# Third-party notices AZET Care for Mac assembles the following open-source parts. Each LICENSE was read from the upstream repository for this release. ## usnistgov/macos_security (macOS Security Compliance Project) Rule titles, check commands and references in `vendor/macos_security/rules/` (unmodified YAML copies) and in `Sources/CareCore/Resources/rulepack.json` (generated by `scripts/build_rulepack.py`). Licensed CC BY 4.0, with US-government contributions in the public domain (full text: `vendor/macos_security/LICENSE.md`). https://github.com/usnistgov/macos_security Changes: where the NIST check only passes when a configuration profile enforces the setting (for example `objectIsForcedForKey`), AZET Care uses a derived check of the real setting instead (marked `derived` in the rule pack). Rules marked `nist-verbatim` run NIST's check command as written. Rules marked `azet` are our own. The Korean and plain-English explanations are ours. ## macadmins/sofa The public macOS release feed (https://sofafeed.macadmins.io/v1/macos_data_feed.json) answers "is macOS up to date?". The app reads the version fields of that feed from azet.io (https://suite-api.azet.io/suite/v1/macos-feed), which fetches and caches the feed; the app does not contact the feed host. Apache License 2.0. https://github.com/macadmins/sofa. No SOFA code is included. ## caezium/burrow MIT License, Copyright (c) 2026 Henry Zhang. Ported to Swift in `Sources/CareCore/Cleanup.swift`: leftover classification by path shape, the auto-selection policy (caches, logs, group containers and unknowns are not ticked by default), alias-aware app search, and the "clear data only" subset (from `UninstallPreview.swift` and `UninstallPlan.swift`). Burrow's leftover enumeration lives in a binary Rust engine that is not in the repository, so the enumeration is our own code. > Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND. ## Sparkle MIT License, Copyright (c) 2006-2013 Andy Matuschak, 2009-2013 Elgato Systems GmbH, 2011-2014 Kornel Lesinski, 2015-2017 Mayur Pawashe, 2014 C.W. Betts, 2014 Petroules Corporation, 2014 Big Nerd Ranch. Embedded as `Sparkle.framework` 2.10.0 for in-app updates. https://github.com/sparkle-project/Sparkle (its LICENSE also lists bundled externals such as bspatch and ed25519, all permissive). ## Lucide ISC License, Copyright (c) 2026 Lucide Icons and Contributors (portions derived from Feather, MIT, Copyright (c) 2013-2023 Cole Bemis). The shield-check icon (`assets/lucide-shield-check.svg`) is the base of the app icon. In the app window we use Apple SF Symbols, because bundling Lucide as native vector assets is impractical in SwiftUI. ## Lucide icons (in-app icons, Sources/AZETCare/Icons) lucide-static 0.544.0, ISC License. Copyright (c) for portions of Lucide are held by Cole Bemis 2013-2023 as part of Feather (MIT). All other copyright (c) for Lucide are held by Lucide Contributors 2025. The SVG files are used unchanged; the app draws them at stroke width 1.75. ## YARA (VirusTotal/yara) 4.5.8 The known-threat check runs the YARA command-line scanner as a separate process (`Contents/Helpers/yara`), built from the unmodified v4.5.8 source by `scripts/build_yara.sh` (static, without OpenSSL, jansson or libmagic; hashes through Apple CommonCrypto). BSD 3-Clause License, Copyright (c) 2007-2016 The YARA Authors. Full text: `Contents/Resources/YARA-COPYING.txt`. The `dotnet` module inside it is Copyright (c) 2015 The YARA Authors under the Apache License 2.0. Its Bison-generated parser files carry the Bison exception, which lets them be distributed under YARA's own license. https://github.com/VirusTotal/yara > Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: 1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. 3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES ... ARE DISCLAIMED. ## airbnb/binaryalert rules (macOS) Six macOS malware rules, seventeen macOS tool rules and the `MachO` helper rule from `rules/public` at commit a9c0f06affc35e1f8e45bb77f835b92350c68a0b, copied unchanged into `vendor/yara-rules/binaryalert/` and combined (include lines removed) into `threat-rules.yar`. Apache License 2.0, Copyright Airbnb, Inc. Full text: `Contents/Resources/BinaryAlert-LICENSE.txt`. https://github.com/airbnb/binaryalert ## 100DaysofYARA 2024 rules (macOS) Three macOS rules (`APT_NK_TA444_SpectralBlur` by Greg Lesnewich, `MAL_Lckmac_strings` by @petermstewart, `APT_RU_TOOLMARK_MACOS_MALWARE` by @x0rc1sm) at commit 10b162702cdbecb0752ee4cba6c5a3085d2cdcf9, copied unchanged into `vendor/yara-rules/100daysofyara/`. MIT License, Copyright (c) 2023 100DaysofYARA. Full text: `Contents/Resources/100DaysofYARA-LICENSE.txt`. https://github.com/100DaysofYARA/2024 The names we show for each rule (`threat-rules.json`) are ours. ## KnockKnock 4.1.0 (Objective-See) — separate program, GPL-3.0 The checkup runs the official, unmodified, notarized KnockKnock 4.1.0 release (`Contents/Helpers/KnockKnock.app`, signed by Objective-See, team VBG97UB4TA) as its own program with `-whosthere -skipVT` and reads its JSON output to list shell start-up files, sign-in plugins, library inserts, kernel and system extensions, periodic and startup scripts, Spotlight and Quick Look plugins and other places that start programs. No KnockKnock code is compiled into AZET Care, and `-skipVT` means nothing is sent to VirusTotal. Copyright (c) Patrick Wardle / Objective-See. GNU General Public License v3 (full text: `Contents/Resources/KnockKnock-LICENSE.txt`). Source for this exact version, release checksum and our written offer: `Contents/Resources/KnockKnock-SOURCE.txt`; https://github.com/objective-see/KnockKnock/tree/v4.1.0