# Third-party software and model notices

All dependencies are downloaded at development/build time, checksum-verified and served from this app's own origin. No runtime CDN or model-host request is required. Upstream JavaScript and WASM binaries are unmodified; large binary files are byte-split for hosting and verified/reassembled before use.

- Hugging Face Transformers.js 4.3.0, Apache-2.0. Browser image preprocessing and depth pipeline. https://github.com/huggingface/transformers.js
- ONNX Runtime Web 1.31.0-dev.20260914-8d85527a0 and bundled ONNX Runtime Common 1.30.0, MIT. WebGPU/WASM inference. https://github.com/microsoft/onnxruntime
- Bundled Hugging Face Tokenizers 0.2.0, Apache-2.0, and Jinja 0.5.10, MIT. Included in upstream Transformers distribution; not invoked for photo depth. https://github.com/huggingface/tokenizers.js and https://github.com/huggingface/huggingface.js
- ONNX Community Depth Anything V2 Small at revision 4472b7362082ad9968fee890ca0f1e5aca36b93d, Apache-2.0. Quantized and FP16 conversions of Depth Anything V2 Small. https://huggingface.co/onnx-community/depth-anything-v2-small and https://huggingface.co/depth-anything/Depth-Anything-V2-Small

Full license texts and ONNX Runtime third-party notices are deployed in licenses/. Source URLs and SHA-256 pins are in vendor-source/lock.json; deployed chunk checksums and sizes are in vendor/manifest.json. Model weights are not changed or retrained. Source/model data ownership remains with the respective upstream authors. The application does not claim that a single photo reconstructs unseen surfaces.

Advisory check on 2026-10-01: npm bulk advisory lookup for the exact listed software versions returned no matches, and the upstream Transformers.js/ONNX Runtime advisory lists were empty. This is a point-in-time check, not a security guarantee.

Transitive advisory note: ONNX Runtime’s upstream source lock lists protobufjs7.6.3, associated with GHSA-j3f2-48v5-ccww (hostile .proto-schema parsing infinite loop, fixed7.6.5). Transformers4.3.0’s lock lists7.6.6. The advisory excludes trusted-schema binary decoding; this app accepts only the fixed, checksum-validated ONNX model and does not parse user-provided schema/model files. This is not a complete native-WASM security audit. https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww
