributed JavaScript. Should any of them ever be proposed as a runtime dependency, this section must be revisited — the zero-dependency rule exists to prevent exactly that. 3. SPECIFICATION DOCUMENTS -------------------------- Specification TEXT is copyrighted by its publisher. The SYMBOLOGIES the text describes are not — an encoding scheme is a system, not a work of authorship. This project implements the symbologies; it does not reproduce, redistribute or excerpt the specification documents. Document Publisher / rights holder -------------------------------- --------------------------------------- ISO/IEC 18004 (QR Code) ISO/IEC — copyrighted, paywalled ISO/IEC 16022 (Data Matrix) ISO/IEC — copyrighted, paywalled ISO/IEC 15438 (PDF417) ISO/IEC — copyrighted, paywalled ISO/IEC 24778 (Aztec) ISO/IEC — copyrighted, paywalled ISO/IEC 16023 (MaxiCode) ISO/IEC — copyrighted, paywalled ISO/IEC 15417 (Code 128) ISO/IEC — copyrighted, paywalled Codablock-F / Code 16K AIM / public descriptions; terms vary [TO VERIFY] ISO/IEC 16388 (Code 39) ISO/IEC — copyrighted, paywalled ISO/IEC 16390 (ITF) ISO/IEC — copyrighted, paywalled JIS X 0502 (ITF-6 add-on) Japanese Standards Association; terms vary [TO VERIFY] AIM USS Code 25 / 2-of-5 family AIM Inc. — terms vary [TO VERIFY] Data Logic 2 of 5 (China Post) vendor/operator-associated public descriptions; terms vary [TO VERIFY] ISO/IEC 15420 (EAN/UPC) ISO/IEC — copyrighted, paywalled ISO/IEC 23941 (rMQR) ISO/IEC — copyrighted, paywalled ISO/IEC 24724 (GS1 DataBar) ISO/IEC — copyrighted, paywalled ISO 2108 (ISBN numbering) ISO — copyrighted; the numbering scheme, not a symbology JIS X 0501 (JAN numbering) Japanese Standards Association; the numbering convention, not a symbology [TO VERIFY] ISO/IEC 24723 (GS1 Composite) ISO/IEC — copyrighted, paywalled GS1 General Specifications GS1 — freely downloadable; redistribution terms are GS1's own [TO VERIFY] AIM symbology specifications AIM Inc. — terms vary [TO VERIFY] GB/T 21049 (Han Xin Code) SAC (China) [TO VERIFY] USPS publications (POSTNET, PLANET, Intelligent Mail, FIM) USPS — published openly [TO VERIFY] Royal Mail RM4SCC, KIX, Australia Post, Japan Post respective postal operators; public material and usage terms vary [TO VERIFY] KarTrak ACI (AAR Automatic Car no surviving purchasable AAR standard Identification) document; implemented from cross-verified public technical descriptions, see licenses/kartrak-aci.license [TO VERIFY] PostBar (Canada Post CPC CPC's own engineering spec is not four-state bar code) published; implemented from the disclosure in US Patent 5,602,382A (expired), see licenses/postbar.license [TO VERIFY] DX Film Edge Barcode no separate published standard; the only detailed disclosure is US Patent 4,965,628A (expired), cross-checked against real-sample literature, see licenses/dx-film-edge-barcode.license [TO VERIFY] ISO/IEC 23634 (JAB Code) ISO/IEC — copyrighted, paywalled; no free copy located. Implemented from the reference implementation's own source (github.com/jabcode/jabcode, MIT since April 2026) instead, consulted for understanding only, see licenses/jab-code.license 4. PATENT POSITIONS ------------------- Barcode patents from the 1990s have broadly expired, and several rights holders issued public statements permitting free use. NONE OF THE FOLLOWING HAS BEEN INDEPENDENTLY VERIFIED BY THE AUTHOR. Treat every entry as a research pointer. Symbology Rights holder Reported position ------------- ----------------- -------------------------------------- QR Code DENSO WAVE patent rights reportedly not exercised for standardised QR [TO VERIFY] Micro QR DENSO WAVE assumed to follow QR [TO VERIFY] rMQR DENSO WAVE standardised 2022 — MUCH NEWER; do NOT assume the older QR position covers it [TO VERIFY — PRIORITY] DENSO FrameQR DENSO WAVE proprietary product; public material is not a native implementation [LEGAL REVIEW] Data Matrix orig. RVSI/CiMatrix ECC200 reported released for public use [TO VERIFY] PDF417 orig. Symbol Tech. reported released for public use [TO VERIFY] Aztec Code orig. Welch Allyn reported placed in the public domain [TO VERIFY] MaxiCode UPS reported released for public use [TO VERIFY] DotCode AIM open AIM standard [TO VERIFY] Han Xin Code Chinese nat'l std status under GB/T 21049 [TO VERIFY] GS1 Composite GS1 / ISO/IEC 24723 component and patent status require current jurisdictional review [TO VERIFY] DataBar/GS1 GS1 published for open use [TO VERIFY] Code 128 / 39 / 93 / Codabar / ITF / MSI / Plessey / Code 11 / Telepen / Pharmacode originating patents long expired [TO VERIFY] Code 25 / Industrial 2-of-5 / IATA 2-of-5 / Code 32 / PZN application profiles and originating patents require current status review [TO VERIFY] Data Logic 2 of 5 (China Post) same 2-of-5-family era; vendor (Datalogic) and operator (China Post) association requires current status review [TO VERIFY] Matrix 2 of 5 same 2-of-5-family era as Data Logic (shares its digit table); status review required [TO VERIFY] Postal 4-state family operator-specific rights and indicia/certification terms require jurisdictional