Decoder provenance: heic-to npm 1.6.5, verified against npm SHA-512 integrity. Exact unmodified module: package/src/lib/libheif-without-unsafe-eval.js, served as libheif.js. Sources: libheif v1.23.5; libde265 v1.0.16; heic-to 1.6.5 npm archive including README and worker/build configuration. Use the included heic-to libheif build instructions with USE_UNSAFE_EVAL=0, USE_WASM=0 and LIBDE265_VERSION=1.0.16. Inspect the included package README and libheif build-emscripten.sh for required Emscripten tools. Exact upstream build command in a libheif buildjs directory: LIBDE265_VERSION=1.0.16 USE_UNSAFE_EVAL=0 USE_WASM=0 ../build-emscripten.sh .. The upstream README documents the llvm-nm path adjustment used on macOS. Original project: https://github.com/hoppergee/heic-to FileMelon wrapper source: ../heic-worker.js and ../image-decoder.js, supplied in readable form. No changes to the compiled decoder. Workers load the library from this site only.