# Third-party notices

AegisAC integration source is distributed under GPL-3.0-or-later.

- GrimAC: official supplied 2.3.73 binary and tagged source at commit 879d566c05bc6b03918c5f24bb5da1a209352b99, included in upstream/GrimAC-v2.3.73-source.zip. GPL-3.0. All native check, prediction, collision, compensation, dispatcher, block helper and setback implementations are unchanged. Four integration classes differ: loader extensibility, statistics initialization, public alert output, and original punishment-action tagging. Native detector tolerances are retained. The external punishment profile is custom. https://github.com/GrimAnticheat/Grim
- DonutAC: supplied DonutAntiCheat 1.0.0 artifact. Five original listener classes are unchanged. Lifecycle ownership, raw output and punishment dispatch are adapted for the single plugin. This artifact has not been authenticated as the private Donut SMP anticheat, and no affiliation or endorsement is claimed. Its supplied artifact does not identify a distribution licence; this deliverable is for the user's existing private server use. Original and compatibility binaries are retained as build inputs, and current integration/patch source is supplied.
- Paper API and API dependencies are compile/test-only inputs in lib/. They are not copied into AegisAC.jar. https://github.com/PaperMC/Paper
- Grim's shaded runtime dependencies retain their upstream licences and metadata from the original input, except conflicting plugin metadata and signatures.

No Hawk or NoCheatPlus detection code is included in R14. The Aegis detector and cross-engine evidence engine have been removed. Aegis remains the plugin's name and administration/output layer.

The delivered Donut input JARs have their bundled webhook URL cleared; their detector/listener class bytes are preserved. qa/input-resource-sanitization.json records original received and sanitized hashes. No webhook credential is included in this release.

Meteor, Wurst and LiquidBounce source snapshots were examined for module names and behavior. Their code is not copied into the plugin or distributed as client code in this release. The inventory contains factual names, paths, pinned commits, hashes and coverage notes. Official source URLs are recorded in qa/research/client-inventory-provenance.json.

lib/linkage-api-dependencies.jar contains test-only ViaVersion 5.5.0, PlaceholderAPI 2.11.6, Netty 4.1.85 API classes and LuckPerms API 5.4. These are used to reflectively verify declarations that reference optional plugin APIs; they are not embedded in the production JAR and the optional plugins were not installed during live QA. Original dependency metadata is retained. Input hashes are recorded in qa/linkage-inputs.json.


R15 lead engine: upstream 2.3.74-abb95b6 (alpha), commit abb95b6cac22643ff2cf0b9bc63909daebadf4c6. Corresponding source is bundled in lib/grim-corresponding-source.tar.gz. GPL notices remain. The older 2.3.73 references above describe the R14 baseline.
