# SZL 3D — Vendored Library Manifest (Dev0 foundation) Doctrine v11: **0 runtime CDN.** Every 3D library the holographic estate uses is vendored here, in-image, and served same-origin via the allowlisted `/static/3d/vendor/...` route (see `szl3d_holographic.py`). No ` ``` `szl3d_boot.js` uses `three/webgpu` when `navigator.gpu` is present and a device can be acquired, otherwise it imports `three` (WebGL2 `WebGLRenderer`). Both builds are r170 so the scene graph / addons are byte-compatible across the fallback. ## VENDORED ALREADY (elsewhere in the repo, reusable, 0 CDN) These predate this PR and are already served in-image. Devs MAY reuse them instead of re-vendoring: - `static-vendor/3d-force-graph.min.js` — **3d-force-graph** UMD global build (served at `/vendor/3d-force-graph.min.js`). Use for Dev2 (compute fabric) and Dev5 (governance dependency graph). UMD global `ForceGraph3D`. - `static-vendor/three.min.js` — three **r128** UMD standalone (global `THREE`), served at `/vendor/three.min.js`. Legacy; new surfaces SHOULD use the r170 ESM build vendored above, not this. - `static/vendor3d/three.module.min.js` + `OrbitControls.js` — three **r160** ESM, served at `/hero/vendor3d/*`. Superseded by the r170 build here. ## TODO — libraries OTHER devs need, NOT yet vendored (pinned + planned) Vendoring deck.gl + CesiumJS fully is heavy (deck.gl bundle ~1.2 MB, Cesium ~3 MB JS + assets) and out of scope for this foundation PR per the Dev0 contract's escape hatch. They are listed here with the **exact pinned versions** the owning dev must vendor (download once, commit under `/static/3d/vendor//`, add the sha256 to this table, and extend the `_ALLOW` map in `szl3d_holographic.py`). Do **NOT** add a CDN `