From 1ac816c412797f68198ad65c5c76a106008a790f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 22 Sep 2026 00:06:57 +0000 Subject: [PATCH 1/5] Bump @arcforges/api-client in the contracts group across 1 directory Bumps the contracts group with 1 update in the / directory: [@arcforges/api-client](https://github.com/ArcForges/Contracts/tree/HEAD/src/public/ts/api-client). Updates `@arcforges/api-client` from 1.0.0-ci.36.1 to 1.0.0-ci.44.1 - [Commits](https://github.com/ArcForges/Contracts/commits/HEAD/src/public/ts/api-client) --- updated-dependencies: - dependency-name: "@arcforges/api-client" dependency-version: 1.0.0-ci.42.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: contracts ... Signed-off-by: dependabot[bot] --- package-lock.json | 16 ++++++++-------- package.json | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/package-lock.json b/package-lock.json index 545f64d..a133804 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,7 +12,7 @@ "@cloudflare/containers": "0.3.7" }, "devDependencies": { - "@arcforges/api-client": "1.0.0-ci.36.1", + "@arcforges/api-client": "1.0.0-ci.44.1", "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260918.1", "@connectrpc/connect": "2.2.0", @@ -27,22 +27,22 @@ } }, "node_modules/@arcforges/api-client": { - "version": "1.0.0-ci.36.1", - "resolved": "https://registry.npmjs.org/@arcforges/api-client/-/api-client-1.0.0-ci.36.1.tgz", - "integrity": "sha512-zG+Or/D7FqJsaFZJ0yx0iSMmocLDaPrJpyAjoG33TdmjE1/AzSDgT84YwfTP8kNWdYgGEtJnuxTyUa6yocVnKA==", + "version": "1.0.0-ci.44.1", + "resolved": "https://registry.npmjs.org/@arcforges/api-client/-/api-client-1.0.0-ci.44.1.tgz", + "integrity": "sha512-/gZCOQTsllSxRczGW75/ZMhww5mVdW/PMVxJ8/M75JF2gC7ZzEZhDmJqYW0r5yaSbQ4cMqe+zhkM8f9rA3DklQ==", "dev": true, "license": "Apache-2.0", "dependencies": { - "@arcforges/proto": "1.0.0-ci.36.1", + "@arcforges/proto": "1.0.0-ci.44.1", "@bufbuild/protobuf": "2.15.0", "@connectrpc/connect": "2.2.0", "@connectrpc/connect-web": "2.2.0" } }, "node_modules/@arcforges/proto": { - "version": "1.0.0-ci.36.1", - "resolved": "https://registry.npmjs.org/@arcforges/proto/-/proto-1.0.0-ci.36.1.tgz", - "integrity": "sha512-mEne+YlrNtB5ZtqOA3AVu0nqdTR688ZeiwUuKutLbCvkuGOIbd8xmxxsEYrFAXEZXZlNdRn7X0Cg9SW3xc49mw==", + "version": "1.0.0-ci.44.1", + "resolved": "https://registry.npmjs.org/@arcforges/proto/-/proto-1.0.0-ci.44.1.tgz", + "integrity": "sha512-GJc6x7TRFT1N9H7mlKAPf2+p+55arUOLaaGR+2AdzrRvJ3AnCAM8a7pG8C3CN+KiaXYVFkUKtyKZl9SivJC4Lw==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index 76c2074..3ac1b6b 100644 --- a/package.json +++ b/package.json @@ -38,7 +38,7 @@ "@cloudflare/containers": "0.3.7" }, "devDependencies": { - "@arcforges/api-client": "1.0.0-ci.36.1", + "@arcforges/api-client": "1.0.0-ci.44.1", "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260918.1", "@connectrpc/connect": "2.2.0", From 38c7be9090af5322937ed287f259de4725b7d549 Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 17:20:01 -0700 Subject: [PATCH 2/5] Align NuGet and npm Contracts on the original 74.1 producer --- Directory.Packages.props | 2 +- NOTICE | 2 +- docs/development.md | 2 +- package-lock.json | 16 ++++++++-------- package.json | 2 +- src/ArcForges.Cloud/packages.lock.json | 6 +++--- .../ArcForges.Cloud.Consumer/packages.lock.json | 6 +++--- tests/ArcForges.Cloud.Tests/packages.lock.json | 8 ++++---- 8 files changed, 22 insertions(+), 22 deletions(-) diff --git a/Directory.Packages.props b/Directory.Packages.props index 484fcd9..2f89894 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -5,7 +5,7 @@ - + diff --git a/NOTICE b/NOTICE index 8248d47..dc865aa 100644 --- a/NOTICE +++ b/NOTICE @@ -3,7 +3,7 @@ Copyright ArcForges contributors Original Cloud application and tooling: AGPL-3.0-only; see LICENSE. Contracts APIs are consumed as published Apache-2.0 packages from -https://github.com/ArcForges/Contracts (C#/TypeScript version 1.0.0-ci.36.1; +https://github.com/ArcForges/Contracts (C#/TypeScript version 1.0.0-ci.74.1; Kotlin verification client version 1.0.0-ci.42.1). The standard generated Gradle wrapper scripts and JAR are distributed under diff --git a/docs/development.md b/docs/development.md index 1defd37..a387d94 100644 --- a/docs/development.md +++ b/docs/development.md @@ -22,7 +22,7 @@ npm run check:kotlin npm run candidate ``` -Install JDK 17 and set `JAVA_HOME` before `check:kotlin`. The verification project uses Kotlin 2.4.20, JVM 17 bytecode and the checksum-pinned Gradle 9.7.1 wrapper. This does not change Mobile's toolchain. Maven Central is the only dependency repository for the application; strict locks and verification metadata are committed. C# and TypeScript consume Contracts `1.0.0-ci.36.1`; the Kotlin verification client independently pins `1.0.0-ci.42.1`. Package build numbers may differ while the declared Hello v1 schema and descriptor remain compatible. +Install JDK 17 and set `JAVA_HOME` before `check:kotlin`. The verification project uses Kotlin 2.4.20, JVM 17 bytecode and the checksum-pinned Gradle 9.7.1 wrapper. This does not change Mobile's toolchain. Maven Central is the only dependency repository for the application; strict locks and verification metadata are committed. C# and TypeScript consume Contracts `1.0.0-ci.74.1`; the Kotlin verification client independently pins `1.0.0-ci.42.1`. Package build numbers may differ while the declared Hello v1 schema and descriptor remain compatible. `check:kotlin` compiles the consumer and prepares its distribution without executing it. The loopback deadline fixture is available only as an explicit local `deadlineTest` Gradle task and rejects CI. `candidate` builds the Linux Native AOT image, inspects its declared user/entry point/source label and extracts licence/provenance files from a stopped container. It never launches the application, restarts a service or runs RPC consumers. The build identity companion comes from the same independently resolved inputs supplied to compilation; it is not claimed as a runtime observation. diff --git a/package-lock.json b/package-lock.json index a133804..c0e1b2f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -12,7 +12,7 @@ "@cloudflare/containers": "0.3.7" }, "devDependencies": { - "@arcforges/api-client": "1.0.0-ci.44.1", + "@arcforges/api-client": "1.0.0-ci.74.1", "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260918.1", "@connectrpc/connect": "2.2.0", @@ -27,22 +27,22 @@ } }, "node_modules/@arcforges/api-client": { - "version": "1.0.0-ci.44.1", - "resolved": "https://registry.npmjs.org/@arcforges/api-client/-/api-client-1.0.0-ci.44.1.tgz", - "integrity": "sha512-/gZCOQTsllSxRczGW75/ZMhww5mVdW/PMVxJ8/M75JF2gC7ZzEZhDmJqYW0r5yaSbQ4cMqe+zhkM8f9rA3DklQ==", + "version": "1.0.0-ci.74.1", + "resolved": "https://registry.npmjs.org/@arcforges/api-client/-/api-client-1.0.0-ci.74.1.tgz", + "integrity": "sha512-G2Gri9QnBPKcVdkOtMpFBS/nYgQ0Ug4xrest5auUxcLZXRRXbq9Q7ueQNeGtmWgDjhA54QZT/R7SMfRinm0g1A==", "dev": true, "license": "Apache-2.0", "dependencies": { - "@arcforges/proto": "1.0.0-ci.44.1", + "@arcforges/proto": "1.0.0-ci.74.1", "@bufbuild/protobuf": "2.15.0", "@connectrpc/connect": "2.2.0", "@connectrpc/connect-web": "2.2.0" } }, "node_modules/@arcforges/proto": { - "version": "1.0.0-ci.44.1", - "resolved": "https://registry.npmjs.org/@arcforges/proto/-/proto-1.0.0-ci.44.1.tgz", - "integrity": "sha512-GJc6x7TRFT1N9H7mlKAPf2+p+55arUOLaaGR+2AdzrRvJ3AnCAM8a7pG8C3CN+KiaXYVFkUKtyKZl9SivJC4Lw==", + "version": "1.0.0-ci.74.1", + "resolved": "https://registry.npmjs.org/@arcforges/proto/-/proto-1.0.0-ci.74.1.tgz", + "integrity": "sha512-tjGTLa/mCfY7d2kMrnJhGZ7nLgONPb7rM+OSrM68kfeseKEjp/fUPkEASjYq+VKYbh9drZsXVQo1kLw1Ejl09Q==", "dev": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index 