Project FileIvy third-party image codec notices Updated: 13 August 2026 FileIvy uses these exact-pinned packages only for local, lazy image processing: 1. heic-to 1.5.2 — LGPL-3.0 Upstream source: https://github.com/hoppergee/heic-to Package source: https://www.npmjs.com/package/heic-to/v/1.5.2 Includes libheif 1.22.2 and its applicable codec components. FileIvy uses the unmodified CSP-safe distribution and does not send HEIC/HEIF files to a server. 2. tiff 7.1.3 — MIT Upstream source: https://github.com/image-js/tiff Package source: https://www.npmjs.com/package/tiff/v/7.1.3 3. @jsquash/avif 2.1.1 — Apache-2.0 Upstream source: https://github.com/jamsinclair/jSquash Package source: https://www.npmjs.com/package/@jsquash/avif/v/2.1.1 Derived from libavif/Squoosh browser codec work as documented upstream. The full license text for each package is included in its distributed package and source repository. FileIvy modifies no third-party codec source. Report codec security concerns through the normal Project FileIvy security channel.