# Codec sources, licensing and replacement

The application UI, worker adapter and static pages are original OpusDesk Hub
code, available in the accompanying source package under Apache-2.0. Existing
third-party code retains its own notices and licences; branding is not inherited.

- Preact 11.0.0: MIT.
- jSquash WebP 1.5.0: npm gitHead
  `8bcd212da8c2be7c9c223e8f222eb3d9574a713b`; libwebp
  `d2e245ea9e959a5a79e1db0ed2085206947e98f2` (BSD licence/patent terms).
- jSquash AVIF 2.1.1: npm gitHead
  `b7fa9ac9ec02f224847ad23d19d115f9e296a368`; libavif 1.0.1,
  libaom 3.7.0 and libsharpyuv from libwebp
  `e2c85878f6a33f29948b43d3492d9cdaf801aa54`. Included notices contain the
  upstream BSD/patent terms and libavif's additional attributions.
- libheif-js 1.23.2: npm gitHead
  `6ca00b818c0ff51cb2a5c75b9ce97d708083335a`, LGPL-3.0-or-later.
  libheif source `ac1cb05c39008f01525c991ff8b88f84ddf70fd2`, libde265 1.0.15.
  The wrapper release `libheif-emscripten` v1.23.2 pins that submodule.

## Corresponding HEIC sources

All four pinned archives are distributed beside the decoder under `/source/sources/`:
libheif, libde265, libheif-emscripten, and libheif-js. Full GPL/LGPL texts are
included under `/source/licenses/` and in THIRD_PARTY_NOTICES.txt. The checksums
and original download URLs are in `/source/downloads.json`. Acquisition uses
verified HTTPS; hashes record the acquired bytes, not an independently
reproducible binary-build attestation.

To rebuild the unmodified HEIC library, extract the archives, put the pinned
libheif tree at the wrapper's `libheif/` submodule location and follow the
included `.github/workflows/emscripten.yml` and `dist-prep.sh`. The upstream
recipe uses Ubuntu 22.04, Emscripten 3.1.61, Node 24, TypeScript 5;
`USE_WASM=1 USE_UNSAFE_EVAL=0 USE_TYPESCRIPT=1`. The included libheif
`build-emscripten.sh` uses libde265 1.0.15, defaults to single-threaded HEVC
decoding, disables AOM, OpenJPEG and WebCodecs. Put the supplied libde265
tarball where that script expects it. `scripts/install.js` in libheif-js
defines the wrapper/polyfills and esbuild bundling; its pinned package metadata
contains the development dependency versions. Compiler/toolchain installation
is not performed by the website. Bit-for-bit reproduction of the prebuilt npm
binary has not been independently verified.

## Replace or modify

The LGPL HEIC decoder is dynamically imported as its own ES module; it is not
inlined into proprietary application code and has no signature/replacement lock.
Replace `node_modules/libheif-js/libheif-wasm/libheif-bundle.mjs` with a compatible
rebuilt module, preserve licence notices, then run `npm run build` to relink it
into the hashed codec directory. The app expects `HeifDecoder.decode`,
`HeifImage.get_width/get_height/display/free`, and `heif_context_free`.
The source package supplies the adapter and static build scripts. Reverse
engineering for debugging modifications to LGPL components is permitted.
An alternative is to replace the separately served module at its deployed path;
production cache versioning must then be refreshed. No integrity enforcement
prevents this. Do not impose additional contractual restrictions on these rights.

## Operational boundary

There is no HEIC encoder, x265, or GPL example executable shipped to the visitor.
Codec source build scripts have their own licences. Open-source permissions do
not establish patent clearance for every jurisdiction or indemnity. This is a
technical source/licence inventory, not a legal opinion. Sources and notices must
remain available with a public distribution. Do not remove the `/source/` files
from the deploy ZIP while retaining the LGPL binary.

Squoosh/jSquash attribution remains in the notices. No Google Analytics, original
UI/branding, third-party font or external runtime CDN is used. Images are never
part of source archives, static deployment or error reporting.
