# SZL 3D — Vendored Library Manifest (Dev0 foundation)
Doctrine v11: **0 runtime CDN.** Every 3D library the holographic estate uses is
vendored here, in-image, and served same-origin via the allowlisted
`/static/3d/vendor/...` route (see `szl3d_holographic.py`). No `
```
`szl3d_boot.js` uses `three/webgpu` when `navigator.gpu` is present and a device
can be acquired, otherwise it imports `three` (WebGL2 `WebGLRenderer`). Both builds
are r170 so the scene graph / addons are byte-compatible across the fallback.
## VENDORED ALREADY (elsewhere in the repo, reusable, 0 CDN)
These predate this PR and are already served in-image. Devs MAY reuse them instead
of re-vendoring:
- `static-vendor/3d-force-graph.min.js` — **3d-force-graph** UMD global build
(served at `/vendor/3d-force-graph.min.js`). Use for Dev2 (compute fabric) and
Dev5 (governance dependency graph). UMD global `ForceGraph3D`.
- `static-vendor/three.min.js` — three **r128** UMD standalone (global `THREE`),
served at `/vendor/three.min.js`. Legacy; new surfaces SHOULD use the r170 ESM
build vendored above, not this.
- `static/vendor3d/three.module.min.js` + `OrbitControls.js` — three **r160** ESM,
served at `/hero/vendor3d/*`. Superseded by the r170 build here.
## TODO — libraries OTHER devs need, NOT yet vendored (pinned + planned)
Vendoring deck.gl + CesiumJS fully is heavy (deck.gl bundle ~1.2 MB, Cesium ~3 MB
JS + assets) and out of scope for this foundation PR per the Dev0 contract's
escape hatch. They are listed here with the **exact pinned versions** the owning
dev must vendor (download once, commit under `/static/3d/vendor//`, add the
sha256 to this table, and extend the `_ALLOW` map in `szl3d_holographic.py`). Do
**NOT** add a CDN `