Move Arcade 0.4.0. Vendored: @mediapipe/tasks-vision 1.1.0 (web/mp/vision_bundle.mjs is LOCALLY PATCHED, see below; vision_wasm_* unmodified), three 0.186.1 (web/mp/three.*.js, unmodified), MediaPipe pose_landmarker_lite.task (web/models/, unmodified). Build: GOOS=windows GOARCH=amd64 go build -ldflags "-H=windowsgui -s -w -X main.version=0.4.0"

LOCAL PATCH to web/mp/vision_bundle.mjs (MediaPipe tasks-vision 1.1.0): its built-in usage logger (class Mh) POSTed protobuf to https://odml.pa.googleapis.com/v1/log every 60 s. Disabled in this copy by 3 edits:
 1. constructor: `this.h=setInterval(()=>{this.flush()},6e4)` -> `this.h=void 0`   (no timer)
 2. close(){...this.flush()} -> close(){this.i=[]}; flush(t,e){ now starts with `this.i=[];t?.();return;` (discard, never send); the URL literal is replaced by "about:blank#telemetry-disabled"
 3. event enqueue `(t=t.m).error||t.i.push(e)` -> `void 0` (nothing is queued)
Original is the unmodified npm tarball @mediapipe/tasks-vision@1.1.0. In addition the local server sends a Content-Security-Policy with connect-src 'self' data: blob:, so no page script can contact any other host.

0.4.0 additions (all vendored offline in web/models/, unmodified, served from localhost only, no network use):
 pose_landmarker_full.task (9.4 MB) and pose_landmarker_heavy.task (30.7 MB), hand_landmarker.task (7.8 MB), selfie_segmenter.tflite (0.25 MB).
 Source: https://storage.googleapis.com/mediapipe-models/ (Google MediaPipe; Apache-2.0 code; same wasm runtime and the same locally telemetry-patched vision_bundle.mjs as before).
 SHA-256: pose_landmarker_full 4eaa5eb7a98365221087693fcc286334cf0858e2eb6e15b506aa4a7ecdcec4ad; pose_landmarker_heavy 64437af838a65d18e5ba7a0d39b465540069bc8aae8308de3e318aad31fcbc7b; hand_landmarker fbc2a30080c3c557093b5ddfc334698132eb341044ccee322ccf8bcf3607cde1; selfie_segmenter 191ac9529ae506ee0beefa6b2c945a172dab9d07d1e802a290a4e4038226658b.
 Headless audit 0.4.0: a full session (menu, game, projector, with the pose + segmenter + hand models) made zero requests outside localhost.
