LAZ decoder distributed with TSA GeoTwin Unmodified JavaScript binding (renamed .js to .mjs) and WebAssembly: @loaders.gl/las 4.5.2, dist/libs/laz-rs-wasm/ loaders.gl source commit: 1fb4da2f508244e22e1aebc0e990f782007c27f5 https://github.com/visgl/loaders.gl/tree/1fb4da2f508244e22e1aebc0e990f782007c27f5/modules/las/src/libs/laz-rs-wasm Binding upstream: laz-rs-wasm 0.1.0 (MIT) Copyright (c) 2024 Thomas Montaigu; collaborators Chris Lee. https://github.com/laz-rs/laz-rs-wasm/tree/714d70b9bc5cf5d8fcdff15e0c87d265d0114594 The bundled binary identifies laz 0.5.2. THAT VERSION is LGPL-2.1 with the static-linking exception in its LICENSE.txt, not the Apache license of more recent laz releases. See the exact original texts in LICENSE.txt. The full laz 0.5.2 source, pinned binding source, build instructions and replacement instructions are supplied alongside this file in source.zip. GeoTwin's application wrapper is separate: it calls the public WasmLasZipDecompressor constructor, decompress_many and free APIs and interprets the returned LAS records. No changes to the vendor binary or generated JavaScript have been made. Users may build a modified decoder and replace the binding and WASM pair; GeoTwin does not check a vendor hash at runtime or prohibit reverse engineering for debugging changes. Upstream does not publish the original Cargo.lock/toolchain build recipe with this npm artifact. The source association uses the exact laz crate identified by binary strings, upstream package metadata, pinned wrapper API and error-string comparison. Byte-identical reproducibility of that upstream binary and a complete transitive Rust SBOM are not attested. This package does not claim that the previous overall licensing audit is closed. File hashes and URLs are in the repository evidence manifest.