Source code for redistributed components

Snitt for macOS redistributes third-party software. Some of it is licensed under the GNU LGPL or GPL, which require the corresponding source to be available from the same place as the binary. This page is that place. Nothing here needs to be requested — every tarball below is the exact upstream source of a component inside the app, or the script we used to build it.

Verify any file with shasum -a 256 <file> and compare it to the SHA-256 in the table.

Components

ComponentVersionLicenceDownloadSizeSHA-256
ffmpeg8.1.2LGPL-2.1-or-laterffmpeg-8.1.2.tar.xz11.2 MB464beb5e7bf0c311e68b45ae2f04e9cc2af88851abb4082231742a74d97b524c
dav1d1.5.4BSD-2-Clausedav1d-1.5.4.tar.xz1015 KB686616b7c69eb88d44459391ab25cac13b6647a3b288835c5784e71c1514a5c5
build-ffmpeg.sh (our build recipe)n/aour own scriptbuild-ffmpeg.sh23 KBe846e0e3074627d734bcd6a2bf7226469a1c175b9a0232de8b557c394c2d4311
yt-dlp2026.07.04Unlicenseyt_dlp-2026.7.4.tar.gz2.9 MBb094813404f87a9dd2186f00815231df32e5fd8a5403be0f807b3bb2d21a4432
fetch-yt-dlp.sh (our fetch recipe)n/aour own scriptfetch-yt-dlp.sh11 KB6848095599a261868c4ded1971ee0525892645b284f728de7609e966e7ff6f56
CPython3.14.6PSF-2.0Python-3.14.6.tar.xz22.8 MB143b1dddefaec3bd2e21e3b839b34a2b7fb9842272883c576420d605e9f30c63
OpenSSL3.5.7Apache-2.0openssl-3.5.7.tar.gz50.7 MBa8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8
mutagen1.48.1GPL-2.0-or-latermutagen-1.48.1.tar.gz1.2 MB8f95637ab9f6f305cec6bd1294e197debe207998e3e068596563c74f86b0a173
certifi2026.6.17MPL-2.0certifi-2026.6.17.tar.gz131 KB024c88eeec92ca068db80f02b8b07c9cef7b9fe261d1d535abfd5abd6f6af432

Where each file comes from

FileUpstreamChecksum verified against
ffmpeg-8.1.2.tar.xzhttps://ffmpeg.org/releases/ffmpeg-8.1.2.tar.xzffmpeg.org release checksums, pinned in scripts/build-ffmpeg.sh
dav1d-1.5.4.tar.xzhttps://downloads.videolan.org/pub/videolan/dav1d/1.5.4/dav1d-1.5.4.tar.xzvideolan.org release checksums, pinned in scripts/build-ffmpeg.sh
build-ffmpeg.shthis repositorymeasured here (this file is ours)
yt_dlp-2026.7.4.tar.gzhttps://files.pythonhosted.org/packages/47/c5/9972af4b472b0d55badf841ebafd2f98944cb0ae0f46e11d01f363ea5b91/yt_dlp-2026.7.4.tar.gzPyPI published sha256
fetch-yt-dlp.shthis repositorymeasured here (this file is ours)
Python-3.14.6.tar.xzhttps://www.python.org/ftp/python/3.14.6/Python-3.14.6.tar.xzNONE published — python.org ships PGP .sig + Sigstore only; hash measured here
openssl-3.5.7.tar.gzhttps://github.com/openssl/openssl/releases/download/openssl-3.5.7/openssl-3.5.7.tar.gzopenssl.org published .sha256
mutagen-1.48.1.tar.gzhttps://files.pythonhosted.org/packages/df/70/1675da133ea92227da41bf5b24e1c66be597ff736a1533ade41da986852f/mutagen-1.48.1.tar.gzPyPI published sha256
certifi-2026.6.17.tar.gzhttps://files.pythonhosted.org/packages/c9/c7/424b75da314c1045981bd9777432fad05a9e0c69daa4ed7e308bbaffe405/certifi-2026.6.17.tar.gzPyPI published sha256

Notes

ffmpeg is built by us from the pinned tarball above with build-ffmpeg.sh, configured LGPL-only: no --enable-gpl, no --enable-nonfree, no --enable-version3. dav1d (BSD-2-Clause) is statically linked into it. The build script is published here because the LGPL asks for the scripts used to control compilation.

yt-dlp is redistributed as the official upstream standalone macOS binary, unmodified. The tarballs above are its own source plus the source of the interpreter and libraries frozen into that binary — CPython, OpenSSL, mutagen and certifi. Of those, mutagen is GPL-2.0-or-later; the rest are permissive or weak-copyleft and are mirrored so the corresponding source is complete rather than because each one is separately demanded.

Other libraries inside the yt-dlp binary are permissive-licensed and carry no source-hosting obligation: brotli (MIT), zstd (BSD-2-Clause / GPL-2.0 dual, used under BSD), curl_cffi and its statically linked libcurl-impersonate 8.15.0 (curl licence), nghttp2 (MIT), requests (Apache-2.0), urllib3 (MIT), websockets (BSD-3-Clause) and pycryptodome (BSD-2-Clause / public domain). Ask us and we will mirror any of them too.

Questions, or a component you think is missing: support@snitt.ai.