# Third-party components

Peelframe includes the following upstream components. Large WebAssembly/model files are split into byte-exact parts for delivery and concatenated in order in the browser. Any first-party model transformations are documented separately below.

- `@ffmpeg/ffmpeg` 0.12.15: MIT license. Upstream source repository: https://github.com/ffmpegwasm/ffmpeg.wasm
- `@ffmpeg/core` 0.12.10: GPL-2.0-or-later. FFmpeg n5.1.4 built by ffmpeg.wasm (commit 71aa99d37c02a7b4c435275ca9ef50e612f6efa1) with x264, x265, libvpx, LAME, Ogg, Theora, Opus, Vorbis, zlib, libwebp, FreeType, FriBidi, HarfBuzz, libass and zimg. Each library's license and copyright notice: `ffmpeg-core-libraries.txt`. Upstream source and build configuration: https://github.com/ffmpegwasm/ffmpeg.wasm
- Exact published packages: https://www.npmjs.com/package/@ffmpeg/ffmpeg/v/0.12.15 and https://www.npmjs.com/package/@ffmpeg/core/v/0.12.10
- Upstream FFmpeg source: https://github.com/FFmpeg/FFmpeg ; upstream x264 source: https://code.videolan.org/videolan/x264

See the accompanying license texts. Original copyright notices and license terms remain applicable to these components. Peelframe's first-party HTML, CSS, JavaScript, launchers, and README are provided in source form in the personal package. The site's application source is also retained in its source repository.

For rebuilding the binary, consult the pinned upstream source/build configuration and its dependency versions; the binary's file name does not imply that the engine is MIT-licensed. No proprietary code or paid service is needed for video processing in this version.

## AI test mode

- LaMa: https://github.com/advimman/lama (Apache-2.0). Included `lama-Apache-2.0.txt`.
- ONNX export: https://huggingface.co/g-ronimo/lama ; exact distributed model hash in `ai/assets.json`. Original model bytes are unchanged and split into eight byte-exact parts. Included model card.
- ONNX Runtime Web 1.23.2: https://github.com/microsoft/onnxruntime/tree/v1.23.2 (MIT), https://www.npmjs.com/package/onnxruntime-web/v/1.23.2. Included `onnxruntime-MIT.txt`. Original runtime assets preserved, WASM split into two byte-exact parts.

First-party AI implementation source is included as `ai.js` and `ai-worker.js`. No paid API is used.

- js-sha256 0.11.1: https://github.com/emn178/js-sha256 (MIT). SHA256 fallback in HTTP preview environments, included `js-sha256-MIT.txt`.

## Browser video acceleration (1.6.0)

- Mediabunny 1.61.0: https://github.com/Vanilagy/mediabunny ; exact published package https://www.npmjs.com/package/mediabunny/v/1.61.0 . MPL-2.0, included `mediabunny-MPL-2.0.txt`. The original `dist/bundles/mediabunny.min.mjs` is redistributed unchanged under `vendor/`. Corresponding upstream source is available from the pinned package/repository version.
- ONNX Runtime Web 1.23.2 WebGPU/JSEP assets: same MIT-licensed upstream package as the CPU runtime above. `ort.webgpu.min.js`, `ort-wasm-simd-threaded.jsep.mjs` are unchanged. JSEP WASM is split into three byte-exact parts; original length and SHA256 are in `ai/assets.json`.
- `scripts/prepare-browser-assets.mjs` copies the pinned upstream assets and prepares delivery parts. The library licenses continue to apply to their original files.

## LaMa speed profiles (1.5.0)

The 128/256 restoration profiles retain the original learned weights while changing the input and Fourier calculation grids. Their complete SHA256 values and byte patches are documented in `ai/assets.json`; first-party reproduction code is `scripts/make-fast-lama.py` in the Site source repository. The LaMa Apache-2.0 license and original model card remain included.

## Sign-in (1.8.0)

- Firebase JavaScript SDK 12.19.0 (`firebase/app`, `firebase/auth`; @firebase/app 0.16.2, @firebase/auth 1.13.6 and their @firebase/util, component and logger dependencies): https://github.com/firebase/firebase-js-sdk , exact package https://www.npmjs.com/package/firebase/v/12.19.0 . Apache-2.0. Bundled with esbuild 0.28.2 into `vendor/firebase-auth.js` (only the sign-in functions Peelframe uses; upstream license comments kept at the end of the file). Also includes tslib 2.8.1 (0BSD) and idb 7.1.1 (ISC). License texts: `Firebase-JS-SDK-NOTICE.txt`.
- The bundle is loaded only when `auth-config.js` contains a Firebase project (sign-in is enabled on the website and in the personal package since 1.8.1). Video processing never uses it.

## Source code (1.8.3)

The complete corresponding source code of the video engine `@ffmpeg/core` 0.12.10 (FFmpeg n5.1.4 and every library listed above, plus the ffmpeg.wasm build scripts at commit 71aa99d) is published on the website under `/source/`; `source/SOURCES.txt` lists each archive with its upstream address, version, commit and SHA-256. Mediabunny (MPL-2.0) is redistributed unmodified; its source is at https://github.com/Vanilagy/mediabunny/tree/v1.61.0 . In addition, for as long as Peelframe provides this video engine and for three years afterwards, the operator will give anyone who asks the complete corresponding source code for a charge no more than the cost of distribution (free when sent electronically); the contact address is on the site's Open-source licenses page (`licenses.html`). ONNX Runtime's own third-party notices: `onnxruntime-ThirdPartyNotices.txt`.
