Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/provenance.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ exports, exact bundle hash, installed package versions/integrities, both Docker
image pins, Native AOT source/configuration/lock inputs and applicable full legal
texts. Unknown or changed material requires a newly reviewed profile and record.

Cloud's own type checker is **TypeScript 7.0.2**, with **Wrangler 4.132.0**.
Cloud's own type checker is **TypeScript 7.0.2**, with **Wrangler 4.135.0**.
The historical **TypeScript 6.0.3** identity in the Containers provenance record
describes the compiler used by upstream `@cloudflare/containers@0.3.7`. It was used
only to reproduce that package's four published JavaScript files exactly. It is
Expand Down
8 changes: 4 additions & 4 deletions eng/provenance/NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,13 @@ https://github.com/github/choosealicense.com @ 58267f8f2c5c0099810849cfd7677f52a
AGPL-3.0-only
GNU Affero General Public License version 3; Copyright Free Software Foundation, Inc. Complete original licence and its verbatim-copying permission are retained.

cloud-runtime-notices-r10
https://github.com/ArcForges/Cloud @ 3ccb15362196cbe9009998ab876317ed355ef762
cloud-runtime-notices-r11
https://github.com/ArcForges/Cloud @ 3b51ed444b6ebbe7fa7797363b01b4c38d87f627
AGPL-3.0-only
ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.

cloud-worker-bundle-r9
https://github.com/ArcForges/Cloud @ 3ccb15362196cbe9009998ab876317ed355ef762
cloud-worker-bundle-r10
https://github.com/ArcForges/Cloud @ 3b51ed444b6ebbe7fa7797363b01b4c38d87f627
AGPL-3.0-only
Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle.

Expand Down
90 changes: 90 additions & 0 deletions eng/provenance/artifact-profiles/cloud-release-r10.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
{
"schemaVersion": 1,
"id": "cloud-release-r10",
"ownerCommit": "3b51ed444b6ebbe7fa7797363b01b4c38d87f627",
"worker": {
"sha256": "a386a9f90d50f2b297f22e78c460f47e29f4005ec4313980348e4c53b82764e4",
"inputs": {
"node_modules/@cloudflare/containers/dist/lib/helpers.js": "320eae245a1d05a64c8348652f6808fa54c776340bd7c24391c19fe3b9e0f05f",
"node_modules/@cloudflare/containers/dist/lib/container.js": "9dfc5feaa43b2bdec08863c85eb94731237aeb9f19c7b7e58ff426776ec8863c",
"node_modules/@cloudflare/containers/dist/lib/utils.js": "22f96e63b873b10081fc15216bffc8d23a4614516efcb64be99db87372d4011c",
"node_modules/@cloudflare/containers/dist/index.js": "4788f78cbab43389d23feb71c8ef4e6657c01f9eeffe962650310784390bd486",
"worker/router.ts": "8e6fbb57855f0987cdf95dea492ce66184825cc2f5ae127865ff7988f8b57af3",
"worker/index.ts": "5317c8257a4ffcd4e023b08981cf8861d10092984a2664852b0eb55d2f34e50d"
},
"outputInputs": [
"node_modules/@cloudflare/containers/dist/index.js",
"node_modules/@cloudflare/containers/dist/lib/container.js",
"node_modules/@cloudflare/containers/dist/lib/helpers.js",
"worker/index.ts",
"worker/router.ts"
],
"externalImports": [
"cloudflare:workers"
],
"exports": [
"CloudContainer",
"default"
],
"packages": {
"@cloudflare/containers": {
"version": "0.3.7",
"integrity": "sha512-DM9dm3FnIBSyiSJ1FLavKwl/lk3oAmTaynCzZQ9pZR0ncRPquSxkxd8Nu2MFILxmDDsPkxKsSNEh9mHHMty4Fw=="
},
"wrangler": {
"version": "4.135.0",
"integrity": "sha512-WrNBQSfIG6YcILJcodYr5ty8vgkzGsV8YX+kfd+uZ5/Bd8cUW0GnUIRKAVfn5kYKqh1m/BPcji9h1d7mE8euFw=="
},
"esbuild": {
"version": "0.28.1",
"integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw=="
}
},
"legalFiles": [
"LICENSE",
"NOTICE",
"eng/provenance/NOTICE.txt",
"third-party/Containers.LICENSE.txt",
"third-party/Esbuild.LICENSE.txt"
]
},
"image": {
"baseImage": "mcr.microsoft.com/dotnet/runtime-deps:10.0.12-noble-chiseled@sha256:18d4848091a40d13dbfdd6a8340c1657dc3e2f2d7fa2f042e9d162e68669dbc9",
"baseLegal": {
"/usr/share/doc/base-files/copyright": "fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23",
"/usr/share/doc/ca-certificates/copyright": "e85e1bcad3a915dc7e6f41412bc5bdeba275cadd817896ea0451f2140a93967c",
"/usr/share/doc/gcc-14-base/copyright": "20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79",
"/usr/share/doc/libc6/copyright": "d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265",
"/usr/share/doc/libssl3t64/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35",
"/usr/share/doc/openssl/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35"
},
"legalFiles": [
"LICENSE",
"NOTICE",
"eng/provenance/NOTICE.txt",
"third-party/DotNet.AspNetCore.NOTICES.txt",
"third-party/DotNet.LICENSE.txt",
"third-party/DotNet.Runtime.NOTICES.txt",
"third-party/Grpc.LICENSE.txt",
"third-party/Protobuf.LICENSE.txt"
],
"inputs": {
"Directory.Build.props": "594fe799ea787c02d4406e14360c4b1902a5aee8679b76c8ac797ae34a9e792c",
"Directory.Build.targets": "fa4bf35487140fecd21b71a2fb524792631a292df2313f9440f8c6e7e90a82d2",
"Directory.Packages.props": "bd428b5fd151458ac4ae0a8914dfe7a6ff34f6741b3b75c2a57e123e2d0f31bb",
"NuGet.Config": "cb93c65e28718aa9075fce221e9f9cea9e72d3fe1b30462383448a591f5b3aa1",
"global.json": "67381be18aa807c04218165844967cf58235875477f30495ba98c3648248a9d4",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj": "d2b84581970f81643c43207cb1e24557cd44abb7867e2ddfca6c18b6ed5c7851",
"src/ArcForges.Cloud/HealthStatus.cs": "984e22e7e2473e186e39e9db156b3c1b1275dd32af5d64e5591438785438739b",
"src/ArcForges.Cloud/HelloEndpoint.cs": "15ed003e7867e8131a8fa32ae74ffe2b6347f970d8ca679e0e538409aeb76598",
"src/ArcForges.Cloud/Program.cs": "5591a3562e67d399234b4ccd74e2f72e46dcff141e08f43c26dc87448ace534c",
"src/ArcForges.Cloud/packages.lock.json": "d37f1d76d1793d3b91d09acffdf305bec34f1e57246e84e9e9c72dd5f606e04c",
"Dockerfile": "cbe3e60d8b49be36901370e80b5171832642dd30680af83356431910edb07537",
".dockerignore": "1bbebcf664aad8b96ed8e57799f555ea44ff8a99e526bf8eee0111a8ec1444ae",
"eng/version-sources.json": "9a848f211b5b64ce5b75ff398e991e16adc5f20fa716c5b46ccc71ddab210766",
"package-lock.json": "8c9d53354ece1773470de50caa37393aa92e56a9c0610681093fddba72576358",
"src/ArcForges.Cloud/BuildIdentity.cs": "203f8d8fd30df0cfd1bf9ea68fb38ffa48403aa5c653bb09db29e5d752976e85"
},
"buildImage": "mcr.microsoft.com/dotnet/sdk:10.0.401-noble-aot@sha256:96f3b7d45f53eb05990f05b89ce61c4e23d07a5098521c2f20b018630e34f298"
}
}
5 changes: 4 additions & 1 deletion eng/provenance/files.json
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@
"eng/policy/reuse-policy.json",
"eng/provenance/NOTICE.txt",
"eng/provenance/artifact-profiles/cloud-release-r1.json",
"eng/provenance/artifact-profiles/cloud-release-r10.json",
"eng/provenance/artifact-profiles/cloud-release-r2.json",
"eng/provenance/artifact-profiles/cloud-release-r3.json",
"eng/provenance/artifact-profiles/cloud-release-r4.json",
Expand All @@ -57,6 +58,7 @@
"eng/provenance/records/canonical-agpl-legal-r1.json",
"eng/provenance/records/cloud-runtime-notices-r1.json",
"eng/provenance/records/cloud-runtime-notices-r10.json",
"eng/provenance/records/cloud-runtime-notices-r11.json",
"eng/provenance/records/cloud-runtime-notices-r2.json",
"eng/provenance/records/cloud-runtime-notices-r3.json",
"eng/provenance/records/cloud-runtime-notices-r4.json",
Expand All @@ -66,6 +68,7 @@
"eng/provenance/records/cloud-runtime-notices-r8.json",
"eng/provenance/records/cloud-runtime-notices-r9.json",
"eng/provenance/records/cloud-worker-bundle-r1.json",
"eng/provenance/records/cloud-worker-bundle-r10.json",
"eng/provenance/records/cloud-worker-bundle-r2.json",
"eng/provenance/records/cloud-worker-bundle-r3.json",
"eng/provenance/records/cloud-worker-bundle-r4.json",
