Dirk Farin, the independent developer behind the libheif and libde265 HEIC and AVIF codec libraries, updated the project’s status note to say the libraries are used by practically every open-source application and service that handles HEIC or AVIF files, but that the maintenance work is almost entirely unfunded. The note reports that 73 security advisories were published for libheif between January and October 2026, most of them found with automated tools by organizations that ship the library in their products, and that ten releases were made mainly to ship security fixes, with reproducing, fixing, testing, fuzzing and releasing still done in evenings and on weekends. Recurring sponsorship through GitHub Sponsors amounted to 1 per month as of September against a ,000 monthly goal that would fund about two days a week, and the project is offering paid commercial support that includes pre-release notice of embargoed advisories, a direct contact for security and integration questions, an agreed number of engineering hours per month, and scoped hardening or fuzzing projects.
libheif maintainer says HEIC and AVIF maintenance runs on almost no funding
Dirk Farin, the independent developer behind the libheif and libde265 HEIC and AVIF codec libraries, updated the project's status note to say the libraries are used by practically every open-source application and service that handles HEIC or AVIF files, but that the maintenance work is almost entirely unfunded. The note reports that 73 security advisories were published for libheif between January and October 2026, most of them found with automated tools by organizations that ship the library in their products, and that ten releases were made mainly to ship security fixes, with reproducing, fixing, testing, fuzzing and releasing still done in evenings and on weekends. Recurring sponsorship through GitHub Sponsors amounted to 1 per month as of September against a ,000 monthly goal that would fund about two days a week, and the project is offering paid commercial support that includes pre-release notice of embargoed advisories, a direct contact for security and integration questions, an agreed number of engineering hours per month, and scoped hardening or fuzzing projects.
Source: Github