# ImageUnbox third-party notices ImageUnbox vendors these decoder files for same-origin, on-device image conversion. Conversion does not call a third-party conversion service. The application loads the decoders lazily. The HEIF ES module contains its WebAssembly binary; AVIF loads its adjacent WebAssembly file from this site. ## libheif-js 1.23.5 — LGPL-3.0 The unmodified browser module is `dist/assets/vendor/libheif/libheif-bundle.mjs`, from the npm package `libheif-js@1.23.5`. - Package source: https://github.com/catdad-experiments/libheif-js/tree/d8ec4bc3bc5bf8055975577bccbbc7e1d7313c2d - Package archive: https://registry.npmjs.org/libheif-js/-/libheif-js-1.23.5.tgz - Build sources: https://github.com/catdad-experiments/libheif-emscripten/tree/v1.23.5 - Upstream libheif source, version 1.23.5, also confirmed by the binary's `heif_get_version()`: https://github.com/strukturag/libheif/tree/v1.23.5 - Included HEVC decoder libde265, version 1.0.15, confirmed by `_de265_get_version()`: https://github.com/strukturag/libde265/tree/v1.0.15 - Full license texts are supplied alongside the module in `LICENSE-libheif-js`, `LICENSE-libheif` (including LGPL/GPL texts), and `LICENSE-libde265`. The library remains a separate ES module. No library code has been modified or merged into the application. The corresponding source and build instructions above permit the library to be studied, rebuilt, modified, and replaced. Preserve these notices and upstream license texts when redistributing the site or vendor files. The upstream license applies to the library; it is not a license grant for unrelated application code. ## @jsquash/avif 2.1.1 — Apache-2.0 The unmodified `decode.js`, `utils.js`, and `codec/dec/avif_dec.js` / `avif_dec.wasm` files come from `@jsquash/avif@2.1.1`. Encoder files are intentionally omitted because the site exports JPG and PNG using browser Canvas. - Package source: https://github.com/jamsinclair/jSquash/tree/b7fa9ac9ec02f224847ad23d19d115f9e296a368/packages/avif - Package archive: https://registry.npmjs.org/@jsquash/avif/-/avif-2.1.1.tgz - Codec build definition: https://github.com/jamsinclair/jSquash/blob/b7fa9ac9ec02f224847ad23d19d115f9e296a368/packages/avif/codec/Makefile - Supplied Apache-2.0 license: `dist/assets/vendor/avif/LICENSE`. The upstream Google and Jamie Sinclair notices remain in the JavaScript files. - libavif 1.0.1 source: https://github.com/AOMediaCodec/libavif/tree/v1.0.1 — BSD-2-Clause, supplied as `LICENSE-libavif`. - libaom 3.7.0 source: https://aomedia.googlesource.com/aom/+/v3.7.0 — supplied as `LICENSE-libaom` and `PATENTS-libaom`. These versions are taken from the package's decoder README and the pinned build Makefile. No runtime dependency on npm, jsDelivr, unpkg, or another CDN is introduced. The application does not use the package's encoder or its `wasm-feature-detect` dependency. ## Integrity and verification `dist/assets/vendor/manifest.json` records package versions, source references, file sizes, and SHA-256 hashes. Run `node scripts/vendor-deps.mjs` to verify the checked-in dependency files and real HEIC/AVIF fixtures without a browser. See `docs/VALIDATION.md` for the exact checks and known limitations. Test fixtures are development-only and are not in the deployed `dist` directory.