Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -153,7 +153,7 @@ jobs:
if: matrix.language == 'csharp'
with:
global-json-file: global.json
- uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4
- uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Expand All @@ -162,7 +162,7 @@ jobs:
run: |
dotnet restore ArcSlate.slnx --locked-mode
dotnet build ArcSlate.slnx -c Release --no-restore -p:UseSharedCompilation=false
- uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4
- uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4
with:
category: /language:${{ matrix.language }}

Expand Down
18 changes: 9 additions & 9 deletions eng/policy/dependency-review.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"schemaVersion": 1,
"owner": "ArcSlate",
"decision": "approved",
"reviewedOn": "2026-09-21",
"reviewedOn": "2026-09-26",
"baselineCommit": "26331c3b240a95603d2f9d25949f47899ac484e0",
"baselineFrameworkVersions": {
"dotnet": "10.0.401",
Expand All @@ -11,18 +11,18 @@
"frameworkMajorUpgrade": false,
"runtimePostureAssessment": "No framework version changes: existing desktop Native AOT and trim posture retained.",
"checks": {
"compilation": "Retain required Windows/Linux compilation in the existing CI graph.",
"aot": "Retain Windows x64/ARM64 and Linux x64 AOT publication; no runtime graph changed.",
"compatibility": "No package versions, APIs or generated public contracts changed; prior WP02 stage evidence retained.",
"licence": "Complete locked closure and published cached metadata reviewed; existing source/native notices and provenance gates retained.",
"security": "Existing dependency-review and CodeQL gates remain required; no duplicated scanner or vulnerability-free assertion.",
"sbom": "Existing portable dependencies.json is generated from actual restore assets; no distributed closure changed.",
"localRuntime": "Not run: dependency policy tooling changes do not affect application runtime behavior.",
"compilation": "Workflow-only update: github/codeql-action init/analyze 4.38.0 -> 4.38.1 (Dependabot actions group). Required Windows/Linux compilation runs unchanged in CI.",
"aot": "No project, package or publish input changed; existing Windows x64/ARM64 and Linux x64 AOT publication jobs are unchanged.",
"compatibility": "Patch release within CodeQL action v4 with the same inputs and outputs; no package versions, APIs or generated contracts changed.",
"licence": "GitHub-owned action pinned to the immutable commit 1c5b675653bb5c22dbe9b12b556ec555138e09fd of annotated tag v4.38.1; no distributed closure or notice changed.",
"security": "Immutable SHA pin retained; CodeQL and dependency-review gates stay required; no vulnerability-absence claim.",
"sbom": "No restore closure change; the portable dependencies.json SBOM is unaffected.",
"localRuntime": "Not run: CI-only workflow action update; no application runtime behavior changed.",
"performance": "Not applicable: no runtime dependency, executable behavior or performance-sensitive algorithm changed.",
"migration": "Not applicable: no persistence format or storage dependency changed."
},
"inputs": {
".github/workflows/ci.yml": "72e49befc9213d9c02974853313cf19e0c8adb1642a44b5ba33b8b00de90c8c2",
".github/workflows/ci.yml": "4df50b97f6c50da7faed6609ef2789b412c78679f533d22168a25ad685ac18b7",
"Directory.Build.props": "3152c97565a3f41762fc224fb86cbe723849235ec4010c80bdc9a604d5fe3909",
"Directory.Build.targets": "178d0fc0bbc04d39c2b8c3df01ddcc81fc709d54f435606212625ab5ec58d99d",
"Directory.Packages.props": "ef826d5a6865882ae44e02c03a21e2d94e3146a2027a22bdbc6a558aac260321",
Expand Down
3 changes: 2 additions & 1 deletion eng/provenance/NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ ArcForges source provenance notices

Generated from reviewed active records. Original licence files and dependency notices remain authoritative.

arcnotes-provenance-tools-r4
arcnotes-provenance-tools-r5
Source: https://github.com/ArcForges/ArcNotes @ b7358bd7b1dca0671cd51cf6d798d5c09911b198
Material licence: AGPL-3.0-only
Notice scope: source
Expand All @@ -11,6 +11,7 @@ Original provenance checker from Contracts: Apache-2.0; complete source terms an
ArcSlate adapts product identity and future format/storage owner declarations.
ArcSlate owner modifications: reduce hosted CI to Windows/Linux compilation and offline checks; remove mandatory runtime evidence and redundant validation.
ArcSlate owner modifications: add reviewed dependency policy, upgrade records and offline negative fixtures adapted from ArcNotes b7358bd7b1dca0671cd51cf6d798d5c09911b198.
ArcSlate owner modifications: reviewed dependency updates are recorded in the owner dependency admission and review inputs.
Copyright ArcForges contributors. ArcSlate adapts ArcNotes dependency admission and retained support tooling under AGPL-3.0-only; original Apache checker attribution remains retained.