3ac1b6b..e65a067 100644 --- a/package.json +++ b/package.json @@ -38,7 +38,7 @@ "@cloudflare/containers": "0.3.7" }, "devDependencies": { - "@arcforges/api-client": "1.0.0-ci.44.1", + "@arcforges/api-client": "1.0.0-ci.74.1", "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260918.1", "@connectrpc/connect": "2.2.0", diff --git a/src/ArcForges.Cloud/packages.lock.json b/src/ArcForges.Cloud/packages.lock.json index 3527500..1c120a5 100644 --- a/src/ArcForges.Cloud/packages.lock.json +++ b/src/ArcForges.Cloud/packages.lock.json @@ -10,9 +10,9 @@ }, "ArcForges.Contracts.PublicApi": { "type": "Direct", - "requested": "[1.0.0-ci.36.1, )", - "resolved": "1.0.0-ci.36.1", - "contentHash": "4+pUDeDcOScTV5rEei5yri8CLvVb9309Zdl5TBcVKXBvFrowcOoPx5pkZmpqzcLQZAZ2LH6LVv8JCGURpf42zQ==", + "requested": "[1.0.0-ci.74.1, )", + "resolved": "1.0.0-ci.74.1", + "contentHash": "36NPDQqRDJLAMDF8alGsztpcEWyMcW+omWMZ05Vt3GsdhdkxgCCyxTWNOYCdmK8s5KGVhD9PiMBYX9XE+USwsA==", "dependencies": { "Google.Protobuf": "3.36.1", "Grpc.Core.Api": "2.83.0" diff --git a/tests/ArcForges.Cloud.Consumer/packages.lock.json b/tests/ArcForges.Cloud.Consumer/packages.lock.json index 74e739d..769c30d 100644 --- a/tests/ArcForges.Cloud.Consumer/packages.lock.json +++ b/tests/ArcForges.Cloud.Consumer/packages.lock.json @@ -10,9 +10,9 @@ }, "ArcForges.Contracts.PublicApi": { "type": "Direct", - "requested": "[1.0.0-ci.36.1, )", - "resolved": "1.0.0-ci.36.1", - "contentHash": "4+pUDeDcOScTV5rEei5yri8CLvVb9309Zdl5TBcVKXBvFrowcOoPx5pkZmpqzcLQZAZ2LH6LVv8JCGURpf42zQ==", + "requested": "[1.0.0-ci.74.1, )", + "resolved": "1.0.0-ci.74.1", + "contentHash": "36NPDQqRDJLAMDF8alGsztpcEWyMcW+omWMZ05Vt3GsdhdkxgCCyxTWNOYCdmK8s5KGVhD9PiMBYX9XE+USwsA==", "dependencies": { "Google.Protobuf": "3.36.1", "Grpc.Core.Api": "2.83.0" diff --git a/tests/ArcForges.Cloud.Tests/packages.lock.json b/tests/ArcForges.Cloud.Tests/packages.lock.json index 676dd1e..50db326 100644 --- a/tests/ArcForges.Cloud.Tests/packages.lock.json +++ b/tests/ArcForges.Cloud.Tests/packages.lock.json @@ -293,16 +293,16 @@ "arcforges.cloud": { "type": "Project", "dependencies": { - "ArcForges.Contracts.PublicApi": "[1.0.0-ci.36.1, )", + "ArcForges.Contracts.PublicApi": "[1.0.0-ci.74.1, )", "Grpc.AspNetCore": "[2.84.0, )", "Grpc.AspNetCore.Web": "[2.84.0, )" } }, "ArcForges.Contracts.PublicApi": { "type": "CentralTransitive", - "requested": "[1.0.0-ci.36.1, )", - "resolved": "1.0.0-ci.36.1", - "contentHash": "4+pUDeDcOScTV5rEei5yri8CLvVb9309Zdl5TBcVKXBvFrowcOoPx5pkZmpqzcLQZAZ2LH6LVv8JCGURpf42zQ==", + "requested": "[1.0.0-ci.74.1, )", + "resolved": "1.0.0-ci.74.1", + "contentHash": "36NPDQqRDJLAMDF8alGsztpcEWyMcW+omWMZ05Vt3GsdhdkxgCCyxTWNOYCdmK8s5KGVhD9PiMBYX9XE+USwsA==", "dependencies": { "Google.Protobuf": "3.36.1", "Grpc.Core.Api": "2.83.0" From df95c062f5dae56bae8cf126385dcff0ec993a22 Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 17:21:19 -0700 Subject: [PATCH 3/5] Bind coherent Contracts producer and dependency locks in provenance --- eng/provenance/NOTICE.txt | 8 +- .../artifact-profiles/cloud-release-r11.json | 90 +++++++ eng/provenance/files.json | 5 +- .../records/cloud-runtime-notices-r12.json | 221 ++++++++++++++++++ .../records/cloud-worker-bundle-r11.json | 155 ++++++++++++ 5 files changed, 474 insertions(+), 5 deletions(-) create mode 100644 eng/provenance/artifact-profiles/cloud-release-r11.json create mode 100644 eng/provenance/records/cloud-runtime-notices-r12.json create mode 100644 eng/provenance/records/cloud-worker-bundle-r11.json diff --git a/eng/provenance/NOTICE.txt b/eng/provenance/NOTICE.txt index 8fbe831..7f5b709 100644 --- a/eng/provenance/NOTICE.txt +++ b/eng/provenance/NOTICE.txt @@ -12,13 +12,13 @@ https://github.com/github/choosealicense.com @ 58267f8f2c5c0099810849cfd7677f52a AGPL-3.0-only GNU Affero General Public License version 3; Copyright Free Software Foundation, Inc. Complete original licence and its verbatim-copying permission are retained. -cloud-runtime-notices-r11 -https://github.com/ArcForges/Cloud @ 3b51ed444b6ebbe7fa7797363b01b4c38d87f627 +cloud-runtime-notices-r12 +https://github.com/ArcForges/Cloud @ 38c7be9090af5322937ed287f259de4725b7d549 AGPL-3.0-only ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. -cloud-worker-bundle-r10 -https://github.com/ArcForges/Cloud @ 3b51ed444b6ebbe7fa7797363b01b4c38d87f627 +cloud-worker-bundle-r11 +https://github.com/ArcForges/Cloud @ 38c7be9090af5322937ed287f259de4725b7d549 AGPL-3.0-only Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle. diff --git a/eng/provenance/artifact-profiles/cloud-release-r11.json b/eng/provenance/artifact-profiles/cloud-release-r11.json new file mode 100644 index 0000000..5c13842 --- /dev/null +++ b/eng/provenance/artifact-profiles/cloud-release-r11.json @@ -0,0 +1,90 @@ +{ + "schemaVersion": 1, + "id": "cloud-release-r11", + "ownerCommit": "38c7be9090af5322937ed287f259de4725b7d549", + "worker": { + "sha256": "a386a9f90d50f2b297f22e78c460f47e29f4005ec4313980348e4c53b82764e4", + "inputs": { + "node_modules/@cloudflare/containers/dist/lib/helpers.js": "320eae245a1d05a64c8348652f6808fa54c776340bd7c24391c19fe3b9e0f05f", + "node_modules/@cloudflare/containers/dist/lib/container.js": "9dfc5feaa43b2bdec08863c85eb94731237aeb9f19c7b7e58ff426776ec8863c", + "node_modules/@cloudflare/containers/dist/lib/utils.js": "22f96e63b873b10081fc15216bffc8d23a4614516efcb64be99db87372d4011c", + "node_modules/@cloudflare/containers/dist/index.js": "4788f78cbab43389d23feb71c8ef4e6657c01f9eeffe962650310784390bd486", + "worker/router.ts": "8e6fbb57855f0987cdf95dea492ce66184825cc2f5ae127865ff7988f8b57af3", + "worker/index.ts": "5317c8257a4ffcd4e023b08981cf8861d10092984a2664852b0eb55d2f34e50d" + }, + "outputInputs": [ + "node_modules/@cloudflare/containers/dist/index.js", + "node_modules/@cloudflare/containers/dist/lib/container.js", + "node_modules/@cloudflare/containers/dist/lib/helpers.js", + "worker/index.ts", + "worker/router.ts" + ], + "externalImports": [ + "cloudflare:workers" + ], + "exports": [ + "CloudContainer", + "default" + ], + "packages": { + "@cloudflare/containers": { + "version": "0.3.7", + "integrity": "sha512-DM9dm3FnIBSyiSJ1FLavKwl/lk3oAmTaynCzZQ9pZR0ncRPquSxkxd8Nu2MFILxmDDsPkxKsSNEh9mHHMty4Fw==" + }, + "wrangler": { + "version": "4.135.0", + "integrity": "sha512-WrNBQSfIG6YcILJcodYr5ty8vgkzGsV8YX+kfd+uZ5/Bd8cUW0GnUIRKAVfn5kYKqh1m/BPcji9h1d7mE8euFw==" + }, + "esbuild": { + "version": "0.28.1", + "integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==" + } + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/Containers.LICENSE.txt", + "third-party/Esbuild.LICENSE.txt" + ] + }, + "image": { + "baseImage": "mcr.microsoft.com/dotnet/runtime-deps:10.0.12-noble-chiseled@sha256:18d4848091a40d13dbfdd6a8340c1657dc3e2f2d7fa2f042e9d162e68669dbc9", + "baseLegal": { + "/usr/share/doc/base-files/copyright": "fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23", + "/usr/share/doc/ca-certificates/copyright": "e85e1bcad3a915dc7e6f41412bc5bdeba275cadd817896ea0451f2140a93967c", + "/usr/share/doc/gcc-14-base/copyright": "20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79", + "/usr/share/doc/libc6/copyright": "d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265", + "/usr/share/doc/libssl3t64/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35", + "/usr/share/doc/openssl/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35" + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/DotNet.AspNetCore.NOTICES.txt", + "third-party/DotNet.LICENSE.txt", + "third-party/DotNet.Runtime.NOTICES.txt", + "third-party/Grpc.LICENSE.txt", + "third-party/Protobuf.LICENSE.txt" + ], + "inputs": { + "Directory.Build.props": "594fe799ea787c02d4406e14360c4b1902a5aee8679b76c8ac797ae34a9e792c", + "Directory.Build.targets": "fa4bf35487140fecd21b71a2fb524792631a292df2313f9440f8c6e7e90a82d2", + "Directory.Packages.props": "b842214f27a1b95af27bfba82a786df28ed41f0443b545976c4fffc195df4c55", + "NuGet.Config": "cb93c65e28718aa9075fce221e9f9cea9e72d3fe1b30462383448a591f5b3aa1", + "global.json": "67381be18aa807c04218165844967cf58235875477f30495ba98c3648248a9d4", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj": "d2b84581970f81643c43207cb1e24557cd44abb7867e2ddfca6c18b6ed5c7851", + "src/ArcForges.Cloud/HealthStatus.cs": "984e22e7e2473e186e39e9db156b3c1b1275dd32af5d64e5591438785438739b", + "src/ArcForges.Cloud/HelloEndpoint.cs": "15ed003e7867e8131a8fa32ae74ffe2b6347f970d8ca679e0e538409aeb76598", + "src/ArcForges.Cloud/Program.cs": "5591a3562e67d399234b4ccd74e2f72e46dcff141e08f43c26dc87448ace534c", + "src/ArcForges.Cloud/packages.lock.json": "cbd7175143f33615d861ed2dc65e7b8cb30671a0e0ce62b81781943df6b2520c", + "Dockerfile": "cbe3e60d8b49be36901370e80b5171832642dd30680af83356431910edb07537", + ".dockerignore": "1bbebcf664aad8b96ed8e57799f555ea44ff8a99e526bf8eee0111a8ec1444ae", + "eng/version-sources.json": "9a848f211b5b64ce5b75ff398e991e16adc5f20fa716c5b46ccc71ddab210766", + "package-lock.json": "ffc439bd73191160b61b7f660690291799bad6f7d247d51593114707a25adbbe", + "src/ArcForges.Cloud/BuildIdentity.cs": "203f8d8fd30df0cfd1bf9ea68fb38ffa48403aa5c653bb09db29e5d752976e85" + }, + "buildImage": "mcr.microsoft.com/dotnet/sdk:10.0.401-noble-aot@sha256:96f3b7d45f53eb05990f05b89ce61c4e23d07a5098521c2f20b018630e34f298" + } +} diff --git a/eng/provenance/files.json b/eng/provenance/files.json index f98fbf3..433f977 100644 --- a/eng/provenance/files.json +++ b/eng/provenance/files.json @@ -45,6 +45,7 @@ "eng/provenance/NOTICE.txt", "eng/provenance/artifact-profiles/cloud-release-r1.json", "eng/provenance/artifact-profiles/cloud-release-r10.json", + "eng/provenance/artifact-profiles/cloud-release-r11.json", "eng/provenance/artifact-profiles/cloud-release-r2.json", "eng/provenance/artifact-profiles/cloud-release-r3.json", "eng/provenance/artifact-profiles/cloud-release-r4.json", @@ -59,6 +60,7 @@ "eng/provenance/records/cloud-runtime-notices-r1.json", "eng/provenance/records/cloud-runtime-notices-r10.json", "eng/provenance/records/cloud-runtime-notices-r11.json", + "eng/provenance/records/cloud-runtime-notices-r12.json", "eng/provenance/records/cloud-runtime-notices-r2.json", "eng/provenance/records/cloud-runtime-notices-r3.json", "eng/provenance/records/cloud-runtime-notices-r4.json", @@ -69,6 +71,7 @@ "eng/provenance/records/cloud-runtime-notices-r9.json", "eng/provenance/records/cloud-worker-bundle-r1.json", "eng/provenance/records/cloud-worker-bundle-r10.json", + "eng/provenance/records/cloud-worker-bundle-r11.json", "eng/provenance/records/cloud-worker-bundle-r2.json", "eng/provenance/records/cloud-worker-bundle-r3.json", "eng/provenance/records/cloud-worker-bundle-r4.json", @@ -149,5 +152,5 @@ "eng/version-sources.json": "arcnotes-build-identity-r1", "tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1" }, - "artifacts": ["cloud-runtime-notices-r11", "cloud-worker-bundle-r10"] + "artifacts": ["cloud-runtime-notices-r12", "cloud-worker-bundle-r11"] } diff --git a/eng/provenance/records/cloud-runtime-notices-r12.json b/eng/provenance/records/cloud-runtime-notices-r12.json new file mode 100644 index 0000000..89c60a3 --- /dev/null +++ b/eng/provenance/records/cloud-runtime-notices-r12.json @@ -0,0 +1,221 @@ +{ + "schemaVersion": 1, + "id": "cloud-runtime-notices-r12", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "38c7be9090af5322937ed287f259de4725b7d549", + "sourcePaths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image.", + "copyingPermission": null + }, + "attribution": [ + "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files." + ], + "targets": [], + "artifactTargets": [ + { + "project": "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "package": "arcforges-cloud-container", + "kind": "native-image-notices", + "profile": "eng/provenance/artifact-profiles/cloud-release-r11.json", + "sha256": "5faa9ad31460d4cedc37c841ce79051b7f695f69e432872063fc2d25ac9366ae" + } + ], + "disposition": "Copy", + "verification": { + "kind": "actual-image", + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs", + "sha256": "fdd1e2c6cb47d67b7f920a449d155434f8ad07a5779a574e9fcb1f52a5db37b6", + "finding": "Exact ILCompiler entry point independently fetched at the locked .NET commit. Its own file header explicitly grants MIT. Compiler implementation is a generator, not copied runtime application source." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "38c7be9090af5322937ed287f259de4725b7d549", + "paths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/grpc/grpc-dotnet", + "commit": "4c6997a214601422dd66c5c74c1969db749479e9", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "The restored Grpc 2.84.0 NuGet packages identify this official release source commit. Its complete Apache-2.0 LICENSE matches the retained full legal text." + } + ] + }, + { + "repository": "https://github.com/protocolbuffers/protobuf", + "commit": "f377bfefc5e2cfab68b816903c25b23e091c439d", + "paths": [ + "LICENSE" + ], + "spdx": "BSD-3-Clause", + "evidence": [ + { + "path": "LICENSE", + "sha256": "6e5e117324afd944dcf67f36cf329843bc1a92229a8cd9bb573d7a83130fea7d", + "finding": "Exact source commit is recorded by Google.Protobuf 3.36.1; this is the full upstream licence." + } + ] + }, + { + "repository": "https://github.com/ArcForges/Contracts", + "commit": "9f0e90f65d57f405fcee311d467a57a255dfd644", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "Normally restored NuGet and npm Contracts 1.0.0-ci.74.1 contain matching clean producer receipts at this source commit. The Hello v1 descriptor is unchanged, and the full published Apache-2.0 licence matches the retained legal