TagLib 2.3.1 — corresponding source information App: Lyrics Fetcher 0.1.0 (macOS) Component: TagLib dynamic library (libtag.2.dylib) Upstream project: https://taglib.org/ Upstream repository: https://github.com/taglib/taglib Upstream release tag: v2.3.1 Self-hosted source archive on this site: /open-source/lyrics-fetcher/taglib/2.3.1/taglib-2.3.1.tar.gz SHA-256: a19d90e6fd41d09a0281ec0fe762d51491d7a6ccffc923c4f7868c5e647ca230 Official upstream release archive: https://github.com/taglib/taglib/archive/refs/tags/v2.3.1.tar.gz Staged unsigned dylib (Vendor/TagLib/2.3.1/libtag.2.dylib before app embed/sign): SHA-256: d43f3d83a4b8028a549cde6ea392d784df3e02809baace142b6840c5369e03db Install name: @rpath/libtag.2.dylib CPU: arm64 Minimum macOS: 15.0 Signed Release dylib (Lyrics Fetcher 0.1.0 Release build, after embed-taglib.sh codesign): SHA-256: 7638886b3587bfaf4f5cc9c355250d9a0abc363e726daa32a5418ac06fce7635 Note: codesigning adds embedded signature data; the signed bytes differ from the staged unsigned dylib. License options in upstream TagLib 2.3.1: - GNU Lesser General Public License version 2.1 or later (COPYING.LGPL) - Mozilla Public License version 1.1 (COPYING.MPL) Lyrics Fetcher links TagLib dynamically under the LGPL terms. Full LGPL text is bundled in the app and published on this page. Modification statement: No source patches are applied to TagLib. The library is built from the verified upstream archive using the documented CMake configuration. Human review items (not legal approval): - Whether App Store distribution satisfies your LGPL obligations for dynamically linked libraries - Whether users can obtain and replace libtag.2.dylib in practice on a sandboxed Mac App Store build - Whether additional written offers or object files are required for your distribution channel In-app notices: Help → Third-party Notices