# Vendored decoder provenance - **File:** `libheif-bundle.js` (WASM inlined, single file) - **SHA-256:** `793b36c913689784b2bfba60456fd87c14ed49e2d13f3b4d2611baaf05148f81` — asserted by `tests/structure-d3.js` so an unexpected substitution of the portfolio's only third-party code fails the build. - **Package:** `libheif-js` 1.19.8 (npm) — prebuilt WASM distribution of **libheif** (struktura AG), including the libde265 HEVC decoder - **Upstream:** https://github.com/strukturag/libheif · https://www.npmjs.com/package/libheif-js - **Corresponding source for THIS build** (LGPL-3.0 §6a; a floating branch link does not discharge it — the same standard the charter's MP3 checklist sets for lamejs): https://registry.npmjs.org/libheif-js/-/libheif-js-1.19.8.tgz · https://github.com/strukturag/libheif/tree/v1.19.8 Linked from `methodology/` and `terms/` as well as here, so the duty is discharged on a served page and not only in this file. - **License:** LGPL-3.0 (see `LICENSE` in this directory). Shipped unmodified as a separately served static file; not bundled into any site code. Attribution and license link appear on the methodology page. - **Why it exists:** Chrome/Edge/Firefox cannot decode HEIC natively. This is one of three vendored third-party components on the site (the others: `../lamejs/`, the MP3 encoder, and `../gifjs/`, the GIF encoder, both added 2026-08-08) — rationale and payload accounting in `docs/2026-08-04-build-d3-decisions.md`. - **Loading:** lazy only (idle prefetch + on-demand injection). Never referenced by a `