Browser codec sources and rebuild notes The site serves its codec modules locally. No codec is downloaded from a CDN while processing a file. Versions are pinned in package-lock.json. HEIC/HEIF decoding Package: libheif-js 1.23.2 (LGPL-3.0) npm wrapper source, including scripts/install.js and scripts/bundle.js: https://github.com/catdad-experiments/libheif-js/tree/6ca00b818c0ff51cb2a5c75b9ce97d708083335a Source archive: https://github.com/catdad-experiments/libheif-js/archive/6ca00b818c0ff51cb2a5c75b9ce97d708083335a.tar.gz Codec build repository, workflow and pinned libheif submodule: https://github.com/catdad-experiments/libheif-emscripten/tree/v1.23.2 https://github.com/strukturag/libheif/tree/ac1cb05c39008f01525c991ff8b88f84ddf70fd2 https://github.com/strukturag/libheif/archive/ac1cb05c39008f01525c991ff8b88f84ddf70fd2.tar.gz libheif's build-emscripten.sh pins its HEVC decoder to libde265 1.0.15: https://github.com/strukturag/libde265/tree/v1.0.15 https://github.com/strukturag/libde265/releases/download/v1.0.15/libde265-1.0.15.tar.gz The libheif and libde265 libraries are distributed under the GNU LGPL; the accompanying GPL/LGPL license texts ship in libheif-codec-1.23.2.txt. Rebuilding: check out libheif-emscripten tag v1.23.2 with submodules. Follow its .github/workflows/emscripten.yml (Emscripten 3.1.61), enabling USE_WASM=1 and USE_UNSAFE_EVAL=0. Run dist-prep.sh and archive libheif and libheif-wasm as the workflow specifies. In the pinned npm wrapper checkout, run scripts/install.js with that local archive to regenerate the JS bundle. This application imports libheif-js/libheif-wasm/libheif-bundle.mjs lazily from src/engines/image/heif.ts; it does not modify the library source. Replace that module with a compatible rebuilt module and run npm run build to use a modified library. No signature check restricts replacement. WebP encoding fallback Package: @jsquash/webp 1.5.0 (Apache-2.0 wrapper) Source and codec build instructions: https://github.com/jamsinclair/jSquash/tree/main/packages/webp The distributed codec README identifies libwebp v1.0.2 (BSD). https://github.com/webmproject/libwebp/tree/v1.0.2 The codec's bundled BSD notice is shipped separately as libwebp-codec.txt. Imported lazily from src/engines/image/index.ts when canvas cannot encode actual WebP. Both regular and SIMD assets are served from the site's origin. MD5 checksums Package: hash-wasm 4.12.0 (MIT) https://github.com/Daninet/hash-wasm/tree/v4.12.0 Used for legacy checksums only. SHA-256/384/512 use browser Web Crypto. AVIF decoding uses the browser's own codec. PDF preview retains PDF.js's useWasm:false setting. Public license files are regenerated from installed dependencies by scripts/prepare-assets.mjs; source archives above are linked for inspection and rebuilding, not requested at runtime.