# Third-party dependencies Runtime dependencies are locked in package-lock.json. Next.js, React, React DOM, Radix Themes and gifenc use MIT licenses; Lucide uses ISC. Full dependency licenses remain in the installed packages. The bundled encoding implementation requires the following notice. ## gifenc 1.0.3 The MIT License (MIT) Copyright (c) 2017 Matt DesLauriers Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ## Local format modules added 2026-09-30 - **@jsquash/webp 1.5.0**, Apache-2.0, © Jamie Sinclair and contributors; derived from Google Squoosh. Only the encoder is imported on demand. Complete license: `/licenses/jsquash.txt`. - **libwebp encoder 1.1.0**, BSD-3-Clause, © 2010 Google Inc. The installed WASM's `version()` reports `0x010100`; package README version labels are stale. Both SIMD and non-SIMD encoder binaries are self-hosted. Complete copyright and conditions: `/licenses/libwebp.txt`; additional patent grant: `/licenses/libwebp-patents.txt`. No old libwebp decoder is shipped or executed: bounded static frames are decoded by the browser. User-supplied compressed WebP bytes never enter this WASM encoder. - **mediabunny 1.61.0**, MPL-2.0, © 2026-present Vanilagy and contributors. Imported only on video tools. The library uses browser codecs; no FFmpeg/codecs are downloaded. License: `/licenses/mediabunny.txt`. The exact unmodified installed Source Code Form (src, package.json, README and license) is available to recipients at `/licenses/mediabunny-1.61.0-source.tar.gz`. Application source is separate; the library was not modified. See the About page for these links. - **fflate 0.8.3**, MIT, © 2020 Arjun Barrett. ZIP generation is imported only when requested. Complete license: `/licenses/fflate.txt`. The root application ships no telemetry or remote font/media service. Codec WASM is fetched from the same origin; no user file data is part of these requests. Asset binaries can be reproduced from the exact package-lock version by `npm run codecs`. ## Local expansion codecs and models (2026-10-01) All code and weights below are fetched from this website's own origin on demand. Inference and decoding take place on the user's device. No remote inference API is used. Source and asset hashes are recorded in `docs/completion-evidence-2026-10-01/license-sources.json` and the model manifest. - **@jsquash/avif 2.1.1**, Apache-2.0 (`/licenses/jsquash-avif.txt`), bundles libavif and its codec dependencies. Their notices are in `/licenses/libavif.txt`, `/licenses/libaom-license.txt`, `/licenses/libaom-patents.txt` and `/licenses/dav1d.txt`. Static AVIF only; no claim of lossless conversion. - **libheif-js 1.23.2** wrapper, MIT (`/licenses/libheif-js.txt`), and **libheif** WASM, LGPL-3.0 (`/licenses/libheif-wasm.txt`). Unmodified binary from the fixed npm package. Its build uses libheif commit `ac1cb05c39008f01525c991ff8b88f84ddf70fd2`, libde265 1.0.15 and Emscripten 3.1.61. Corresponding library source: `/licenses/libheif-ac1cb05-source.tar.gz`, `/licenses/libde265-1.0.15-source.tar.gz`; build recipe: `/licenses/libheif-emscripten-1.23.2-source.tar.gz`; wrapper source: `/licenses/libheif-js-6ca00b8-source.tar.gz`. These separate library modules may be replaced by compatible modified builds; reverse engineering for debugging modifications to these LGPL components is not restricted. The application is not a HEIC encoder. - **TensorFlow.js 4.22.0**, Apache-2.0 (`/licenses/tensorflow.txt`). **ESRGAN Slim x2/x4**, MIT (`/licenses/esrgan-slim.txt`), from the fixed UpscalerJS model packages. This is learned super-resolution, not simple resizing; small-image CPU inference only, with separately resampled alpha. - **ONNX Runtime Web 1.23.2**, MIT (`/licenses/onnxruntime.txt`). **MODNet**, Apache-2.0 (`/licenses/modnet.txt`), FP32 ONNX conversion from Xenova/modnet revision `fa2fa546052fba4c08921230a26cc69a333fca12`. Portrait matting only; foreground objects are not generally supported. The tested quantized alternative was rejected for visibly missing foreground detail; it is not shipped. - **MediaPipe Tasks Vision 0.10.32** and **BlazeFace short-range float16 model**, Apache-2.0 (`/licenses/mediapipe.txt`). Face boxes are suggestions requiring manual inspection, not an assurance that every face or private detail was detected. The NASA portrait used solely in local test fixtures is public-domain NASA artwork, sourced via the scikit-image test collection; see `tests/fixtures/README.md`. It is not a production user upload or a product testimonial. No trained model is modified by user data.