# Third-party notices

void-rules fetches and transforms third-party rule data without executing upstream code. The authoritative source inventory and per-build hashes are published in `catalog/sources.yaml` and `generated/sources.lock.json`.

Initial upstream families include:

- AdGuardTeam/AdGuardHome documentation and filter syntax.
- blackmatrix7/ios_rule_script (GitHub reports GPL-2.0).
- DustinWin/domain-list-custom (GitHub reports MIT).
- juewuy/ShellCrash (GitHub reports GPL-3.0).
- Loyalsoldier/clash-rules (GitHub reports GPL-3.0).
- MetaCubeX/meta-rules-dat (GitHub reports GPL-3.0).
- QuixoticHeart/rule-set (GitHub reports GPL-3.0).
- snapei/clash-pro-rules (GitHub reports GPL-3.0).
- TG-Twilight/AWAvenue-Ads-Rule (GitHub reports GPL-3.0).
- v2fly/domain-list-community and v2fly/v2ray-core for the documented geosite DAT protobuf format.
- VoidInTheShell/cross-border-finance-rules (GitHub reports MIT).
- VoidInTheShell/pcdn-block-list (no SPDX license reported by the GitHub API when first registered).
- xixu-me/RFM (GitHub reports GPL-3.0).
- VPSDance/ai-proxy-rules (MIT, Copyright (c) 2026 VPSDance).
- xiaolai/anthropic-claude-surge-rules-set (README declares MIT).

The exact upstream list can grow through reviewed catalog changes. A generated artifact is never evidence that an upstream author endorses this project.