Expand Down Expand Up @@ -146,5 +149,5 @@
"eng/version-sources.json": "arcnotes-build-identity-r1",
"tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1"
},
"artifacts": ["cloud-runtime-notices-r10", "cloud-worker-bundle-r9"]
"artifacts": ["cloud-runtime-notices-r11", "cloud-worker-bundle-r10"]
}
221 changes: 221 additions & 0 deletions eng/provenance/records/cloud-runtime-notices-r11.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,221 @@
{
"schemaVersion": 1,
"id": "cloud-runtime-notices-r11",
"kind": "generated",
"sourceRepository": "https://github.com/ArcForges/Cloud",
"sourceCommit": "3b51ed444b6ebbe7fa7797363b01b4c38d87f627",
"sourcePaths": [
"Directory.Build.props",
"Directory.Build.targets",
"Directory.Packages.props",
"NuGet.Config",
"global.json",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"src/ArcForges.Cloud/HealthStatus.cs",
"src/ArcForges.Cloud/HelloEndpoint.cs",
"src/ArcForges.Cloud/Program.cs",
"src/ArcForges.Cloud/packages.lock.json",
"Dockerfile",
".dockerignore",
"eng/version-sources.json",
"package-lock.json",
"src/ArcForges.Cloud/BuildIdentity.cs"
],
"licence": {
"spdx": "AGPL-3.0-only",
"category": "agpl-compatible",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile."
}
],
"scope": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image.",
"copyingPermission": null
},
"attribution": [
"ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files."
],
"targets": [],
"artifactTargets": [
{
"project": "src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"package": "arcforges-cloud-container",
"kind": "native-image-notices",
"profile": "eng/provenance/artifact-profiles/cloud-release-r10.json",
"sha256": "64d42894d16c07d90086a8e5b52ea046b4fc1d8b436e0c41867ffb84c2f1f8f8"
}
],
"disposition": "Copy",
"verification": {
"kind": "actual-image",
"command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.",
"expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.",
"artifacts": []
},
"notice": {
"required": true,
"text": "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.",
"files": [
"eng/provenance/NOTICE.txt"
],
"distribution": "source-and-applicable-artifacts",
"reason": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image."
},
"lifetime": {
"status": "permanent",
"owner": "Cloud Licensing and Provenance Owner",
"removalTrigger": null
},
"generation": {
"generators": [
{
"repository": "https://github.com/dotnet/dotnet",
"commit": "95017c711e6afc1085133d440e42b4bd78155701",
"paths": [
"src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs"
],
"spdx": "MIT",
"evidence": [
{
"path": "LICENSE.TXT",
"sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b",
"finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term."
},
{
"path": "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs",
"sha256": "fdd1e2c6cb47d67b7f920a449d155434f8ad07a5779a574e9fcb1f52a5db37b6",
"finding": "Exact ILCompiler entry point independently fetched at the locked .NET commit. Its own file header explicitly grants MIT. Compiler implementation is a generator, not copied runtime application source."
}
]
}
],
"inputs": [
{
"repository": "https://github.com/ArcForges/Cloud",
"commit": "3b51ed444b6ebbe7fa7797363b01b4c38d87f627",
"paths": [
"Directory.Build.props",
"Directory.Build.targets",
"Directory.Packages.props",
"NuGet.Config",
"global.json",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"src/ArcForges.Cloud/HealthStatus.cs",
"src/ArcForges.Cloud/HelloEndpoint.cs",
"src/ArcForges.Cloud/Program.cs",
"src/ArcForges.Cloud/packages.lock.json",
"Dockerfile",
".dockerignore",
"eng/version-sources.json",
"package-lock.json",
"src/ArcForges.Cloud/BuildIdentity.cs"
],
"spdx": "AGPL-3.0-only",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile."
