Open-source notices

Every component below is self-hosted from fileslimmer.com. Full licence text and copyright notices are held in each project's linked repository.

FileSlimmer is operated by ZENIT GROUP S.A.S. Reviewed licence state for this release: 16 August 2026.

Bundled libraries

Production dependencies, their pinned versions and licences.
ComponentVersionLicence (SPDX)Source
astro7.2.2MITwithastro/astro
@astrojs/preact6.0.2MITwithastro/astro
preact10.29.8MITpreactjs/preact
@preact/signals2.11.1MITpreactjs/signals
browser-image-compression2.0.2MITDonaldcwl/browser-image-compression
@jsquash/jpeg1.6.0Apache-2.0jamsinclair/jSquash
@jsquash/png3.1.1Apache-2.0jamsinclair/jSquash
@jsquash/oxipng2.3.0Apache-2.0jamsinclair/jSquash
@jsquash/webp1.5.0Apache-2.0jamsinclair/jSquash
@jsquash/avif2.1.1Apache-2.0jamsinclair/jSquash
@jsquash/resize2.1.1Apache-2.0jamsinclair/jSquash
onnxruntime-web1.27.0MITmicrosoft/onnxruntime
pdf-lib1.17.1MITHopding/pdf-lib
pdfjs-dist6.2.108Apache-2.0mozilla/pdf.js
svgo4.0.2MITsvg/svgo
terser5.50.0BSD-2-Clauseterser/terser
csso5.0.5MITcss/csso
fflate0.8.3MIT101arrowz/fflate
mediabunny1.54.0MPL-2.0Vanilagy/mediabunny

The jSquash packages carry Apache-2.0 for the JavaScript wrapper and redistribute the upstream codec builds under their own terms: MozJPEG (BSD-3-Clause and IJG), libwebp (BSD-3-Clause), libaom (BSD-2-Clause) and oxipng (MIT). ONNX Runtime Web bundles Boost-licensed (BSL-1.0) and Apache-2.0 components alongside its MIT core, and PDF.js redistributes BSD-3-Clause font tooling.

Mozilla Public License 2.0 — Mediabunny

Mediabunny is distributed under the MPL-2.0, which is file-level copyleft. FileSlimmer ships Mediabunny unmodified. If a future release modifies a Mediabunny source file, the modified file is published under the MPL-2.0 and linked from this page. The full licence text and the corresponding source are available in the Mediabunny repository.

LGPL components and the relinking offer

Two WebAssembly modules are built from LGPL-licensed sources by FileSlimmer's own reproducible build scripts:

LGPL WebAssembly modules and their build scripts.
ModuleLicence (SPDX)Build scriptUpstream source
Decode-only libheif build, served at /wasm/heic/libheif-decode.wasm LGPL-3.0-or-later scripts/build-libheif.mjs strukturag/libheif, strukturag/libde265
Narrow FFmpeg core, served at /wasm/video/ffmpeg-core.wasm LGPL-2.1-or-later scripts/build-custom-ffmpeg.mjs FFmpeg/FFmpeg

The libheif module is distributed with this build. Its complete corresponding source ships beside it and is downloadable directly:

The narrow FFmpeg core is not distributed: it is absent from this build and no route serves it. The offer below covers it should a future build include it.

Written offer for corresponding source

ZENIT GROUP S.A.S. distributes the complete corresponding source for these modules, together with the build scripts, the emscripten toolchain configuration and the exact upstream revision and configure flags used to produce each artifact. For three years from the date a build containing these modules is distributed, ZENIT GROUP S.A.S. will supply that corresponding source to any recipient on written request, on a durable medium or by download, for a charge no greater than the cost of performing the distribution.

Relinking

The module is a standalone WebAssembly file fetched at runtime, not statically linked into the application bundle. A recipient may modify libheif or libde265, rebuild the module with the published build script, and replace the shipped artifact at /wasm/heic/libheif-decode.wasm with their own — the application loads it by URL and calls it through the C interface listed in RELINKING.md, so any build exporting that same interface takes its place without modifying FileSlimmer.

The exported symbols, the emscripten flags and the exact upstream tags are recorded in RELINKING.md and reproduced by scripts/build-libheif.mjs, which pins the toolchain image. The decode-only build excludes x265 encoding, so no GPL-only component is present.

ZENIT GROUP S.A.S.
Carrera 7T No. 73-119
Cali, Valle del Cauca, Colombia
NIT: 902023036-6
Mercantile registration: 1273566-16
Cámara de Comercio de Cali
Legal representative: Emilssen Rodríguez Ballesteros
Email: info@zenitgroup.com.co
Phone: +57 314 729 1775

Machine-learning models

Background removal runs a self-hosted, hash-pinned ONNX model through ONNX Runtime Web. Model weights are licensed separately from the runtime.

Model artifacts, their tasks and licences.
ModelTaskLicence (SPDX)Source
MODNet, quantizedPortrait mattingApache-2.0ZHKKKe/MODNet
U²-NetP-compatibleSalient-object segmentationApache-2.0, pending artifact verificationxuebinqin/U-2-Net

Both model artifacts are distributed with this build and are served on demand when a visitor asks for background removal. Each is pinned to a sha256 recorded in src/engines/ai/model-registry.ts, and the worker refuses any file whose digest does not match before it reaches an inference session.

Components that are not distributed

Some libraries were reviewed and left out. @imgly/background-removal is AGPL-3.0-or-later, which does not fit this distribution, and is not installed. heic2any is not used in production because a licensing question about its bundled decoder distribution is unresolved. The stock @ffmpeg/core distribution is replaced by the narrow build described above. None of these are served to browsers.