text." + } + ] + }, + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "LICENSE.TXT", + "src/runtime/THIRD-PARTY-NOTICES.TXT", + "src/aspnetcore/THIRD-PARTY-NOTICES.txt" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/THIRD-PARTY-NOTICES.TXT", + "sha256": "66f1d4e44973185519bb4aa8a9718eb22fc7af2cc532e3ae9cfc4c127ee7fc54", + "finding": "Full original legal document. This record permits required unmodified notice reproduction only; it does not relicense listed components or admit their implementation." + } + ] + }, + { + "repository": "https://github.com/ArcForges/ArcNotes", + "commit": "0c797e30690a10d8798ddca19ca7f37b16cecf01", + "paths": [ + "src/ArcForges.ArcNotes.Core/BuildIdentity.cs", + "eng/version-sources.json" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Complete AGPL terms retained; owner-specific adaptation and exact targets are reviewed in arcnotes-build-identity-r1." + } + ] + } + ], + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "PR #12 carries the original PR #17 Contracts 74.1 target after Dependabot closed #17 and deleted its branch. The central NuGet declaration and all three project locks align with npm 74.1, preserving the existing shared-producer guard. Normally restored source receipts match exactly at clean source 9f0e90f65d57f405fcee311d467a57a255dfd644; the Hello v1 descriptor 7219a8d730978bcc3b7b8769e159d06711dff3f2b07715a6d487589f8c09b99c and full Apache licence are unchanged. Kotlin remains independently locked at 42.1 with the same descriptor. The profile admits only the central declaration, host lock and embedded npm lock changes. Worker source, generators and expected bytes, Docker pins and other native package versions remain unchanged. Release compilation and all 16 offline C# tests passed; retained static, offline and candidate checks apply under P2-017.", + "baselineCommit": "4c430f1a170725685c3864c9493e64888b905ebc", + "reconciliation": false + }, + "supersedes": "cloud-runtime-notices-r11" +} diff --git a/eng/provenance/records/cloud-worker-bundle-r11.json b/eng/provenance/records/cloud-worker-bundle-r11.json new file mode 100644 index 0000000..b14b832 --- /dev/null +++ b/eng/provenance/records/cloud-worker-bundle-r11.json @@ -0,0 +1,155 @@ +{ + "schemaVersion": 1, + "id": "cloud-worker-bundle-r11", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "38c7be9090af5322937ed287f259de4725b7d549", + "sourcePaths": [ + "worker/index.ts", + "worker/router.ts" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced.", + "copyingPermission": null + }, + "attribution": [ + "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle." + ], + "targets": [], + "artifactTargets": [ + { + "project": "package.json", + "package": "arcforges-cloud-worker", + "kind": "worker-bundle", + "profile": "eng/provenance/artifact-profiles/cloud-release-r11.json", + "sha256": "5faa9ad31460d4cedc37c841ce79051b7f695f69e432872063fc2d25ac9366ae" + } + ], + "disposition": "Rewrite", + "verification": { + "kind": "regeneration", + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/cloudflare/workers-sdk", + "commit": "f9e7727dbef58e71c6b297dc688d3c544cef87cb", + "paths": [ + "packages/wrangler/src/deployment-bundle/bundle.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Wrangler 4.135.0 retains the MIT grant; the standard deployment bundler source is unchanged from 4.132.0. Only unused experimental build-output handling changes in that directory. Wrangler remains a build tool, not bundled Worker code." + } + ] + }, + { + "repository": "https://github.com/evanw/esbuild", + "commit": "bb9db84c02433fbe37b3509f53f9f3e3cc48725e", + "paths": [ + "internal/runtime/runtime.go" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.md", + "sha256": "b40ec5baec7bb34fa5b1c09521fa3cd52d5fad7adafed74932a2010d3612a681", + "finding": "Only the actual generated __defProp/__name helper is inserted; its MIT licence accompanies the Worker." + } + ] + }, + { + "repository": "https://github.com/microsoft/TypeScript", + "commit": "050880ce59e30b356b686bd3144efe24f875ebc8", + "paths": [ + "src/compiler/transformers/ts.ts" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE.txt", + "sha256": "a7d00bfd54525bc694b6e32f64c7ebcf5e6b7ae3657be5cc12767bce74654a47", + "finding": "Upstream exact lock selects 6.0.3. Independent transpilation reproduced all four Containers JavaScript files byte-for-byte; compiler implementation is not bundled." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "38c7be9090af5322937ed287f259de4725b7d549", + "paths": [ + "worker/index.ts", + "worker/router.ts" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/cloudflare/containers", + "commit": "298169f4aaba82e7b712458b7c6b14fc3e40ad78", + "paths": [ + "src/lib/helpers.ts", + "src/lib/container.ts", + "src/lib/utils.ts", + "src/index.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Exact source files and generated npm package bytes reviewed; no subordinate licence override; MIT alternative selected, full copyright/terms retained." + } + ] + } + ], + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "PR #12 carries the original PR #17 Contracts 74.1 target after Dependabot closed #17 and deleted its branch. The central NuGet declaration and all three project locks align with npm 74.1, preserving the existing shared-producer guard. Normally restored source receipts match exactly at clean source 9f0e90f65d57f405fcee311d467a57a255dfd644; the Hello v1 descriptor 7219a8d730978bcc3b7b8769e159d06711dff3f2b07715a6d487589f8c09b99c and full Apache licence are unchanged. Kotlin remains independently locked at 42.1 with the same descriptor. The profile admits only the central declaration, host lock and embedded npm lock changes. Worker source, generators and expected bytes, Docker pins and other native package versions remain unchanged. Release compilation and all 16 offline C# tests passed; retained static, offline and candidate checks apply under P2-017.", + "baselineCommit": "4c430f1a170725685c3864c9493e64888b905ebc", + "reconciliation": false + }, + "supersedes": "cloud-worker-bundle-r10" +} From 944f54c52953952c434585c6d7cae9772f1d3010 Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 17:29:24 -0700 Subject: [PATCH 4/5] Retain published Contracts package attribution notice --- NOTICE | 4 +- eng/provenance/NOTICE.txt | 5 ++ eng/provenance/files.json | 4 +- .../records/contracts-notice-legal-r1.json | 80 +++++++++++++++++++ third-party/Contracts.NOTICE.txt | 64 +++++++++++++++ 5 files changed, 155 insertions(+), 2 deletions(-) create mode 100644 eng/provenance/records/contracts-notice-legal-r1.json create mode 100644 third-party/Contracts.NOTICE.txt diff --git a/NOTICE b/NOTICE index dc865aa..464b6f1 100644 --- a/NOTICE +++ b/NOTICE @@ -4,7 +4,9 @@ Copyright ArcForges contributors Original Cloud application and tooling: AGPL-3.0-only; see LICENSE. Contracts APIs are consumed as published Apache-2.0 packages from https://github.com/ArcForges/Contracts (C#/TypeScript version 1.0.0-ci.74.1; -Kotlin verification client version 1.0.0-ci.42.1). +Kotlin verification client version 1.0.0-ci.42.1). The complete published +NuGet NOTICE, including generator