# Third-party software and models in the Waymark Gaze demo

> **Status: released with Waymark Gaze 1.0.0; served at https://falconlab.app/gaze/.** The vendored
> files were **verified against the official npm packages on 2026-10-01**: both npm tarballs match
> their registry integrity values (recorded below), and every vendored library file is
> byte-identical to the file in the official package. `face_landmarker.task` matches its recorded
> md5. The MediaPipe npm package and repository publish no separate NOTICE or third-party notices
> file for the wasm build; MediaPipe's Apache-2.0 `LICENSE` is included next to the files. ONNX
> Runtime's `ThirdPartyNotices.txt` is vendored.

Everything below is served from the page's own address, under `vendor/`. The page loads nothing
from a CDN and makes no request to any other host. Checksums of the vendored files are in `vendor/SHA256SUMS`
(`cd vendor && shasum -a 256 -c SHA256SUMS`).

Our own files (`index.html`, `app.js`, `styles.css`, `lib/`, `scripts/`, `tests/`,
`model/stub-zeros.onnx`, and `model/gaze.onnx` once the trainer's export is installed) are ours.
The gaze model is trained only on our own procedural synthetic eye patches; no third-party dataset
and no image of a real person is involved.

| Component | Version | Licence | Commercial use (licence of this component only) |
|---|---|---|---|
| MediaPipe Tasks Vision (JS + wasm) | 0.10.35 | Apache-2.0; the package and repository publish no separate notices file for the wasm build | allowed |
| MediaPipe Face Landmarker model (`face_landmarker.task`) | float16 / 1 | Apache-2.0 | allowed |
| ONNX Runtime Web (JS + wasm) | 1.30.0 | MIT | allowed |

## Upstream integrity values (verified 2026-10-01)

| Artefact | Value | Checked |
|---|---|---|
| npm tarball `@mediapipe/tasks-vision@0.10.35` | integrity `sha512-HOvadwVRE6JC+45nyYhmnywnr5h/J8KZvOeUNVOG9q/0875pZgItznFB9bRTvLc264YSJqiZ1NsIpCStJw/egg==` | **Yes, 2026-10-01.** The tarball matches the registry integrity, and every vendored file of this library is byte-identical to the file in the package. |
| npm tarball `onnxruntime-web@1.30.0` | integrity `sha512-q0y+JrrtukXSzsBWEMccVfqX25LRmosXHF+CaRJmg8pZClzcV7svNc4rKY3jL02Vb7QmRMDs1SigqR4CXAfKYQ==` | **Yes, 2026-10-01.** The tarball matches the registry integrity, and every vendored file of this library is byte-identical to the file in the package. |
| `face_landmarker.task` (float16 / 1) | md5 `b0e7274907a1644404fef66b28dd6d85` | **Yes, matches.** `md5 vendor/mediapipe-models/face_landmarker.task` on 2026-10-01 gives `b0e7274907a1644404fef66b28dd6d85` (3,758,596 bytes; sha256 `64184e22...0bc9ff` as in `SHA256SUMS`). |

To repeat the check: `npm pack @mediapipe/tasks-vision@0.10.35 onnxruntime-web@1.30.0`, confirm each
tarball's `sha512` (base64) equals the integrity string above (`npm view <pkg>@<version>
dist.integrity` prints the registry's value), unpack, and compare the unpacked files' SHA-256 with
`vendor/SHA256SUMS` (`cd vendor && shasum -a 256 -c SHA256SUMS` checks this folder against it).

## 1. MediaPipe Tasks Vision 0.10.35

- Files: `vendor/tasks-vision-0.10.35/vision_bundle.mjs`, `wasm/vision_wasm_internal.{js,wasm}`,
  `wasm/vision_wasm_nosimd_internal.{js,wasm}`, `package.json`, `LICENSE`. Unmodified.
- Source: npm package `@mediapipe/tasks-vision@0.10.35`
  (https://www.npmjs.com/package/@mediapipe/tasks-vision/v/0.10.35), repository
  https://github.com/google-ai-edge/mediapipe.
- Licence: Apache License 2.0. `package.json` says `"license": "Apache-2.0"`. The licence text is
  `vendor/tasks-vision-0.10.35/LICENSE`, taken from
  https://raw.githubusercontent.com/google-ai-edge/mediapipe/v0.10.35/LICENSE (the npm tarball does
  not ship one). The repository has no NOTICE file.
- Notices: the npm package and the repository publish no separate NOTICE or third-party notices
  file for the wasm build, so there is none to carry; the Apache-2.0 `LICENSE` is included.
- Terms relied on (section 2): "each Contributor hereby grants to You a perpetual, worldwide,
  non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare
  Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work".
  Section 4 conditions: "You must give any other recipients of the Work or Derivative Works a copy
  of this License" (the `LICENSE` file is kept next to the files) and "You must cause any modified
  files to carry prominent notices stating that You changed the files" (we do not modify them).
- **Why this version is pinned.** Releases 1.0.0 and 1.0.1 add a metrics logger that posts usage
  data to `https://odml.pa.googleapis.com/v1/log`; their README says "MediaPipe Tasks APIs send
  metrics about the performance and utilization of the APIs in your app to Google". 0.10.35 is the
  last release without it: its bundle contains no `http(s)` endpoint (checked again here with
  `grep`: the only `googleapis` string is a protobuf type name, `type.googleapis.com/mediapipe...`).
  Do not upgrade without repeating that check. The page's CSP (`connect-src 'self'`) is a second
  safeguard.

