# HEIC decoder source and build information

The distributed `libheif-bundle.js` is the unmodified libheif-js 1.19.8 browser bundle.
It is loaded as a separate script and can be replaced by a compatible build exposing
the same `libheif` decoding API. The application does not embed the decoder into its
own source. No restriction on modification or reverse engineering of these library
components is imposed by this site.

Matching sources are available beside the distributed library:

- [libheif-js source](./libheif-js-source.tar.gz), npm gitHead
  `fe8e9c29440b839910be9dc32e8d2b826c8217ca`.
- [libheif Emscripten build wrapper](./emscripten-source.tar.gz), release v1.19.8.
- [libheif C/C++ source](./libheif-source.tar.gz), matching submodule commit
  `5e9deb19fe6b3768af0bb8e9e5e8438b15171bf3`.
- [libde265 1.0.15](./libde265-source.tar.gz), the default HEVC decoder version
  in the matching build script. [License](./libde265-LICENSE.txt).
- [AOM 3.6.1](./aom-source.tar.gz), the default AV1 decoder version
  in the matching build script. [License](./aom-LICENSE.txt), [patent license](./aom-PATENTS.txt).

The archives include their original license and copyright notices.
The published npm metadata is preserved in `npm-source.json`; the wrapper tree
records the libheif submodule commit in `emscripten-source-tree.json`.

To rebuild, unpack the source archives into your own build workspace, restore the
libheif submodule from the matching archive and follow the archived build workflow.
The upstream workflow uses Ubuntu 22.04 and Emscripten 3.1.61. Its instructions are
preserved in [source-build.yml](./source-build.yml); the original libheif build script
is [source-build-emscripten.sh](./source-build-emscripten.sh). Preserve the specified
dependency versions. The npm wrapper's [installation script](./source-install.js)
and [README](./source-README.md) show how the Emscripten files become the browser bundle.
The wrapper also uses the build dependencies and bundling scripts in its source archive.

Replace the site's separate browser bundle with the compatible result and reload the
page. Existing browser caches may need refreshing. This source set was inspected
against published metadata; a bit-for-bit rebuild was not performed here.

Upstream:
- https://github.com/catdad-experiments/libheif-js
- https://github.com/catdad-experiments/libheif-emscripten/tree/v1.19.8
- https://github.com/strukturag/libheif/tree/5e9deb19fe6b3768af0bb8e9e5e8438b15171bf3
- https://github.com/strukturag/libde265/releases/tag/v1.0.15
- https://aomedia.googlesource.com/aom/+/v3.6.1

This notice records provenance and source access, rather than making a general
legal or patent clearance statement.
