# Media engine source and build records

These five archives are unmodified upstream source snapshots. They are associated with the published versions below; no byte-identical rebuild is claimed.

- `@ffmpeg/core@0.12.10`: GPL-2.0-or-later. The matching ffmpeg.wasm release is `v12.15`, commit `71aa99d37c02a7b4c435275ca9ef50e612f6efa1`. The similarly named `v0.12.10` release contains core 0.12.6 and is not the correct release.
- `heic-to@1.5.2`: source LICENSE grants LGPL-3.0-or-later; npm metadata abbreviates this as LGPL-3.0. Exact npm gitHead is `f37af866f9aa6212ddc84b67a279c9f2386aba4f`.

| Archive | Bytes | Source revision |
|---|---:|---|
| ffmpeg-wasm-v12.15.tar.gz | 1329368 | 71aa99d37c02a7b4c435275ca9ef50e612f6efa1 |
| heic-to-1.5.2.tar.gz | 5970908 | f37af866f9aa6212ddc84b67a279c9f2386aba4f |
| ffmpeg-5.1.4.tar.gz | 14428595 | 4729204c17f756e186d622060088371d10b34f7e |
| libheif-1.22.2.tar.gz | 2006398 | 763bc8bb87788d64d39ece623ceed988de12dc5b |
| libde265-1.0.16.tar.gz | 439851 | 7ba65889d3d6d8a0d99b5360b028243ba843be3a |

All files are below 25 MB individually. `manifest.json` records original URLs, SHA-256 hashes, licenses and source provenance. License text copies are included.

## Completeness limitations

- The ffmpeg.wasm release tag proves release association, not a byte-for-byte source-to-binary attestation; npm core metadata contains no gitHead.
- The Dockerfile fetches external repositories. In particular x264 4-cores and lame master are floating branches; exact commits used by the 2025 publisher are not recorded. Other named refs also require immutable resolution for a reproducible rebuild.
- The five downloaded archives do not include all FFmpeg codec dependency sources. Their original refs and URLs are listed separately. zimg is cloned recursively, so submodule sources also need inclusion for a complete source bundle.
- The FFmpeg recipe pins emscripten/emsdk:3.1.40 by tag, not digest, and pulls apt build dependencies without exact versions. It also builds SDL2 via Emscripten ports. Those build inputs are not downloaded here.
- heic-to source includes generated libheif JavaScript. The preferred C/C++ sources are the separately downloaded libheif and libde265 archives. Exact build environment is not fully recorded: README uses brew install emscripten and a local llvm-nm path replacement.
- heic-to README sets LIBDE265_VERSION=1.0.16 USE_WASM=0. The libheif script defaults AOM and OpenJPEG support off; no evidence reviewed here proves additional optional codecs were enabled in the published bundle.
- No byte-identical rebuild or package-binary comparison was performed. These artifacts should be labeled upstream sources and build instructions, not certified complete corresponding source or verified reproducible source.
- License notices and source links do not by themselves resolve every distribution obligation. Preserve the exact license grants and copyright notices, and retain the means needed to replace/rebuild applicable LGPL components.

## All codec/library refs from the matched FFmpeg Dockerfile

- [ffmpegwasm/x264](https://github.com/ffmpegwasm/x264/tree/4-cores): `4-cores` (known floating branch).
- [ffmpegwasm/x265](https://github.com/ffmpegwasm/x265/tree/3.4): `3.4`.
- [ffmpegwasm/libvpx](https://github.com/ffmpegwasm/libvpx/tree/v1.13.1): `v1.13.1`.
- [ffmpegwasm/lame](https://github.com/ffmpegwasm/lame/tree/master): `master` (known floating branch).
- [ffmpegwasm/Ogg](https://github.com/ffmpegwasm/Ogg/tree/v1.3.4): `v1.3.4`.
- [ffmpegwasm/theora](https://github.com/ffmpegwasm/theora/tree/v1.1.1): `v1.1.1`.
- [ffmpegwasm/opus](https://github.com/ffmpegwasm/opus/tree/v1.3.1): `v1.3.1`.
- [ffmpegwasm/vorbis](https://github.com/ffmpegwasm/vorbis/tree/v1.3.3): `v1.3.3`.
- [ffmpegwasm/zlib](https://github.com/ffmpegwasm/zlib/tree/v1.2.11): `v1.2.11`.
- [ffmpegwasm/libwebp](https://github.com/ffmpegwasm/libwebp/tree/v1.3.2): `v1.3.2`.
- [ffmpegwasm/freetype2](https://github.com/ffmpegwasm/freetype2/tree/VER-2-10-4): `VER-2-10-4`.
- [fribidi/fribidi](https://github.com/fribidi/fribidi/tree/v1.0.9): `v1.0.9`.
- [harfbuzz/harfbuzz](https://github.com/harfbuzz/harfbuzz/tree/5.2.0): `5.2.0`.
- [libass/libass](https://github.com/libass/libass/tree/0.15.0): `0.15.0`.
- [FFmpeg/FFmpeg](https://github.com/FFmpeg/FFmpeg/tree/n5.1.4): `n5.1.4`.
- [sekrit-twc/zimg](https://github.com/sekrit-twc/zimg/tree/release-3.0.5): `release-3.0.5`. Includes recursive submodules.