}
]
},
{
"repository": "https://github.com/grpc/grpc-dotnet",
"commit": "4c6997a214601422dd66c5c74c1969db749479e9",
"paths": [
"LICENSE"
],
"spdx": "Apache-2.0",
"evidence": [
{
"path": "LICENSE",
"sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
"finding": "The restored Grpc 2.84.0 NuGet packages identify this official release source commit. Its complete Apache-2.0 LICENSE matches the retained full legal text."
}
]
},
{
"repository": "https://github.com/protocolbuffers/protobuf",
"commit": "f377bfefc5e2cfab68b816903c25b23e091c439d",
"paths": [
"LICENSE"
],
"spdx": "BSD-3-Clause",
"evidence": [
{
"path": "LICENSE",
"sha256": "6e5e117324afd944dcf67f36cf329843bc1a92229a8cd9bb573d7a83130fea7d",
"finding": "Exact source commit is recorded by Google.Protobuf 3.36.1; this is the full upstream licence."
}
]
},
{
"repository": "https://github.com/ArcForges/Contracts",
"commit": "d77aefabe0676dbe32845cbcf50aee361eb3fe7e",
"paths": [
"LICENSE"
],
"spdx": "Apache-2.0",
"evidence": [
{
"path": "LICENSE",
"sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
"finding": "NuGet 1.0.0-ci.36.1 binds this producer source; standard Apache legal text is identical and retained in full."
}
]
},
{
"repository": "https://github.com/dotnet/dotnet",
"commit": "95017c711e6afc1085133d440e42b4bd78155701",
"paths": [
"LICENSE.TXT",
"src/runtime/THIRD-PARTY-NOTICES.TXT",
"src/aspnetcore/THIRD-PARTY-NOTICES.txt"
],
"spdx": "MIT",
"evidence": [
{
"path": "LICENSE.TXT",
"sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b",
"finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term."
},
{
"path": "src/runtime/THIRD-PARTY-NOTICES.TXT",
"sha256": "66f1d4e44973185519bb4aa8a9718eb22fc7af2cc532e3ae9cfc4c127ee7fc54",
"finding": "Full original legal document. This record permits required unmodified notice reproduction only; it does not relicense listed components or admit their implementation."
}
]
},
{
"repository": "https://github.com/ArcForges/ArcNotes",
"commit": "0c797e30690a10d8798ddca19ca7f37b16cecf01",
"paths": [
"src/ArcForges.ArcNotes.Core/BuildIdentity.cs",
"eng/version-sources.json"
],
"spdx": "AGPL-3.0-only",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Complete AGPL terms retained; owner-specific adaptation and exact targets are reviewed in arcnotes-build-identity-r1."
}
]
}
],
"command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.",
"outputSpdx": "AGPL-3.0-only"
},
"review": {
"owner": "Licensing and Provenance Owner",
"reviewer": "Codex, acting under the maintainer's implementation/review authorization",
"reviewedOn": "2026-09-21",
"decision": "approved",
"rationale": "PR11 updates Wrangler 4.132.0 to 4.135.0 and workers-types to 5.20260918.1 while retaining the already merged Biome/Prettier patches. Official workers-sdk source f9e7727dbef58e71c6b297dc688d3c544cef87cb leaves the standard deployment bundler and MIT grant unchanged; the only deployment-bundle directory change is unused experimental build-output preview handling. Containers 0.3.7 inputs and esbuild 0.28.1 remain exact. The expected Worker bytes are inherited unchanged from the independently reviewed predecessor, never learned from this candidate. The profile updates only the embedded npm lock and Wrangler package identity. Native dependencies, Docker pins and full legal documents are unchanged. Dry-run compilation and retained static/offline checks apply under P2-017.",
"baselineCommit": "561f5fbf274c16ccca1d6537b89c25d3d0dc4eae",
"reconciliation": false
},
"supersedes": "cloud-runtime-notices-r10"
}
Loading
Loading