canonical-agpl-legal-r1
Expand Down
43 changes: 22 additions & 21 deletions eng/provenance/files.json
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@
"eng/provenance/records/arcnotes-provenance-tools-r2.json",
"eng/provenance/records/arcnotes-provenance-tools-r3.json",
"eng/provenance/records/arcnotes-provenance-tools-r4.json",
"eng/provenance/records/arcnotes-provenance-tools-r5.json",
"eng/provenance/records/canonical-agpl-legal-r1.json",
"eng/provenance/records/contracts-apache-legal-r1.json",
"eng/provenance/records/upstream-avalonia-legal-r1.json",
Expand All @@ -64,10 +65,10 @@
"third-party/sources.json"
],
"reused": {
"eng/ArcForges.Repository/ProvenancePolicy.cs": "arcnotes-provenance-tools-r4",
"eng/ArcForges.Repository/Program.cs": "arcnotes-provenance-tools-r4",
"tests/ArcForges.ArcSlate.Tests/ProvenancePolicyTests.cs": "arcnotes-provenance-tools-r4",
"tests/ArcForges.ArcSlate.Tests/CandidateTests.cs": "arcnotes-provenance-tools-r4",
"eng/ArcForges.Repository/ProvenancePolicy.cs": "arcnotes-provenance-tools-r5",
"eng/ArcForges.Repository/Program.cs": "arcnotes-provenance-tools-r5",
"tests/ArcForges.ArcSlate.Tests/ProvenancePolicyTests.cs": "arcnotes-provenance-tools-r5",
"tests/ArcForges.ArcSlate.Tests/CandidateTests.cs": "arcnotes-provenance-tools-r5",
"LICENSE": "canonical-agpl-legal-r1",
"eng/third-party/LICENSE.Contracts.txt": "contracts-apache-legal-r1",
"third-party/Avalonia.LICENSE.txt": "upstream-avalonia-legal-r1",
Expand All @@ -76,23 +77,23 @@
"third-party/MicroCom.LICENSE.txt": "upstream-microcom-legal-r1",
"third-party/Protobuf.LICENSE.txt": "upstream-protobuf-legal-r1",
"third-party/Tmds.DBus.LICENSE.txt": "upstream-tmds-dbus-legal-r1",
"eng/ArcForges.Repository/IdentityEvidence.cs": "arcnotes-provenance-tools-r4",
"src/ArcForges.ArcSlate.Core/BuildIdentity.cs": "arcnotes-provenance-tools-r4",
"tests/ArcForges.ArcSlate.Tests/BuildIdentityTests.cs": "arcnotes-provenance-tools-r4",
"Directory.Build.targets": "arcnotes-provenance-tools-r4",
"Directory.Build.props": "arcnotes-provenance-tools-r4",
"Directory.Packages.props": "arcnotes-provenance-tools-r4",
"eng/ArcForges.Repository/ArcForges.Repository.csproj": "arcnotes-provenance-tools-r4",
"src/ArcForges.ArcSlate/ArcForges.ArcSlate.csproj": "arcnotes-provenance-tools-r4",
"src/ArcForges.ArcSlate/Program.cs": "arcnotes-provenance-tools-r4",
"src/ArcForges.ArcSlate/LiveSmoke.cs": "arcnotes-provenance-tools-r4",
".github/workflows/ci.yml": "arcnotes-provenance-tools-r4",
"eng/version-sources.json": "arcnotes-provenance-tools-r4",
"eng/ArcForges.Repository/DependencyPolicy.cs": "arcnotes-provenance-tools-r4",
"docs/dependency-policy.md": "arcnotes-provenance-tools-r4",
"eng/policy/dependency-policy.json": "arcnotes-provenance-tools-r4",
"tests/ArcForges.ArcSlate.Tests/DependencyPolicyTests.cs": "arcnotes-provenance-tools-r4",
"eng/policy/dependency-review.json": "arcnotes-provenance-tools-r4"
"eng/ArcForges.Repository/IdentityEvidence.cs": "arcnotes-provenance-tools-r5",
"src/ArcForges.ArcSlate.Core/BuildIdentity.cs": "arcnotes-provenance-tools-r5",
"tests/ArcForges.ArcSlate.Tests/BuildIdentityTests.cs": "arcnotes-provenance-tools-r5",
"Directory.Build.targets": "arcnotes-provenance-tools-r5",
"Directory.Build.props": "arcnotes-provenance-tools-r5",
"Directory.Packages.props": "arcnotes-provenance-tools-r5",
"eng/ArcForges.Repository/ArcForges.Repository.csproj": "arcnotes-provenance-tools-r5",
"src/ArcForges.ArcSlate/ArcForges.ArcSlate.csproj": "arcnotes-provenance-tools-r5",
"src/ArcForges.ArcSlate/Program.cs": "arcnotes-provenance-tools-r5",
"src/ArcForges.ArcSlate/LiveSmoke.cs": "arcnotes-provenance-tools-r5",
".github/workflows/ci.yml": "arcnotes-provenance-tools-r5",
"eng/version-sources.json": "arcnotes-provenance-tools-r5",
"eng/ArcForges.Repository/DependencyPolicy.cs": "arcnotes-provenance-tools-r5",
"docs/dependency-policy.md": "arcnotes-provenance-tools-r5",
"eng/policy/dependency-policy.json": "arcnotes-provenance-tools-r5",
"tests/ArcForges.ArcSlate.Tests/DependencyPolicyTests.cs": "arcnotes-provenance-tools-r5",
"eng/policy/dependency-review.json": "arcnotes-provenance-tools-r5"
},
"artifacts": []
}
Loading
Loading