libheif-js 1.23.5 (npm), an Emscripten build of libheif 1.23.5 with libde265 1.0.15: the HEIC and HEIF decoder of the image converter (src/components/tools/image). Vendored 2026-10-05 and served unmodified, never bundled. libheif.js 91,255 bytes sha256 376c0bb483c23ac458cd22d718074693748ea75eddc3e4929353d4153e365a2e libheif.wasm 1,463,506 bytes sha256 184d3d20f8323877f13e9f5254f9c6a0ce272c9a3a2f823b0b2bcd2ee9f73f80 from https://registry.npmjs.org/libheif-js/-/libheif-js-1.23.5.tgz, folder libheif-wasm/ (sha512-umXZPthnWZtF3iG/5mQG+AZ2V6i0UeYpo3z2CkggTEgL8dKmIIwJT6TDuAMuabXa1yTW8uJ1ZAgR+CxNTklYYw==, checked on download). Copyright. These two files are not the studio's work. Their authors' notices, as their sources carry them: libheif "HEIF codec. Copyright (c) 2017-2025 Dirk Farin " (libheif/api/libheif/heif.h at v1.23.5), and in its README: "Copyright (c) 2017-2020 Struktur AG", "Copyright (c) 2017-2026 Dirk Farin". libde265 "H.265 video codec. Copyright (c) 2013-2014 struktur AG, Dirk Farin " (libde265/de265.h at v1.0.15). The npm package, libheif-js, is Kiril Vatev's (the author its package.json names). The compiled files themselves carry no notice; these lines stand for it here. Licence. libheif and libde265 are free software: you can redistribute them and modify them under the terms of the GNU Lesser General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. They are distributed WITHOUT ANY WARRANTY; see the licence for details. LICENSE.txt libheif's own COPYING, as the package ships it (libheif-wasm/LICENSE): the LGPL version 3, the GPL version 3 it builds on, and the MIT text under which libheif's sample applications and its Go and C++ wrappers are distributed. libde265 is under the same LGPL, whose text this is. LICENSE.libheif-js.txt the npm package's own licence file (LICENSE: LGPL-3.0). Both are the package's files, unchanged but for the .txt that lets a browser show them. The JavaScript beside the WebAssembly also holds Emscripten's runtime (MIT / University of Illinois NCSA licences). Permission. This site's terms of use forbid reproducing or modifying its content without written authorization. For libheif.js, libheif.wasm and the two licence files, this notice is that authorization, and it adds no condition to their licence: you may copy, study, modify, share and debug them under the LGPL. heic-worker.js, the studio's own file beside them, may be copied and adapted for the purpose of running a modified libheif. Source. The exact source of these two files: libheif https://github.com/strukturag/libheif/tree/v1.23.5 (commit 413e2a87e6a70b3eccc3a3adc5801179dd2d9e00) libde265 https://github.com/strukturag/libde265/releases/tag/v1.0.15 the build libheif's own build-emscripten.sh, run by https://github.com/catdad-experiments/libheif-emscripten (release v1.23.5; Emscripten 3.1.61; USE_WASM=1 USE_UNSAFE_EVAL=0) the package https://github.com/catdad-experiments/libheif-js, version 1.23.5 (scripts/install.js passes libheif.js through esbuild: minified, ES2019; libheif.wasm is the build's own file, untouched) Questions about the source, or a request for it: contact@mystya.com. Using a build of your own. Build libheif with its build-emscripten.sh, with USE_WASM=1 and USE_UNSAFE_EVAL=0, which writes libheif.js and libheif.wasm. The second setting matters: the script's default, 1, makes a build that turns text into code as it runs, and the policy heic-worker.js is served with (below) refuses that. Serve yours at these two addresses (your browser's developer tools can substitute local files for them): the page fetches libheif.wasm and hands it to heic-worker.js, which loads libheif.js; both are used as they are. What heic-worker.js asks of the library: to decode the global `libheif` factory that libheif.js defines (called with { wasmBinary }); `new HeifDecoder()`, its `decode(bytes)` and its `decoder` context, freed with `heif_context_free`; on each picture `is_primary()`, `get_width()`, `get_height()`, `has_alpha_channel()`, `free()`, and either `display({ data, width, height }, callback)` or, where the build has all of it, the call `display` itself makes: `heif_js_decode_image2(handle, colorspace, chroma)` with the picture's `handle`, `heif_colorspace.heif_colorspace_RGB`, `heif_chroma.heif_chroma_interleaved_RGBA` and `heif_channel.heif_channel_interleaved`; of its answer, `code`, `image` and, of each of its `channels`, `id`, `data`, `width`, `height` and `stride`; then `heif_image_release`. optional to say that part of a picture could not be read: `_heif_image_get_decoding_warnings`, on the decoded picture's pointer (an internal of the build's binding), with `_malloc` and `_free`. to tell a Display P3 photo: `_heif_image_handle_get_color_profile_type`, `_heif_image_handle_get_nclx_color_profile`, `_heif_nclx_color_profile_free`, `_heif_image_handle_get_raw_color_profile_size`, `_heif_image_handle_get_raw_color_profile`, `HEAPU8`, `_malloc` and `_free`, on the picture handle's pointer (the same internal). A build without `heif_js_decode_image2` or its three enumerations is read through `display`, and one without the optional calls still decodes: either reports no damage, and the second leaves a Display P3 photo's numbers as they are, a little dull. heic-worker.js is the studio's own file and not part of the library. The page fetches libheif.wasm and hands it to the worker with the first picture. The worker is served with a policy that allows it scripts from this site's own address and WebAssembly, and nothing else: no request, no socket, no font, no worker of its own. Before the library's script runs, the worker also replaces its own ways out with functions that refuse: the network functions, workers, the registration of a service worker, and the browser's storage (caches, IndexedDB, the storage directory, locks). Neither lock is enough alone in every browser; together, tried from inside the worker in three of them, they leave nothing in the worker able to send a picture to another address or to leave it in the browser's storage. libheif.js is itself served with a policy that allows it nothing, should a browser ever be made to run it on its own. The one thing left possible is a script load from this site's own address, which reaches this site's server and no other: the site answers no address with a redirect to another site. The library, as vendored, makes no request of any kind (measured in three browsers). The worker decodes one file at a time, brings Display P3 colours into sRGB (the library hands back the file's own numbers) and hands the pixels back to the page. Loaded only by the image converter, only when a HEIC or HEIF file is dropped, and only where the browser cannot read that file by itself (Safari reads most). Not copied: the pure-JavaScript build (libheif/), the single-file bundles, the type declarations.