LAZ decoder distributed with TSA GeoTwin

Unmodified JavaScript binding (renamed .js to .mjs) and WebAssembly:
@loaders.gl/las 4.5.2, dist/libs/laz-rs-wasm/
loaders.gl source commit: 1fb4da2f508244e22e1aebc0e990f782007c27f5
https://github.com/visgl/loaders.gl/tree/1fb4da2f508244e22e1aebc0e990f782007c27f5/modules/las/src/libs/laz-rs-wasm

Binding upstream: laz-rs-wasm 0.1.0 (MIT)
Copyright (c) 2024 Thomas Montaigu; collaborators Chris Lee.
https://github.com/laz-rs/laz-rs-wasm/tree/714d70b9bc5cf5d8fcdff15e0c87d265d0114594

The bundled binary identifies laz 0.5.2. THAT VERSION is LGPL-2.1 with
the static-linking exception in its LICENSE.txt, not the Apache license
of more recent laz releases. See the exact original texts in LICENSE.txt.
The full laz 0.5.2 source, pinned binding source, build instructions and
replacement instructions are supplied alongside this file in source.zip.

GeoTwin's application wrapper is separate: it calls the public
WasmLasZipDecompressor constructor, decompress_many and free APIs and
interprets the returned LAS records. No changes to the vendor binary or
generated JavaScript have been made. Users may build a modified decoder
and replace the binding and WASM pair; GeoTwin does not check a vendor
hash at runtime or prohibit reverse engineering for debugging changes.

Upstream does not publish the original Cargo.lock/toolchain build recipe
with this npm artifact. The source association uses the exact laz crate
identified by binary strings, upstream package metadata, pinned wrapper
API and error-string comparison. Byte-identical reproducibility of that
upstream binary and a complete transitive Rust SBOM are not attested.
This package does not claim that the previous overall licensing audit
is closed. File hashes and URLs are in the repository evidence manifest.