attributions and protobuf BSD terms, is +retained in third-party/Contracts.NOTICE.txt and the Native AOT image notices. The standard generated Gradle wrapper scripts and JAR are distributed under Apache-2.0 by the Gradle contributors; their original notices are retained. diff --git a/eng/provenance/NOTICE.txt b/eng/provenance/NOTICE.txt index 7f5b709..27bf674 100644 --- a/eng/provenance/NOTICE.txt +++ b/eng/provenance/NOTICE.txt @@ -27,6 +27,11 @@ https://github.com/cloudflare/containers @ 298169f4aaba82e7b712458b7c6b14fc3e40a MIT Copyright 2020 Cloudflare, Inc. Complete selected MIT notice for Containers 0.3.7 Worker code. +contracts-notice-legal-r1 +https://github.com/ArcForges/Contracts @ 9f0e90f65d57f405fcee311d467a57a255dfd644 +Apache-2.0 +The complete published ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 NOTICE is retained verbatim, including ArcForges, Google, gRPC, Buf and Connect attributions and the full protobuf-generator BSD-3-Clause text. Apache-2.0 describes the Contracts notice compilation/source grant; every named component retains its original terms. This admits only the package legal document, not generator implementations or additional runtime dependencies. + dotnet-aspnetcore-legal-r1 https://github.com/dotnet/dotnet @ 95017c711e6afc1085133d440e42b4bd78155701 MIT diff --git a/eng/provenance/files.json b/eng/provenance/files.json index 433f977..935dce7 100644 --- a/eng/provenance/files.json +++ b/eng/provenance/files.json @@ -81,6 +81,7 @@ "eng/provenance/records/cloud-worker-bundle-r8.json", "eng/provenance/records/cloud-worker-bundle-r9.json", "eng/provenance/records/containers-mit-legal-r1.json", + "eng/provenance/records/contracts-notice-legal-r1.json", "eng/provenance/records/dotnet-aspnetcore-legal-r1.json", "eng/provenance/records/dotnet-license-legal-r1.json", "eng/provenance/records/dotnet-runtime-legal-r1.json", @@ -150,7 +151,8 @@ "src/ArcForges.Cloud/BuildIdentity.cs": "arcnotes-build-identity-r1", "tests/ArcForges.Cloud.Tests/BuildIdentityTests.cs": "arcnotes-build-identity-r1", "eng/version-sources.json": "arcnotes-build-identity-r1", - "tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1" + "tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1", + "third-party/Contracts.NOTICE.txt": "contracts-notice-legal-r1" }, "artifacts": ["cloud-runtime-notices-r12", "cloud-worker-bundle-r11"] } diff --git a/eng/provenance/records/contracts-notice-legal-r1.json b/eng/provenance/records/contracts-notice-legal-r1.json new file mode 100644 index 0000000..3fb99c6 --- /dev/null +++ b/eng/provenance/records/contracts-notice-legal-r1.json @@ -0,0 +1,80 @@ +{ + "schemaVersion": 1, + "id": "contracts-notice-legal-r1", + "kind": "legal-document", + "sourceRepository": "https://github.com/ArcForges/Contracts", + "sourceCommit": "9f0e90f65d57f405fcee311d467a57a255dfd644", + "sourcePaths": [ + "eng/packaging_tools.py", + "eng/check_provenance.py", + "eng/provenance/records/hello-bindings-r1.json", + "eng/provenance/records/protobuf-generator-licence-r1.json" + ], + "licence": { + "spdx": "Apache-2.0", + "category": "permissive", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "Complete published Apache-2.0 terms match this producer source licence. The normally restored NuGet source receipt identifies this clean producer commit." + }, + { + "path": "eng/packaging_tools.py", + "sha256": "c2b8ca25a74633b3d25f67ba7ee76c989718ed10bccb28a96b68cc566e3cd0d4", + "finding": "metadata() compiles the package-specific NOTICE from its resolved dependency inventory and package_notice(). The copied target is the complete NOTICE from the normally restored NuGet 74.1 package, not the repository root NOTICE." + }, + { + "path": "eng/check_provenance.py", + "sha256": "c9e888d9845bd479c36439922c26038f29807214740ad7c467dfb3bb414a3024", + "finding": "package_notice() retains the active package-scoped hello-bindings and protobuf-generator legal records in the published NOTICE." + } + ], + "scope": "The complete published ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 NOTICE is retained verbatim, including ArcForges, Google, gRPC, Buf and Connect attributions and the full protobuf-generator BSD-3-Clause text. Apache-2.0 describes the Contracts notice compilation/source grant; every named component retains its original terms. This admits only the package legal document, not generator implementations or additional runtime dependencies.", + "copyingPermission": "Preserve the complete original legal text verbatim under its stated reproduction/attribution terms. This admits only legal documents, not differently licensed implementation." + }, + "attribution": [ + "The complete published ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 NOTICE is retained verbatim, including ArcForges, Google, gRPC, Buf and Connect attributions and the full protobuf-generator BSD-3-Clause text. Apache-2.0 describes the Contracts notice compilation/source grant; every named component retains its original terms. This admits only the package legal document, not generator implementations or additional runtime dependencies." + ], + "targets": [ + { + "path": "third-party/Contracts.NOTICE.txt", + "sha256": "07e4a8b46ff33f352f55b0ece39ab776c8e2830dfd11fab5ed0736aee6b320a3", + "normalization": "lf" + } + ], + "artifactTargets": [], + "disposition": "Copy", + "verification": { + "kind": "byte-match", + "command": "Compare complete recorded source and target bytes, allowing only declared LF normalization; run the owning source and actual candidate gates.", + "expected": "All exact target hashes and complete legal obligations match the reviewed sources.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "The complete published ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 NOTICE is retained verbatim, including ArcForges, Google, gRPC, Buf and Connect attributions and the full protobuf-generator BSD-3-Clause text. Apache-2.0 describes the Contracts notice compilation/source grant; every named component retains its original terms. This admits only the package legal document, not generator implementations or additional runtime dependencies.", + "files": [ + "eng/provenance/NOTICE.txt", + "third-party/Contracts.NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "The complete published ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 NOTICE is retained verbatim, including ArcForges, Google, gRPC, Buf and Connect attributions and the full protobuf-generator BSD-3-Clause text. Apache-2.0 describes the Contracts notice compilation/source grant; every named component retains its original terms. This admits only the package legal document, not generator implementations or additional runtime dependencies." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": null, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "Independent review of the actually restored Contracts 74.1 package identified added generator attributions and BSD terms absent from the predecessor package NOTICE. Retain the complete published legal document in the source tree, image notices and release legal bundle. The package source receipt and exact upstream packaging entry points establish its origin; no downloads, additional copied implementation or changed licence grants are involved.", + "baselineCommit": "4c430f1a170725685c3864c9493e64888b905ebc", + "reconciliation": false + }, + "supersedes": null +} diff --git a/third-party/Contracts.NOTICE.txt b/third-party/Contracts.NOTICE.txt new file mode 100644 index 0000000..d24db69 --- /dev/null +++ b/third-party/Contracts.NOTICE.txt @@ -0,0 +1,64 @@ +ArcForges Contracts +Copyright 2026 ArcForges contributors + +ArcForges.Contracts.PublicApi 1.0.0-ci.74.1 (Apache-2.0) + +Resolved runtime dependency inventory (dependencies retain their own licences): +- Google.Protobuf 3.36.1: BSD-3-Clause (pkg:nuget/Google.Protobuf@3.36.1) +- Grpc.Core.Api 2.83.0: Apache-2.0 (pkg:nuget/Grpc.Core.Api@2.83.0) + +Third-party dependencies are referenced, not vendored into this package. +The installed dependency packages supply their original licence and notice files. + +ArcForges source provenance notices + +Generated from reviewed active records. Original licence files and dependency notices remain authoritative. + +hello-bindings-r1 +Source: https://github.com/ArcForges/Contracts @ 76a3e0d39e61c7868b497ae7e059e29ac69f44de +Material licence: Apache-2.0 +Notice scope: packages +Copyright 2026 ArcForges contributors. +Copyright 2008 Google Inc. All rights reserved. +Copyright 2015, 2019, 2020 gRPC authors. +Copyright 2021-2026 Buf Technologies, Inc. +Copyright 2022-2026 The Connect Authors. +Hello bindings are generated from the Apache-2.0 ArcForges proto using Grpc.Tools 2.84.0, protoc-gen-es 2.15.0, grpc-java 1.84.0, grpc-kotlin 1.5.0 and Connect-Kotlin 0.9.0. Grpc.Tools provenance binds protobuf submodule 35cd01f9fe9afbeea38cc7b979a3b6bfcde82c03. Generator implementations are build tools and are not bundled in the client packages. Preserve these attributions, Apache-2.0 terms and the protobuf BSD terms below. + +protobuf-generator-licence-r1 +Source: https://github.com/protocolbuffers/protobuf @ 35cd01f9fe9afbeea38cc7b979a3b6bfcde82c03 +Material licence: BSD-3-Clause +Notice scope: packages +Copyright 2008 Google Inc. All rights reserved. +Copyright 2008 Google Inc. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are +met: + + * Redistributions of source code must retain the above copyright +notice, this list of conditions and the following disclaimer. + * Redistributions in binary form must reproduce the above +copyright notice, this list of conditions and the following disclaimer +in the documentation and/or other materials provided with the +distribution. + * Neither the name of Google Inc. nor the names of its +contributors may be used to endorse or promote products derived from +this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +Code generated by the Protocol Buffer compiler is owned by the owner +of the input file used when generating it. This code is not +standalone and requires a support library to be linked with it. This +support library is itself covered by the above license. From 3305d61edd39ad5b4f59a7a96c43870f6ad10a67 Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 17:30:03 -0700 Subject: [PATCH 5/5] Include Contracts NOTICE in candidate image legal bundle --- eng/provenance/NOTICE.txt | 10 +- .../artifact-profiles/cloud-release-r12.json | 91 ++++++++ eng/provenance/files.json | 5 +- .../records/cloud-runtime-notices-r13.json | 221 ++++++++++++++++++ .../records/cloud-worker-bundle-r12.json | 155 ++++++++++++ 5 files changed, 476 insertions(+), 6 deletions(-) create mode 100644 eng/provenance/artifact-profiles/cloud-release-r12.json create mode 100644 eng/provenance/records/cloud-runtime-notices-r13.json create mode 100644 eng/provenance/records/cloud-worker-bundle-r12.json diff --git a/eng/provenance/NOTICE.txt b/eng/provenance/NOTICE.txt index 27bf674..ec38e60 100644 --- a/eng/provenance/NOTICE.txt +++ b/eng/provenance/NOTICE.txt @@ -12,13 +12,13 @@ https://github.com/github/choosealicense.com @ 58267f8f2c5c0099810849cfd7677f52a AGPL-3.0-only GNU Affero General Public License version 3; Copyright Free Software Foundation, Inc. Complete original licence and its verbatim-copying permission are retained. -cloud-runtime-notices-r12 -https://github.com/ArcForges/Cloud @ 38c7be9090af5322937ed287f259de4725b7d549 +cloud-runtime-notices-r13 +https://github.com/ArcForges/Cloud @ 944f54c52953952c434585c6d7cae9772f1d3010 AGPL-3.0-only -ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. +ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. The complete published Contracts NOTICE is retained under third-party/Contracts.NOTICE.txt, including all generator attributions and the protobuf-generator BSD terms; generator implementations are not shipped. -cloud-worker-bundle-r11 -https://github.com/ArcForges/Cloud @ 38c7be9090af5322937ed287f259de4725b7d549 +cloud-worker-bundle-r12 +https://github.com/ArcForges/Cloud @ 944f54c52953952c434585c6d7cae9772f1d3010 AGPL-3.0-only Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle. diff --git a/eng/provenance/artifact-profiles/cloud-release-r12.json b/eng/provenance/artifact-profiles/cloud-release-r12.json new file mode 100644 index 0000000..6ac9b5b --- /dev/null +++ b/eng/provenance/artifact-profiles/cloud-release-r12.json @@ -0,0 +1,91 @@ +{ + "schemaVersion": 1, + "id": "cloud-release-r12", + "ownerCommit": "944f54c52953952c434585c6d7cae9772f1d3010", + "worker": { + "sha256": "a386a9f90d50f2b297f22e78c460f47e29f4005ec4313980348e4c53b82764e4", + "inputs": { + "node_modules/@cloudflare/containers/dist/lib/helpers.js": "320eae245a1d05a64c8348652f6808fa54c776340bd7c24391c19fe3b9e0f05f", + "node_modules/@cloudflare/containers/dist/lib/container.js": "9dfc5feaa43b2bdec08863c85eb94731237aeb9f19c7b7e58ff426776ec8863c", + "node_modules/@cloudflare/containers/dist/lib/utils.js": "22f96e63b873b10081fc15216bffc8d23a4614516efcb64be99db87372d4011c", + "node_modules/@cloudflare/containers/dist/index.js": "4788f78cbab43389d23feb71c8ef4e6657c01f9eeffe962650310784390bd486", + "worker/router.ts": "8e6fbb57855f0987cdf95dea492ce66184825cc2f5ae127865ff7988f8b57af3", + "worker/index.ts": "5317c8257a4ffcd4e023b08981cf8861d10092984a2664852b0eb55d2f34e50d" + }, + "outputInputs": [ + "node_modules/@cloudflare/containers/dist/index.js", + "node_modules/@cloudflare/containers/dist/lib/container.js", + "node_modules/@cloudflare/containers/dist/lib/helpers.js", + "worker/index.ts", + "worker/router.ts" + ], + "externalImports": [ + "cloudflare:workers" + ], + "exports": [ + "CloudContainer", + "default" + ], + "packages": { + "@cloudflare/containers": { + "version": "0.3.7", + "integrity": "sha512-DM9dm3FnIBSyiSJ1FLavKwl/lk3oAmTaynCzZQ9pZR0ncRPquSxkxd8Nu2MFILxmDDsPkxKsSNEh9mHHMty4Fw==" + }, + "wrangler": { + "version": "4.135.0", + "integrity": "sha512-WrNBQSfIG6YcILJcodYr5ty8vgkzGsV8YX+kfd+uZ5/Bd8cUW0GnUIRKAVfn5kYKqh1m/BPcji9h1d7mE8euFw==" + }, + "esbuild": { + "version": "0.28.1", + "integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==" + } + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/Containers.LICENSE.txt", + "third-party/Esbuild.LICENSE.txt" + ] + }, + "image": { + "baseImage": "mcr.microsoft.com/dotnet/runtime-deps:10.0.12-noble-chiseled@sha256:18d4848091a40d13dbfdd6a8340c1657dc3e2f2d7fa2f042e9d162e68669dbc9", + "baseLegal": { + "/usr/share/doc/base-files/copyright": "fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23", + "/usr/share/doc/ca-certificates/copyright": "e85e1bcad3a915dc7e6f41412bc5bdeba275cadd817896ea0451f2140a93967c", + "/usr/share/doc/gcc-14-base/copyright": "20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79", + "/usr/share/doc/libc6/copyright": "d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265", + "/usr/share/doc/libssl3t64/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35", + "/usr/share/doc/openssl/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35" + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/Contracts.NOTICE.txt", + "third-party/DotNet.AspNetCore.NOTICES.txt", + "third-party/DotNet.LICENSE.txt", + "third-party/DotNet.Runtime.NOTICES.txt", + "third-party/Grpc.LICENSE.txt", + "third-party/Protobuf.LICENSE.txt" + ], + "inputs": { + "Directory.Build.props": "594fe799ea787c02d4406e14360c4b1902a5aee8679b76c8ac797ae34a9e792c", + "Directory.Build.targets": "fa4bf35487140fecd21b71a2fb524792631a292df2313f9440f8c6e7e90a82d2", + "Directory.Packages.props": "b842214f27a1b95af27bfba82a786df28ed41f0443b545976c4fffc195df4c55", + "NuGet.Config": "cb93c65e28718aa9075fce221e9f9cea9e72d3fe1b30462383448a591f5b3aa1", + "global.json": "67381be18aa807c04218165844967cf58235875477f30495ba98c3648248a9d4", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj": "d2b84581970f81643c43207cb1e24557cd44abb7867e2ddfca6c18b6ed5c7851", + "src/ArcForges.Cloud/HealthStatus.cs": "984e22e7e2473e186e39e9db156b3c1b1275dd32af5d64e5591438785438739b", + "src/ArcForges.Cloud/HelloEndpoint.cs": "15ed003e7867e8131a8fa32ae74ffe2b6347f970d8ca679e0e538409aeb76598", + "src/ArcForges.Cloud/Program.cs": "5591a3562e67d399234b4ccd74e2f72e46dcff141e08f43c26dc87448ace534c", + "src/ArcForges.Cloud/packages.lock.json": "cbd7175143f33615d861ed2dc65e7b8cb30671a0e0ce62b81781943df6b2520c", + "Dockerfile": "cbe3e60d8b49be36901370e80b5171832642dd30680af83356431910edb07537", + ".dockerignore": "1bbebcf664aad8b96ed8e57799f555ea44ff8a99e526bf8eee0111a8ec1444ae", + "eng/version-sources.json": "9a848f211b5b64ce5b75ff398e991e16adc5f20fa716c5b46ccc71ddab210766", + "package-lock.json": "ffc439bd73191160b61b7f660690291799bad6f7d247d51593114707a25adbbe", + "src/ArcForges.Cloud/BuildIdentity.cs": "203f8d8fd30df0cfd1bf9ea68fb38ffa48403aa5c653bb09db29e5d752976e85" + }, + "buildImage": "mcr.microsoft.com/dotnet/sdk:10.0.401-noble-aot@sha256:96f3b7d45f53eb05990f05b89ce61c4e23d07a5098521c2f20b018630e34f298" + } +} diff --git a/eng/provenance/files.json b/eng/provenance/files.json index 935dce7..d1ddbbb 100644 --- a/eng/provenance/files.json +++ b/eng/provenance/files.json @@ -46,6 +46,7 @@ "eng/provenance/artifact-profiles/cloud-release-r1.json", "eng/provenance/artifact-profiles/cloud-release-r10.json", "eng/provenance/artifact-profiles/cloud-release-r11.json", + "eng/provenance/artifact-profiles/cloud-release-r12.json", "eng/provenance/artifact-profiles/cloud-release-r2.json", "eng/provenance/artifact-profiles/cloud-release-r3.json", "eng/provenance/artifact-profiles/cloud-release-r4.json", @@ -61,6 +62,7 @@ "eng/provenance/records/cloud-runtime-notices-r10.json", "eng/provenance/records/cloud-runtime-notices-r11.json", "eng/provenance/records/cloud-runtime-notices-r12.json", + "eng/provenance/records/cloud-runtime-notices-r13.json", "eng/provenance/records/cloud-runtime-notices-r2.json", "eng/provenance/records/cloud-runtime-notices-r3.json", "eng/provenance/records/cloud-runtime-notices-r4.json", @@ -72,6 +74,7 @@ "eng/provenance/records/cloud-worker-bundle-r1.json", "eng/provenance/records/cloud-worker-bundle-r10.json", "eng/provenance/records/cloud-worker-bundle-r11.json", + "eng/provenance/records/cloud-worker-bundle-r12.json", "eng/provenance/records/cloud-worker-bundle-r2.json", "eng/provenance/records/cloud-worker-bundle-r3.json", "eng/provenance/records/cloud-worker-bundle-r4.json", @@ -154,5 +157,5 @@ "tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1", "third-party/Contracts.NOTICE.txt": "contracts-notice-legal-r1" }, - "artifacts": ["cloud-runtime-notices-r12", "cloud-worker-bundle-r11"] + "artifacts": ["cloud-runtime-notices-r13", "cloud-worker-bundle-r12"] } diff --git a/eng/provenance/records/cloud-runtime-notices-r13.json b/eng/provenance/records/cloud-runtime-notices-r13.json new file mode 100644 index 0000000..dd5639c --- /dev/null +++ b/eng/provenance/records/cloud-runtime-notices-r13.json @@ -0,0 +1,221 @@ +{ + "schemaVersion": 1, + "id": "cloud-runtime-notices-r13", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "944f54c52953952c434585c6d7cae9772f1d3010", + "sourcePaths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image. The complete published Contracts NOTICE is retained under third-party/Contracts.NOTICE.txt, including all generator attributions and the protobuf-generator BSD terms; generator implementations are not shipped.", + "copyingPermission": null + }, + "attribution": [ + "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. The complete published Contracts NOTICE is retained under third-party/Contracts.NOTICE.txt, including all generator attributions and the protobuf-generator BSD terms; generator implementations are not shipped." + ], + "targets": [], + "artifactTargets": [ + { + "project": "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "package": "arcforges-cloud-container", + "kind": "native-image-notices", + "profile": "eng/provenance/artifact-profiles/cloud-release-r12.json", + "sha256": "2240b17719fa5131582045b6164735ae79c2880fd79c6c0c4e6479e0d4626321" + } + ], + "disposition": "Copy", + "verification": { + "kind": "actual-image", + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "expected": "Declared build inputs and the complete legal files, including the published Contracts NOTICE, match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. The complete published Contracts NOTICE is retained under third-party/Contracts.NOTICE.txt, including all generator attributions and the protobuf-generator BSD terms; generator implementations are not shipped.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image. The complete published Contracts NOTICE is retained under third-party/Contracts.NOTICE.txt, including all generator attributions and the protobuf-generator BSD terms; generator implementations are not shipped." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs", + "sha256": "fdd1e2c6cb47d67b7f920a449d155434f8ad07a5779a574e9fcb1f52a5db37b6", + "finding": "Exact ILCompiler entry point independently fetched at the locked .NET commit. Its own file header explicitly grants MIT. Compiler implementation is a generator, not copied runtime application source." