Trademark & Forks
How the code, the name, and the official builds relate — so a derivative can be built and described clearly.
License — the code is yours to reuse
Cefrium is licensed under LGPL-3.0-or-later. You may build it, modify it, and redistribute it, including the SDK AAR, under the terms of that license. Forks and derivatives are welcome; enabling them is the purpose of copyleft.
The LGPL asks a few things in return. In plain terms:
- Keep the copyright and license notices intact.
- State the changes you made.
- Make the corresponding source of your modified library available under the same license.
The underlying CEF and Chromium code is BSD-licensed and carries its own notices; keep those too.
Trademark — the name is not part of the license
“Cefrium” is a trademark of the project's maintainer, with a Spanish trademark application pending (OEPM, classes 9 and 42). A software license grants rights to the code, not to the name. This separation is normal in free software — Firefox and its rebuilt derivatives are the best-known example — and most FLOSS projects state it the same way.
Using the name is fine
No permission is needed to refer to the project accurately:
- Saying a derivative “is based on Cefrium” or “uses Cefrium”.
- Naming the upstream version you track, such as a tag like
cefrium-0.9.2-…, as an honest statement of origin. - Linking to cefrium.com and to the source repository.
What needs marking
An unofficial build should not be presented as an official Cefrium release, and a modified artifact should not be named so that it reads as the official SDK. Third-party builds should say plainly that they are unofficial derivatives.
The reason is user safety rather than control: this is a browser engine, and someone installing it needs to know whose security updates and CVE cadence they are relying on. Clear labelling answers that question; it does not restrict reuse.
If you are unsure whether a name or a description is fine, just ask: cefrium@proton.me. The answer is usually yes.
Official builds vs derivatives — how to tell
The official distribution is exactly these channels:
- The source at codeberg.org/cefrium/cef-android.
- The releases listed on cefrium.com/releases.
- The artifacts published as
com.cefrium:*on Maven Central, and the Codeberg Maven mirror.
Release archives carry a GPG-signed SHA256SUMS, signed with the
maintainer's key:
2A84 0ED0 0DE6 69F4 219B 8B33 02A7 9E3B 8215 1695
Anything obtained elsewhere is a third-party build. That is legitimate, and the point of the verification steps on the releases page is simply to let anyone confirm which of the two they have.
Pinning a version? Resolve from
Maven Central (mavenCentral(),
com.cefrium:*), where every published version stays available
permanently. The Codeberg Maven mirror serves only the latest version, so a
coordinate pinned there stops resolving at the next release. See the
Quickstart.
Codecs — what the official builds ship
Two variants are published:
cefrium-sdk— the standard build, with H.264 and AAC.cefrium-sdk-libre— royalty-free codecs only.
The official distribution deliberately does not ship proprietary codecs such as AC3 or EAC3 (Dolby), for the same reason Chromium omits them: they carry patent-licensing obligations that a distributor has to hold.
A derivative is free to add them under the LGPL. Doing so is the redistributor's own decision and carries the redistributor's own patent responsibility. Cefrium takes no position on, and assumes no liability for, codecs it does not distribute.
Questions
Anything unclear here is worth an email rather than a guess: cefrium@proton.me, or an issue on Codeberg.