## 2. MediaPipe Face Landmarker model

- File: `vendor/mediapipe-models/face_landmarker.task` (3,758,596 bytes,
  md5 `b0e7274907a1644404fef66b28dd6d85`), with `vendor/mediapipe-models/LICENSE`. Unmodified.
- Source: https://storage.googleapis.com/mediapipe-models/face_landmarker/face_landmarker/float16/1/face_landmarker.task
  (documented at https://developers.google.com/edge/mediapipe/solutions/vision/face_landmarker).
- The bundle contains three models. Each model card states "LICENSED UNDER Apache License,
  Version 2.0":
  - BlazeFace (short range): https://storage.googleapis.com/mediapipe-assets/MediaPipe%20BlazeFace%20Model%20Card%20(Short%20Range).pdf
  - Face Mesh V2 (478 landmarks, "predicts 10 additional iris landmarks"):
    https://storage.googleapis.com/mediapipe-assets/Model%20Card%20MediaPipe%20Face%20Mesh%20V2.pdf
  - Blendshape V2 (52 coefficients incl. `eyeBlinkLeft` / `eyeBlinkRight`):
    https://storage.googleapis.com/mediapipe-assets/Model%20Card%20Blendshape%20V2.pdf
- Use restrictions stated on the cards (not licence terms, but we keep to them): the BlazeFace card
  says "Any form of surveillance or identity recognition is explicitly out of scope". This demo
  does neither: it estimates where the person at the keyboard is looking, on their own computer.
- The model-card quotes were recorded by this project's research step on 2026-09-30; the PDFs are
  not vendored.

## 3. ONNX Runtime Web 1.30.0

- Files: `vendor/onnxruntime-web-1.30.0/ort.wasm.min.mjs`, `ort-wasm-simd-threaded.mjs`,
  `ort-wasm-simd-threaded.wasm`, `package.json`, `LICENSE`, `ThirdPartyNotices.txt`. Unmodified.
  Only the wasm (CPU) backend is vendored, run single-threaded; the WebGPU build is not.
- Source: npm package `onnxruntime-web@1.30.0`
  (https://www.npmjs.com/package/onnxruntime-web/v/1.30.0), repository
  https://github.com/microsoft/onnxruntime.
- Licence: MIT, "Copyright (c) Microsoft Corporation". `package.json` says `"license": "MIT"`. The
  licence text is `vendor/onnxruntime-web-1.30.0/LICENSE`, from
  https://raw.githubusercontent.com/microsoft/onnxruntime/v1.30.0/LICENSE.
- Terms relied on: "Permission is hereby granted, free of charge, to any person obtaining a copy of
  this software ... to deal in the Software without restriction, including without limitation the
  rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the
  Software". Condition: "The above copyright notice and this permission notice shall be included in
  all copies or substantial portions of the Software" (the `LICENSE` file is kept next to the files).
- `ThirdPartyNotices.txt` is the notices file of the whole onnxruntime repository (from
  https://github.com/microsoft/onnxruntime/blob/v1.30.0/ThirdPartyNotices.txt); the wasm build
  statically links a subset of the components it lists.

## Not used, and why

- **WebGazer.js** (GPL-3.0-or-later; https://github.com/brownhci/WebGazer): not vendored and its
  source was not read. The calibration here (ridge regression from eye features to screen
  position) is written from scratch.
- **MPIIGaze, GazeCapture, ETH-XGaze, UnityEyes, Columbia Gaze**: research / non-commercial
  datasets; not used for training, evaluation or tests.
- **Test-only tooling**: the browser tests use `playwright-core` (Apache-2.0) from the repository's
  existing `node_modules`; it is not part of the page.

## Algorithms implemented from publications

- One Euro filter: Casiez, Roussel and Vogel, "1€ Filter: A Simple Speed-based Low-pass Filter for
  Noisy Input in Interactive Systems", CHI 2012. Implemented from the paper's equations.