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "944f54c52953952c434585c6d7cae9772f1d3010", + "paths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/grpc/grpc-dotnet", + "commit": "4c6997a214601422dd66c5c74c1969db749479e9", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "The restored Grpc 2.84.0 NuGet packages identify this official release source commit. Its complete Apache-2.0 LICENSE matches the retained full legal text." + } + ] + }, + { + "repository": "https://github.com/protocolbuffers/protobuf", + "commit": "f377bfefc5e2cfab68b816903c25b23e091c439d", + "paths": [ + "LICENSE" + ], + "spdx": "BSD-3-Clause", + "evidence": [ + { + "path": "LICENSE", + "sha256": "6e5e117324afd944dcf67f36cf329843bc1a92229a8cd9bb573d7a83130fea7d", + "finding": "Exact source commit is recorded by Google.Protobuf 3.36.1; this is the full upstream licence." + } + ] + }, + { + "repository": "https://github.com/ArcForges/Contracts", + "commit": "9f0e90f65d57f405fcee311d467a57a255dfd644", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "Normally restored NuGet and npm Contracts 1.0.0-ci.74.1 contain matching clean producer receipts at this source commit. The Hello v1 descriptor is unchanged, and the full published Apache-2.0 licence matches the retained legal text. The additional published NOTICE is independently admitted by contracts-notice-legal-r1 and shipped in full." + } + ] + }, + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "LICENSE.TXT", + "src/runtime/THIRD-PARTY-NOTICES.TXT", + "src/aspnetcore/THIRD-PARTY-NOTICES.txt" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/THIRD-PARTY-NOTICES.TXT", + "sha256": "66f1d4e44973185519bb4aa8a9718eb22fc7af2cc532e3ae9cfc4c127ee7fc54", + "finding": "Full original legal document. This record permits required unmodified notice reproduction only; it does not relicense listed components or admit their implementation." + } + ] + }, + { + "repository": "https://github.com/ArcForges/ArcNotes", + "commit": "0c797e30690a10d8798ddca19ca7f37b16cecf01", + "paths": [ + "src/ArcForges.ArcNotes.Core/BuildIdentity.cs", + "eng/version-sources.json" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Complete AGPL terms retained; owner-specific adaptation and exact targets are reviewed in arcnotes-build-identity-r1." + } + ] + } + ], + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "The independent review found newly added attributions and protobuf-generator BSD terms in the normally restored Contracts 74.1 NuGet NOTICE. The narrow contracts-notice-legal-r1 record retains that complete published document. This successor adds only third-party/Contracts.NOTICE.txt to the image legal-file list; the existing legalBundle and stageImageNotices paths package it without any validator or runtime changes. All image build inputs, dependency locks, Docker pins, Worker inputs, generator versions and expected Worker bytes remain identical to cloud-release-r11. Worker-specific legal files are unchanged because Contracts is development-only in that dependency graph. Previous immutable profiles and records are retained.", + "baselineCommit": "4c430f1a170725685c3864c9493e64888b905ebc", + "reconciliation": false + }, + "supersedes": "cloud-runtime-notices-r12" +} diff --git a/eng/provenance/records/cloud-worker-bundle-r12.json b/eng/provenance/records/cloud-worker-bundle-r12.json new file mode 100644 index 0000000..6a807f6 --- /dev/null +++ b/eng/provenance/records/cloud-worker-bundle-r12.json @@ -0,0 +1,155 @@ +{ + "schemaVersion": 1, + "id": "cloud-worker-bundle-r12", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "944f54c52953952c434585c6d7cae9772f1d3010", + "sourcePaths": [ + "worker/index.ts", + "worker/router.ts" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced.", + "copyingPermission": null + }, + "attribution": [ + "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle." + ], + "targets": [], + "artifactTargets": [ + { + "project": "package.json", + "package": "arcforges-cloud-worker", + "kind": "worker-bundle", + "profile": "eng/provenance/artifact-profiles/cloud-release-r12.json", + "sha256": "2240b17719fa5131582045b6164735ae79c2880fd79c6c0c4e6479e0d4626321" + } + ], + "disposition": "Rewrite", + "verification": { + "kind": "regeneration", + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "expected": "Declared build inputs and the complete legal files, including the published Contracts NOTICE, match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/cloudflare/workers-sdk", + "commit": "f9e7727dbef58e71c6b297dc688d3c544cef87cb", + "paths": [ + "packages/wrangler/src/deployment-bundle/bundle.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Wrangler 4.135.0 retains the MIT grant; the standard deployment bundler source is unchanged from 4.132.0. Only unused experimental build-output handling changes in that directory. Wrangler remains a build tool, not bundled Worker code." + } + ] + }, + { + "repository": "https://github.com/evanw/esbuild", + "commit": "bb9db84c02433fbe37b3509f53f9f3e3cc48725e", + "paths": [ + "internal/runtime/runtime.go" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.md", + "sha256": "b40ec5baec7bb34fa5b1c09521fa3cd52d5fad7adafed74932a2010d3612a681", + "finding": "Only the actual generated __defProp/__name helper is inserted; its MIT licence accompanies the Worker." + } + ] + }, + { + "repository": "https://github.com/microsoft/TypeScript", + "commit": "050880ce59e30b356b686bd3144efe24f875ebc8", + "paths": [ + "src/compiler/transformers/ts.ts" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE.txt", + "sha256": "a7d00bfd54525bc694b6e32f64c7ebcf5e6b7ae3657be5cc12767bce74654a47", + "finding": "Upstream exact lock selects 6.0.3. Independent transpilation reproduced all four Containers JavaScript files byte-for-byte; compiler implementation is not bundled." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "944f54c52953952c434585c6d7cae9772f1d3010", + "paths": [ + "worker/index.ts", + "worker/router.ts" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/cloudflare/containers", + "commit": "298169f4aaba82e7b712458b7c6b14fc3e40ad78", + "paths": [ + "src/lib/helpers.ts", + "src/lib/container.ts", + "src/lib/utils.ts", + "src/index.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Exact source files and generated npm package bytes reviewed; no subordinate licence override; MIT alternative selected, full copyright/terms retained." + } + ] + } + ], + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "The independent review found newly added attributions and protobuf-generator BSD terms in the normally restored Contracts 74.1 NuGet NOTICE. The narrow contracts-notice-legal-r1 record retains that complete published document. This successor adds only third-party/Contracts.NOTICE.txt to the image legal-file list; the existing legalBundle and stageImageNotices paths package it without any validator or runtime changes. All image build inputs, dependency locks, Docker pins, Worker inputs, generator versions and expected Worker bytes remain identical to cloud-release-r11. Worker-specific legal files are unchanged because Contracts is development-only in that dependency graph. Previous immutable profiles and records are retained.", + "baselineCommit": "4c430f1a170725685c3864c9493e64888b905ebc", + "reconciliation": false + }, + "supersedes": "cloud-worker-bundle-r11" +}