Open-source notices
Every component below is self-hosted from fileslimmer.com. Full licence text and copyright notices are held in each project's linked repository.
FileSlimmer is operated by ZENIT GROUP S.A.S. Reviewed licence state for this release: 16 August 2026.
Bundled libraries
| Component | Version | Licence (SPDX) | Source |
|---|---|---|---|
| astro | 7.2.2 | MIT | withastro/astro |
| @astrojs/preact | 6.0.2 | MIT | withastro/astro |
| preact | 10.29.8 | MIT | preactjs/preact |
| @preact/signals | 2.11.1 | MIT | preactjs/signals |
| browser-image-compression | 2.0.2 | MIT | Donaldcwl/browser-image-compression |
| @jsquash/jpeg | 1.6.0 | Apache-2.0 | jamsinclair/jSquash |
| @jsquash/png | 3.1.1 | Apache-2.0 | jamsinclair/jSquash |
| @jsquash/oxipng | 2.3.0 | Apache-2.0 | jamsinclair/jSquash |
| @jsquash/webp | 1.5.0 | Apache-2.0 | jamsinclair/jSquash |
| @jsquash/avif | 2.1.1 | Apache-2.0 | jamsinclair/jSquash |
| @jsquash/resize | 2.1.1 | Apache-2.0 | jamsinclair/jSquash |
| onnxruntime-web | 1.27.0 | MIT | microsoft/onnxruntime |
| pdf-lib | 1.17.1 | MIT | Hopding/pdf-lib |
| pdfjs-dist | 6.2.108 | Apache-2.0 | mozilla/pdf.js |
| svgo | 4.0.2 | MIT | svg/svgo |
| terser | 5.50.0 | BSD-2-Clause | terser/terser |
| csso | 5.0.5 | MIT | css/csso |
| fflate | 0.8.3 | MIT | 101arrowz/fflate |
| mediabunny | 1.54.0 | MPL-2.0 | Vanilagy/mediabunny |
The jSquash packages carry Apache-2.0 for the JavaScript wrapper and redistribute the upstream codec builds under their own terms: MozJPEG (BSD-3-Clause and IJG), libwebp (BSD-3-Clause), libaom (BSD-2-Clause) and oxipng (MIT). ONNX Runtime Web bundles Boost-licensed (BSL-1.0) and Apache-2.0 components alongside its MIT core, and PDF.js redistributes BSD-3-Clause font tooling.
Mozilla Public License 2.0 — Mediabunny
Mediabunny is distributed under the MPL-2.0, which is file-level copyleft. FileSlimmer ships Mediabunny unmodified. If a future release modifies a Mediabunny source file, the modified file is published under the MPL-2.0 and linked from this page. The full licence text and the corresponding source are available in the Mediabunny repository.
LGPL components and the relinking offer
Two WebAssembly modules are built from LGPL-licensed sources by FileSlimmer's own reproducible build scripts:
| Module | Licence (SPDX) | Build script | Upstream source |
|---|---|---|---|
Decode-only libheif build, served at /wasm/heic/libheif-decode.wasm |
LGPL-3.0-or-later |
scripts/build-libheif.mjs |
strukturag/libheif, strukturag/libde265 |
Narrow FFmpeg core, served at /wasm/video/ffmpeg-core.wasm |
LGPL-2.1-or-later |
scripts/build-custom-ffmpeg.mjs |
FFmpeg/FFmpeg |
The libheif module is distributed with this build. Its complete corresponding source ships beside it and is downloadable directly:
/wasm/heic/libheif-decode.wasm— the module, built from libheif v1.19.5 and libde265 v1.0.15/wasm/heic/libheif-source.tar.gz— the complete corresponding source for that moduleLICENSE.libheif.txtandLICENSE.libde265.txt— the licence textsRELINKING.md— the build parameters and the exported interface
The narrow FFmpeg core is not distributed: it is absent from this build and no route serves it. The offer below covers it should a future build include it.
Written offer for corresponding source
ZENIT GROUP S.A.S. distributes the complete corresponding source for these modules, together with the build scripts, the emscripten toolchain configuration and the exact upstream revision and configure flags used to produce each artifact. For three years from the date a build containing these modules is distributed, ZENIT GROUP S.A.S. will supply that corresponding source to any recipient on written request, on a durable medium or by download, for a charge no greater than the cost of performing the distribution.
Relinking
The module is a standalone WebAssembly file fetched at runtime, not statically linked into the application bundle. A recipient may modify libheif or libde265, rebuild the module with the published build script, and replace the shipped artifact at /wasm/heic/libheif-decode.wasm with their own — the application loads it by URL and calls it through the C interface listed in RELINKING.md, so any build exporting that same interface takes its place without modifying FileSlimmer.
The exported symbols, the emscripten flags and the exact upstream tags are recorded in RELINKING.md and reproduced by scripts/build-libheif.mjs, which pins the toolchain image. The decode-only build excludes x265 encoding, so no GPL-only component is present.
Carrera 7T No. 73-119
Cali, Valle del Cauca, Colombia
NIT: 902023036-6
Mercantile registration: 1273566-16
Cámara de Comercio de Cali
Legal representative: Emilssen Rodríguez Ballesteros
Email: info@zenitgroup.com.co
Phone: +57 314 729 1775
Machine-learning models
Background removal runs a self-hosted, hash-pinned ONNX model through ONNX Runtime Web. Model weights are licensed separately from the runtime.
| Model | Task | Licence (SPDX) | Source |
|---|---|---|---|
| MODNet, quantized | Portrait matting | Apache-2.0 | ZHKKKe/MODNet |
| U²-NetP-compatible | Salient-object segmentation | Apache-2.0, pending artifact verification | xuebinqin/U-2-Net |
Both model artifacts are distributed with this build and are served on demand when a visitor asks for background removal. Each is pinned to a sha256 recorded in
src/engines/ai/model-registry.ts, and the worker refuses any file whose digest does not match before it reaches an inference session.
/models/u2netp/u2netp-reviewed-v1.onnx— salient-object detection, the default. Apache-2.0./models/modnet/modnet-quantized-v1.onnx— portrait matting, reached through the passport preset. Apache-2.0.
Components that are not distributed
Some libraries were reviewed and left out. @imgly/background-removal is AGPL-3.0-or-later, which does not fit this distribution, and is not installed. heic2any is not used in production because a licensing question about its bundled decoder distribution is unresolved. The stock @ffmpeg/core distribution is replaced by the narrow build described above. None of these are served to browsers.