OpusDesk Hub HEIC decoder — corresponding source and replacement The supplied libheif and libde265 source archives are compiled with the official Emscripten 3.1.61 image pinned in BUILD-RECEIPT.json. The readable controlled-build.sh selects single-threaded libde265, ES6/WASM, and no unsafe eval. No upstream source or WASM byte is patched; declarations are omitted (USE_TYPESCRIPT=0). The included embed.mjs embeds the new WASM bytes in a replaceable module without minification. The historical libheif-js npm binary is NOT shipped as the decoder and no bit-for-bit equivalence to it is claimed. The two wrapper archives remain as historical acquisition material, not as build inputs to the current decoder. Create an empty work directory and compiled output directory, mount work at /work, the pinned source archives directory at /inputs (read-only), this directory at /recipe (read-only), and compiled output at /output. Run bash /recipe/controlled-build.sh in the pinned Emscripten container. Network is not needed during compilation; the compiler image itself must be acquired first. Then run node embed.mjs . Preserve the full LGPL/GPL license texts and notices provided in ../licenses and ../sources. Replace vendor/rebuilt-heic/libheif-bundle.mjs with your interface-compatible modified library, run the application build, and refresh static-host caches. The image worker dynamically imports this separate module; there is no signature, SRI, account or approval lock. Keep factory(options), HeifDecoder.decode, image.get_width/get_height/display/free, and heif_context_free interfaces. Reverse engineering to debug modifications to this LGPL library is permitted. The application source, worker, package lock and build scripts are supplied. This source material is not a consumer offline application or legal certification.