review [TO VERIFY] Facing Identification Mark (FIM) same USPS publication basis as the postal 4-state family; status review required [TO VERIFY] Codablock-F / Code 16K originating patents and current trademark positions require review [TO VERIFY] KarTrak ACI foundational scanning patent (US 3,225,177, granted 1965) and later Servo Corp. refinements (1976-1982) all expired under the pre-1995 17-year term [TO VERIFY] PostBar (C10/D22/G12 profiles) only disclosed via US Patent 5,602,382A, filed 1994, expired ~2014 under the 20-years-from-filing term [TO VERIFY] DX Film Edge Barcode originating patent US 4,965,628A (filed 1989, granted 1990) expired ~2007; extension patent EP0838718B1/ US5872616A expired ~2017 [TO VERIFY] JAB Code no known patents identified; the reference implementation itself was LGPL until re-licensed MIT in April 2026 — a licensing choice, not evidence either way on patents [TO VERIFY] Formats whose status could not be established as clearly redistributable are NOT IMPLEMENTED by this project. See section 6. 5. TRADEMARKS ------------- **A trademark is not a license.** These marks do not restrict anyone's right to implement the corresponding symbology. They restrict BRANDING — how a product names and presents itself. Mark Holder ----------------------- ----------------------------------- QR Code(R) DENSO WAVE INCORPORATED Micro QR, rMQR DENSO WAVE INCORPORATED FrameQR(R) DENSO WAVE INCORPORATED [LEGAL REVIEW] Aztec Code originally Welch Allyn [TO VERIFY] MaxiCode United Parcel Service of America GS1, GS1 DataBar, GS1 DataMatrix, GS1-128 GS1 AISBL Data Matrix [status TO VERIFY] Telepen SB Electronic Systems Ltd [TO VERIFY] Data Logic, China Post Datalogic S.p.A.; China Post Group [TO VERIFY] Code 32 / PZN descriptive pharmaceutical identifiers; no proprietary mark asserted here [TO VERIFY] KarTrak formerly GTE Sylvania / Servo Corporation of America; system defunct and unused since 1978 [TO VERIFY] PostBar, Canada Post Canada Post Corporation [TO VERIFY] DX, Kodak Eastman Kodak Company [TO VERIFY] All marks are the property of their respective owners and are used here in a purely descriptive, nominative sense — to identify which symbologies this software reads and writes. PRACTICAL CONSEQUENCE: this package may accurately describe itself as implementing QR Code, Aztec Code, MaxiCode and so on. It must NOT be NAMED after any of those marks. A descriptive package name is required. 6. EXPLICITLY NOT IMPLEMENTED — PROPRIETARY OR UNCLEAR STATUS ------------------------------------------------------------- Deliberately excluded because they are proprietary, license-encumbered, or of status too unclear to redistribute an implementation with confidence: Digimarc Barcode ........ proprietary, Digimarc Corporation VeriCode / VSCode ....... proprietary, Veritec Inc. DataGlyphs .............. proprietary, Xerox Snowflake Code .......... proprietary, Marconi Data Systems ShotCode ................ proprietary Microsoft Tag ........... proprietary, discontinued Bokode .................. research project, unclear implementable spec; also an active MIT patent, US8366003B2, through 2030 -- see docs/guides/legal-exclusions.md Softstrip ............... obsolete, unclear status Codablock A .............. real, structurally distinct from the already-implemented Codablock-F (Code 39 rows, mod-43 checksum); its only known standard citation, AIM USA's 1994 "TSC052 - Codablock A (39)," could not be found published anywhere; no major open-source library implements it either [TO VERIFY] Code 49 ................... founding patent expired and the ANSI/AIM BC6-2000 spec is genuinely public, but its own Appendix F -- the 2401-entry symbol-character bar-pattern table -- prints only a 260-row sample and states the complete table AND the generation program are a paid/request-only AIM deliverable, not publicly derivable [TO VERIFY] Ultracode ............... status unresolved [TO VERIFY] WeChat Mini Program Code genuinely distinct ring-shaped symbology, (a.k.a. "sunflower code")not a skinned QR code; Tencent does not publish the bit-level format, only incomplete community reverse-engineering exists, and the shared ring/dot/arc/ positioning-point/logo architecture is explicitly claimed by an active patent (US12204967B2, Alipay.com Co., Ltd., active through 2042); also functionally coupled to Tencent's backend (only server-side generation, tied to a registered Mini Program AppID) [TO VERIFY] DENSO FrameQR ........... proprietary format; this project implements only a separate FrameQR Code profile [LEGAL REVIEW] If any of these is later confirmed to be freely implementable and redistributable, it may move into scope — and this section must be updated in the same commit. 7. MAINTENANCE RULE ------------------- This appendix is normative for the project's process, not for its users. Any change to the dependency set, the oracle tools, or the implemented format list MUST update this file in the same commit. A "[TO VERIFY]" marker may only be removed together with a citation recorded in NOTICE.md. Last reviewed: 2026-09-01