mdb-reader 3.2.0 (MIT) - reader for Microsoft Access databases (.mdb Jet 3/Jet 4, .accdb ACE 12-17), by Andi Pätzold. LICENSE is the package's own LICENSE file. lib/browser/dependencies/iconv-lite/ (here dependencies/iconv-lite/index.js) is a few lines adapted from iconv-lite (MIT) by the mdb-reader author for Windows-1252 text and ships inside the same MIT package. Source: npm registry tarball mdb-reader-3.2.0.tgz (registry.npmjs.org/mdb-reader/-/mdb-reader-3.2.0.tgz) sha256 c0d066a8086ee5361ef8b0d6293b2832f1dad5b6f8f7e00d02d7c8adbf104398 sha1 036407472681d9e24ce180fcfa5e3d5f31037269 (matches the registry's dist.shasum) Files: every .js under the package's lib/browser/ (its browser build: plain ES modules), same paths, built by tools/vendor-mdb-reader.cjs (it checks the sha256 above before unpacking, so re-running it reproduces these files exactly). Left out: lib/node/ (the Node build), lib/types/ (TypeScript declarations), README.md, package.json. Runtime dependencies declared by the package, and what happened to each (all are only reached from environment/index.js and one encryption file): - pako (MIT AND Zlib), for inflating compressed attachments: NOT vendored. Replaced by fflate 0.8.3 (MIT, ../fflate/), decompressSync. - create-hash, browserify-aes (MIT, with a tree of further packages, some ISC): NOT vendored. They are used only to decrypt an Access 2007+ file encrypted with a password. viewhack does not decrypt; such files are refused by name. - fast-xml-parser (MIT): NOT vendored. Used only to read the encryption descriptor of an encrypted .accdb; same reason. - Node's Buffer (the library calls Buffer.from/alloc/concat and Buffer read methods): browsers have none, so ../buffer/ (buffer 6.0.3, MIT, with base64-js MIT and ieee754 BSD-3-Clause) is imported first by js/access-core.js and sets globalThis.Buffer. Changes: 1. environment/index.js is viewhack's own (the original imported the four packages above): inflate = fflate's decompressSync; createHash and createDecipheriv throw an Error named VHEncryptedError ("This database is encrypted with a password."), which js/access-core.js turns into the plain refusal shown on /access/. 2. environment/no-xml-parser.js is new: an XMLParser whose parse() throws the same VHEncryptedError. codec-handler/handlers/office/agile/EncryptionDescriptor.js line 1 imports it instead of "fast-xml-parser" (the only edited library statement). 3. Documentation links in comments lost their "http(s)://" prefix (the link text stays), so test/no-external-hosts.test.cjs sees no remote host. The build script refuses any URL outside a comment line. Lines touched: Database.js 90, 101; JetFormat/index.js 17-20; PageType.js 2; SysObject.js 2, 23; Table.js 220, 240; codec-handler/handlers/office/index.js 8; column.js 22, 23, 33; data/currency.js 5; data/memo.js 7; data/numeric.js 5; data/ole.js 8, 9; data/repid.js 4; data/util.js 2; dependencies/iconv-lite/index.js 2, 8, 14; unicodeCompression.js 3; usage-map.js 5, 18, 26; util.js 18. Licence check (2026-10-01): mdb-reader's package.json "license" is MIT and LICENSE is the MIT text.