# Vendored browser dependencies

Web V1 serves exact pinned assets from `vendor/` on the same static origin. Source tarballs came from the official npm registry, were verified against registry SHA-512 integrity values, and only browser assets plus license files were extracted. `vendor/sources.json` records the tarball URLs and integrity values; `vendor/SHA256SUMS.txt` records file hashes. `tools/vendor.ps1` is a maintainer-only refresh script, not required at runtime. No npm/pnpm installation or build step was used. Choose JSZip's MIT license option.

| Library | Exact version | License | Role |
| --- | --- | --- | --- |
| PDF.js / pdfjs-dist | 5.4.296 | Apache-2.0 | PDF page count and sequential Canvas rendering, plus module worker and data assets |
| pdf-lib | 1.17.1 | MIT | PDF generation, raster embedding, ordered PDF page copying |
| JSZip | 3.10.1 | MIT option of `(MIT OR GPL-3.0-or-later)` | One ZIP for multi-page image outputs |
| jsPDF | 4.2.1 | MIT | Vector PDF document creation from SVG |
| svg2pdf.js | 2.8.1 | MIT | Checked SVG shape conversion to PDF drawing operators |

The exact upstream license texts are retained under each versioned vendor directory. The SVG adapter rejects unsafe/unsupported constructs before invoking svg2pdf.js. This narrows input but is not a formal proof that arbitrary untrusted SVG can be safely converted; the documented subset and final browser acceptance define supported behavior. The browser asset bundles may include bundled transitive code and notices from their distributions. Registry integrity and license verification are distinct from a vulnerability audit.

The previous CDN strategy was replaced because a local copy gives deterministic static deployment and no third-party runtime asset fetch. No floating `latest` URL is used. Future updates should repeat version, license, integrity, regression, and browser checks before replacing assets.
