Align NuGet and npm Contracts at 1.0.0-ci.74.1 - #12
Conversation
6e90ab2 to
c8416dd
Compare
Bumps the contracts group with 1 update in the / directory: [@arcforges/api-client](https://github.com/ArcForges/Contracts/tree/HEAD/src/public/ts/api-client). Updates `@arcforges/api-client` from 1.0.0-ci.36.1 to 1.0.0-ci.44.1 - [Commits](https://github.com/ArcForges/Contracts/commits/HEAD/src/public/ts/api-client) --- updated-dependencies: - dependency-name: "@arcforges/api-client" dependency-version: 1.0.0-ci.42.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: contracts ... Signed-off-by: dependabot[bot] <support@github.com>
c8416dd to
df95c06
Compare
deku2026
left a comment
There was a problem hiding this comment.
Full review passed at df95c06. Actual restored NuGet/npm74.1 receipts agree on clean producer9f0e90f and unchanged Hello v1 descriptor; Kotlin remains42.1 with compatible schema. All three NuGet locks and npm graph are resolver-generated; shared-producer guard remains. Immutable profile only admits reviewed declaration/lock changes, preserving Worker/native expectations and legal text. .NET build/all16 tests and full npm static/all63 offline tests passed. This carries bot-closed17 original target. Final CI and independent cross-review are still required before merge.
deku2026
left a comment
There was a problem hiding this comment.
Final review passed at 3305d61, including an independent full-diff review. NuGet/npm74.1 producer identity and all locks align; Kotlin remains independently pinned42.1 with the same schema. The review finding is fixed: complete published NuGet NOTICE is retained through a narrow legal-document record and included in the image legal file list. No changes to runtime, validators, Worker inputs or expected bytes. Local compilation/offline tests and focused legal staging checks passed. Merge remains conditional on all applicable latest-head CI passing.
Aligns
ArcForges.Contracts.PublicApiand@arcforges/api-clientat1.0.0-ci.74.1. Cloud derives its server identity from both published receipts, so updating either alone fails the existing shared-producer guard. The three NuGet locks and npm lock are regenerated through normal restores. Kotlin stays independently pinned at1.0.0-ci.42.1.The actual NuGet/npm packages contain identical clean source receipts at
9f0e90f65d57f405fcee311d467a57a255dfd644; the Hello v1 descriptor matches the previous packages and Kotlin client. Immutable release profile r11 binds the central declaration, host lock and embedded npm lock changes. Worker code/generators/output, Docker pins and other native dependencies remain unchanged.Independent review identified newly added generator attributions and protobuf BSD terms in the published NuGet NOTICE. The complete package NOTICE is now retained verbatim through a narrow legal-document record. Successor profile r12 adds that document to the image legal files; the existing packaging path carries it into the Native AOT image and release legal bundle. Previous profiles are preserved, and the Worker-specific legal file list and validators are unchanged.
This PR also completes the original NuGet target from #17, which Dependabot closed and whose remote branch it deleted. Its original local branch and worktree are retained.
Validation: actual npm/NuGet restores passed with zero npm vulnerabilities; .NET Release build had zero warnings/errors and all 16 offline tests passed. Full npm check passed toolchain, licence/provenance, formatting, lint, both TypeScript projects and all 63 offline tests. The NOTICE fix additionally passed source/licence checks and pure-file assertions that the complete published text appears in the source, legal bundle and staged image. Final-head retained CI and full independent review are required before merge; the preceding #14 main deployment is already green.