The generated data (owasp_rules.json, waf_patterns/**) is derived from
third-party projects but was implicitly covered by the blanket MIT LICENSE
with no NOTICE. Add the missing attribution — additively and reversibly:
- THIRD_PARTY_NOTICES.md (new): per-source attribution
- OWASP CoreRuleSet -> Apache-2.0 (owasp_rules.json + waf_patterns/**)
- JayBizzle/Crawler-Detect -> MIT (bad-bot list)
- mitchellkrogza/...bad-bot -> MIT (bad-bot list)
- matomo/referrer-spam-... -> Public Domain (referrer spam)
- LICENSES/Apache-2.0.txt (new): canonical license copy (Apache-2.0 §4a).
- README: License section now scopes MIT to the original project code; the
generated data is redistributed under its upstream licenses. Resources now
credit the real bad-bot sources (removed the unused ai.robots.txt mention).
- Converters (owasp2json, json2nginx, json2apache, json2traefik, json2haproxy)
emit a provenance header on every generated file (Apache-2.0 §4b "state
changes"); owasp_rules.json gains a top-level _provenance key. Loaders accept
both the {_provenance, rules} object and the legacy bare-array form.
- owasp_rules.json wrapped as {_provenance, rules} (rule content unchanged).
- update_patterns.yml jq updated for the object shape.
LICENSE stays MIT (GitHub detection unaffected). Propagation of the headers to
waf_patterns/** is left to the daily update_patterns workflow.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>