From 9b19b85f5a9599205b75e6095a27d767e27dada1 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 21 Sep 2026 22:25:29 +0000 Subject: [PATCH 1/3] Bump the tooling group with 2 updates Bumps the tooling group with 2 updates: [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) and [prettier](https://github.com/prettier/prettier). Updates `@biomejs/biome` from 2.5.13 to 2.5.14 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome) Updates `prettier` from 3.9.6 to 3.9.8 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](https://github.com/prettier/prettier/compare/3.9.6...3.9.8) --- updated-dependencies: - dependency-name: "@biomejs/biome" dependency-version: 2.5.14 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: tooling - dependency-name: prettier dependency-version: 3.9.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: tooling ... Signed-off-by: dependabot[bot] --- package-lock.json | 80 +++++++++++++++++++++++------------------------ package.json | 4 +-- 2 files changed, 42 insertions(+), 42 deletions(-) diff --git a/package-lock.json b/package-lock.json index b30a9bc..283321c 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13,11 +13,11 @@ }, "devDependencies": { "@arcforges/api-client": "1.0.0-ci.36.1", - "@biomejs/biome": "2.5.13", + "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260915.1", "@connectrpc/connect": "2.2.0", "@types/node": "24.13.5", - "prettier": "3.9.6", + "prettier": "3.9.8", "typescript": "7.0.2", "wrangler": "4.132.0" }, @@ -50,9 +50,9 @@ } }, "node_modules/@biomejs/biome": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/biome/-/biome-2.5.13.tgz", - "integrity": "sha512-+SEC/mFk1a+5mvUANZgbZTaiZXs1nj4iMhL/PHiqDT5TPUEPFIlliEtkKKZB4N862yylHC3UI+/Sj2I0HJEqhA==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/biome/-/biome-2.5.14.tgz", + "integrity": "sha512-0FabLIjd4M/dm8VFI86RMaLLdgepzbdfiAL2R8cr7V81OYYrP1w7Z73KfAwPK5h9SrEBXTzNG2y+mBwPo9xRnw==", "dev": true, "license": "MIT OR Apache-2.0", "bin": { @@ -66,20 +66,20 @@ "url": "https://opencollective.com/biome" }, "optionalDependencies": { - "@biomejs/cli-darwin-arm64": "2.5.13", - "@biomejs/cli-darwin-x64": "2.5.13", - "@biomejs/cli-linux-arm64": "2.5.13", - "@biomejs/cli-linux-arm64-musl": "2.5.13", - "@biomejs/cli-linux-x64": "2.5.13", - "@biomejs/cli-linux-x64-musl": "2.5.13", - "@biomejs/cli-win32-arm64": "2.5.13", - "@biomejs/cli-win32-x64": "2.5.13" + "@biomejs/cli-darwin-arm64": "2.5.14", + "@biomejs/cli-darwin-x64": "2.5.14", + "@biomejs/cli-linux-arm64": "2.5.14", + "@biomejs/cli-linux-arm64-musl": "2.5.14", + "@biomejs/cli-linux-x64": "2.5.14", + "@biomejs/cli-linux-x64-musl": "2.5.14", + "@biomejs/cli-win32-arm64": "2.5.14", + "@biomejs/cli-win32-x64": "2.5.14" } }, "node_modules/@biomejs/cli-darwin-arm64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-darwin-arm64/-/cli-darwin-arm64-2.5.13.tgz", - "integrity": "sha512-nYSuDJ6zgVqZUkAkJkvhXxsF2PYIrUk/g638K4voCXz7foI9f7b6C2/7+oAihsHQlivZNMUrm/y8ywlcHQtZOw==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-darwin-arm64/-/cli-darwin-arm64-2.5.14.tgz", + "integrity": "sha512-UnzaXO65L4tsZimFITFP2M121GyhDcWFrT3pL5ZJ5U4XcS/0L5VHYytVohdCf/gnDUFHgl2I9xnt5bV/J1kxHQ==", "cpu": [ "arm64" ], @@ -94,9 +94,9 @@ } }, "node_modules/@biomejs/cli-darwin-x64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-darwin-x64/-/cli-darwin-x64-2.5.13.tgz", - "integrity": "sha512-KVy1ceEDuJ3AzFxjT9kkxbVy+UANw1pjEMUS6lvKfxjJ+fmkRvc7sQn1Xo6ETgseEI7wUQoV03KSga3XfE8YRQ==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-darwin-x64/-/cli-darwin-x64-2.5.14.tgz", + "integrity": "sha512-kiy8qA16K93J7uvFfWi4LgjqDpnRKyePAna6A0Y4jxyUga35SYpIZ2cNWlhy0lsfgqRenCpfymnJWEZ6mgpRgA==", "cpu": [ "x64" ], @@ -111,9 +111,9 @@ } }, "node_modules/@biomejs/cli-linux-arm64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-arm64/-/cli-linux-arm64-2.5.13.tgz", - "integrity": "sha512-VlNMtoxOqs0dUR6drxxHr18SNUvI7xxAuHZlH4s/dstYSf3g6RaqVgo8JRnhcOhKz9afWrvtJTboNG1JuYlIDQ==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-arm64/-/cli-linux-arm64-2.5.14.tgz", + "integrity": "sha512-vO/9BaU1n30CiFNLx49gMTMtbCAAqlo/EqFoG0BU3deQInTbJrmXSmTQ9e3FoDZIKQnvSLDVNL4lx1ci7y1T1Q==", "cpu": [ "arm64" ], @@ -131,9 +131,9 @@ } }, "node_modules/@biomejs/cli-linux-arm64-musl": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-arm64-musl/-/cli-linux-arm64-musl-2.5.13.tgz", - "integrity": "sha512-CH32xpep3dNS5EVJpAHlYchkBYznxyVZQrx0b6YYYlPL9u9ZeD2NtqiK/6s64+HFS2a7hGnryLlqqZAOh8ax5g==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-arm64-musl/-/cli-linux-arm64-musl-2.5.14.tgz", + "integrity": "sha512-SJ9PrZkBnnH9dHJDnxk34vKs0GB2dbsioaft6/hPhWJ7AHpwYH83Isnhj0FSRpFkGgpVfJ1lds23ApB2czUDLQ==", "cpu": [ "arm64" ], @@ -151,9 +151,9 @@ } }, "node_modules/@biomejs/cli-linux-x64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-x64/-/cli-linux-x64-2.5.13.tgz", - "integrity": "sha512-Fi6gIxbUaJ3ZCIXeG3ggIBPF76O2DjDN67WrPX/ODRv54GeXPm2gbEPC96Yb0yrJoiH0Eax1JLx1Pi0XbsNFZQ==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-x64/-/cli-linux-x64-2.5.14.tgz", + "integrity": "sha512-VHZRa7CCQBUWKxNwUvHJeuW03WFRgN5NWO//SDGOitc9QIeNyfA42V9zlKm+x82xFSG9Bzi5fi+hbhm9anO8yA==", "cpu": [ "x64" ], @@ -171,9 +171,9 @@ } }, "node_modules/@biomejs/cli-linux-x64-musl": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-x64-musl/-/cli-linux-x64-musl-2.5.13.tgz", - "integrity": "sha512-F3pmwl+VHoUuVJN/tbNLKeLt0SVK3EIyN1jXlMcNyQGYRQQTVqXF+GgkP0/CjGXFN87e/mv0sBfUnWqWza5PKQ==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-linux-x64-musl/-/cli-linux-x64-musl-2.5.14.tgz", + "integrity": "sha512-2kI5PrMgW5dcEZYrstLPmUmCwkUwZY39rP4BN93Vxbwcs2O57LDQOktUZZYPvvspN5i0mhGr3TJtF5sU26NUWg==", "cpu": [ "x64" ], @@ -191,9 +191,9 @@ } }, "node_modules/@biomejs/cli-win32-arm64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-win32-arm64/-/cli-win32-arm64-2.5.13.tgz", - "integrity": "sha512-+WD13qshXrr0Icv4BfsAdzm8Fs3TL+nZ59zEQxsYNd8lcgZJ0A5+OrlwsL1PipVCmWeRpxgIPD6DAcEd7smkCQ==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-win32-arm64/-/cli-win32-arm64-2.5.14.tgz", + "integrity": "sha512-pHgAFffmZtaYoxavEsWEYNvcA7NwOIjLyqw2HXyLbt16xYryX0L4fMV2u0G9ag6LNYPIoqWaWqzUcnc6rLGGXg==", "cpu": [ "arm64" ], @@ -208,9 +208,9 @@ } }, "node_modules/@biomejs/cli-win32-x64": { - "version": "2.5.13", - "resolved": "https://registry.npmjs.org/@biomejs/cli-win32-x64/-/cli-win32-x64-2.5.13.tgz", - "integrity": "sha512-VOofU/nW761XWzUeUNE8zzYNyPrxuMuNFMizL0qz7J75yeV8N7WFheUlk1/K6dOkaFpH9wJ+lDKlwjAbw0346w==", + "version": "2.5.14", + "resolved": "https://registry.npmjs.org/@biomejs/cli-win32-x64/-/cli-win32-x64-2.5.14.tgz", + "integrity": "sha512-oJWmBhoHsnhUKIke+0gXDX0mltJrWHA1UyHsrTlXwX0TL64ilVZAo+TYZm97baecV0esBdpzy3k96q+09JaZUQ==", "cpu": [ "x64" ], @@ -1985,9 +1985,9 @@ "license": "MIT" }, "node_modules/prettier": { - "version": "3.9.6", - "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.6.tgz", - "integrity": "sha512-OpN0zzVdiaiAhxpuuj5efpIS4sY9j7bY6uR5mnj5yPzGkdkjNKSJeUThPb60Jw29QuAZgA4o+/iB49kFiaBX6g==", + "version": "3.9.8", + "resolved": "https://registry.npmjs.org/prettier/-/prettier-3.9.8.tgz", + "integrity": "sha512-WRFq3Wn3WId7LLROfMLdH7xaFr2jR62wU8nLO6rQUOLOxNZUviyJQs1M0iIhLexSFy+L+w0ch66wtoO2jRjG0A==", "dev": true, "license": "MIT", "bin": { diff --git a/package.json b/package.json index 2f7189c..c14b6aa 100644 --- a/package.json +++ b/package.json @@ -39,11 +39,11 @@ }, "devDependencies": { "@arcforges/api-client": "1.0.0-ci.36.1", - "@biomejs/biome": "2.5.13", + "@biomejs/biome": "2.5.14", "@cloudflare/workers-types": "5.20260915.1", "@connectrpc/connect": "2.2.0", "@types/node": "24.13.5", - "prettier": "3.9.6", + "prettier": "3.9.8", "typescript": "7.0.2", "wrangler": "4.132.0" }, From 3ccb15362196cbe9009998ab876317ed355ef762 Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 16:49:00 -0700 Subject: [PATCH 2/3] Keep Biome configuration schema aligned with patched CLI --- biome.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/biome.json b/biome.json index 3c2d47f..e9148e4 100644 --- a/biome.json +++ b/biome.json @@ -1,5 +1,5 @@ { - "$schema": "https://biomejs.dev/schemas/2.5.13/schema.json", + "$schema": "https://biomejs.dev/schemas/2.5.14/schema.json", "vcs": { "enabled": true, "clientKind": "git", From ffc9c9adc8f1eef4d4f6a5321493fc64d13175fa Mon Sep 17 00:00:00 2001 From: sammiller Date: Mon, 21 Sep 2026 16:50:33 -0700 Subject: [PATCH 3/3] Record patched tooling lock in release provenance --- eng/provenance/NOTICE.txt | 8 +- .../artifact-profiles/cloud-release-r9.json | 90 +++++++ eng/provenance/files.json | 5 +- .../records/cloud-runtime-notices-r10.json | 221 ++++++++++++++++++ .../records/cloud-worker-bundle-r9.json | 155 ++++++++++++ 5 files changed, 474 insertions(+), 5 deletions(-) create mode 100644 eng/provenance/artifact-profiles/cloud-release-r9.json create mode 100644 eng/provenance/records/cloud-runtime-notices-r10.json create mode 100644 eng/provenance/records/cloud-worker-bundle-r9.json diff --git a/eng/provenance/NOTICE.txt b/eng/provenance/NOTICE.txt index ccd1ee7..ffda2ef 100644 --- a/eng/provenance/NOTICE.txt +++ b/eng/provenance/NOTICE.txt @@ -12,13 +12,13 @@ https://github.com/github/choosealicense.com @ 58267f8f2c5c0099810849cfd7677f52a AGPL-3.0-only GNU Affero General Public License version 3; Copyright Free Software Foundation, Inc. Complete original licence and its verbatim-copying permission are retained. -cloud-runtime-notices-r9 -https://github.com/ArcForges/Cloud @ 116ae5db1c9f22317e47c15b8f012374db04d881 +cloud-runtime-notices-r10 +https://github.com/ArcForges/Cloud @ 3ccb15362196cbe9009998ab876317ed355ef762 AGPL-3.0-only ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files. -cloud-worker-bundle-r8 -https://github.com/ArcForges/Cloud @ 116ae5db1c9f22317e47c15b8f012374db04d881 +cloud-worker-bundle-r9 +https://github.com/ArcForges/Cloud @ 3ccb15362196cbe9009998ab876317ed355ef762 AGPL-3.0-only Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle. diff --git a/eng/provenance/artifact-profiles/cloud-release-r9.json b/eng/provenance/artifact-profiles/cloud-release-r9.json new file mode 100644 index 0000000..d0bdf21 --- /dev/null +++ b/eng/provenance/artifact-profiles/cloud-release-r9.json @@ -0,0 +1,90 @@ +{ + "schemaVersion": 1, + "id": "cloud-release-r9", + "ownerCommit": "3ccb15362196cbe9009998ab876317ed355ef762", + "worker": { + "sha256": "a386a9f90d50f2b297f22e78c460f47e29f4005ec4313980348e4c53b82764e4", + "inputs": { + "node_modules/@cloudflare/containers/dist/lib/helpers.js": "320eae245a1d05a64c8348652f6808fa54c776340bd7c24391c19fe3b9e0f05f", + "node_modules/@cloudflare/containers/dist/lib/container.js": "9dfc5feaa43b2bdec08863c85eb94731237aeb9f19c7b7e58ff426776ec8863c", + "node_modules/@cloudflare/containers/dist/lib/utils.js": "22f96e63b873b10081fc15216bffc8d23a4614516efcb64be99db87372d4011c", + "node_modules/@cloudflare/containers/dist/index.js": "4788f78cbab43389d23feb71c8ef4e6657c01f9eeffe962650310784390bd486", + "worker/router.ts": "8e6fbb57855f0987cdf95dea492ce66184825cc2f5ae127865ff7988f8b57af3", + "worker/index.ts": "5317c8257a4ffcd4e023b08981cf8861d10092984a2664852b0eb55d2f34e50d" + }, + "outputInputs": [ + "node_modules/@cloudflare/containers/dist/index.js", + "node_modules/@cloudflare/containers/dist/lib/container.js", + "node_modules/@cloudflare/containers/dist/lib/helpers.js", + "worker/index.ts", + "worker/router.ts" + ], + "externalImports": [ + "cloudflare:workers" + ], + "exports": [ + "CloudContainer", + "default" + ], + "packages": { + "@cloudflare/containers": { + "version": "0.3.7", + "integrity": "sha512-DM9dm3FnIBSyiSJ1FLavKwl/lk3oAmTaynCzZQ9pZR0ncRPquSxkxd8Nu2MFILxmDDsPkxKsSNEh9mHHMty4Fw==" + }, + "wrangler": { + "version": "4.132.0", + "integrity": "sha512-61HD7Unw3g7h9zSQoqldzfL3MEbCKUVfwtlMgfSQtjYwMjBD8z83K/EXnYGv75R5hczx3grFfjYH+tdmJm5PHg==" + }, + "esbuild": { + "version": "0.28.1", + "integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==" + } + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/Containers.LICENSE.txt", + "third-party/Esbuild.LICENSE.txt" + ] + }, + "image": { + "baseImage": "mcr.microsoft.com/dotnet/runtime-deps:10.0.12-noble-chiseled@sha256:18d4848091a40d13dbfdd6a8340c1657dc3e2f2d7fa2f042e9d162e68669dbc9", + "baseLegal": { + "/usr/share/doc/base-files/copyright": "fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23", + "/usr/share/doc/ca-certificates/copyright": "e85e1bcad3a915dc7e6f41412bc5bdeba275cadd817896ea0451f2140a93967c", + "/usr/share/doc/gcc-14-base/copyright": "20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79", + "/usr/share/doc/libc6/copyright": "d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265", + "/usr/share/doc/libssl3t64/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35", + "/usr/share/doc/openssl/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35" + }, + "legalFiles": [ + "LICENSE", + "NOTICE", + "eng/provenance/NOTICE.txt", + "third-party/DotNet.AspNetCore.NOTICES.txt", + "third-party/DotNet.LICENSE.txt", + "third-party/DotNet.Runtime.NOTICES.txt", + "third-party/Grpc.LICENSE.txt", + "third-party/Protobuf.LICENSE.txt" + ], + "inputs": { + "Directory.Build.props": "594fe799ea787c02d4406e14360c4b1902a5aee8679b76c8ac797ae34a9e792c", + "Directory.Build.targets": "fa4bf35487140fecd21b71a2fb524792631a292df2313f9440f8c6e7e90a82d2", + "Directory.Packages.props": "bd428b5fd151458ac4ae0a8914dfe7a6ff34f6741b3b75c2a57e123e2d0f31bb", + "NuGet.Config": "cb93c65e28718aa9075fce221e9f9cea9e72d3fe1b30462383448a591f5b3aa1", + "global.json": "67381be18aa807c04218165844967cf58235875477f30495ba98c3648248a9d4", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj": "d2b84581970f81643c43207cb1e24557cd44abb7867e2ddfca6c18b6ed5c7851", + "src/ArcForges.Cloud/HealthStatus.cs": "984e22e7e2473e186e39e9db156b3c1b1275dd32af5d64e5591438785438739b", + "src/ArcForges.Cloud/HelloEndpoint.cs": "15ed003e7867e8131a8fa32ae74ffe2b6347f970d8ca679e0e538409aeb76598", + "src/ArcForges.Cloud/Program.cs": "5591a3562e67d399234b4ccd74e2f72e46dcff141e08f43c26dc87448ace534c", + "src/ArcForges.Cloud/packages.lock.json": "d37f1d76d1793d3b91d09acffdf305bec34f1e57246e84e9e9c72dd5f606e04c", + "Dockerfile": "cbe3e60d8b49be36901370e80b5171832642dd30680af83356431910edb07537", + ".dockerignore": "1bbebcf664aad8b96ed8e57799f555ea44ff8a99e526bf8eee0111a8ec1444ae", + "eng/version-sources.json": "9a848f211b5b64ce5b75ff398e991e16adc5f20fa716c5b46ccc71ddab210766", + "package-lock.json": "28273f64917e1dfb12228c103dcf2ad3f31ff6c829dfc8693abc2adffd8421ae", + "src/ArcForges.Cloud/BuildIdentity.cs": "203f8d8fd30df0cfd1bf9ea68fb38ffa48403aa5c653bb09db29e5d752976e85" + }, + "buildImage": "mcr.microsoft.com/dotnet/sdk:10.0.401-noble-aot@sha256:96f3b7d45f53eb05990f05b89ce61c4e23d07a5098521c2f20b018630e34f298" + } +} diff --git a/eng/provenance/files.json b/eng/provenance/files.json index f6802a5..fd9e491 100644 --- a/eng/provenance/files.json +++ b/eng/provenance/files.json @@ -51,10 +51,12 @@ "eng/provenance/artifact-profiles/cloud-release-r6.json", "eng/provenance/artifact-profiles/cloud-release-r7.json", "eng/provenance/artifact-profiles/cloud-release-r8.json", + "eng/provenance/artifact-profiles/cloud-release-r9.json", "eng/provenance/files.json", "eng/provenance/records/arcnotes-build-identity-r1.json", "eng/provenance/records/canonical-agpl-legal-r1.json", "eng/provenance/records/cloud-runtime-notices-r1.json", + "eng/provenance/records/cloud-runtime-notices-r10.json", "eng/provenance/records/cloud-runtime-notices-r2.json", "eng/provenance/records/cloud-runtime-notices-r3.json", "eng/provenance/records/cloud-runtime-notices-r4.json", @@ -71,6 +73,7 @@ "eng/provenance/records/cloud-worker-bundle-r6.json", "eng/provenance/records/cloud-worker-bundle-r7.json", "eng/provenance/records/cloud-worker-bundle-r8.json", + "eng/provenance/records/cloud-worker-bundle-r9.json", "eng/provenance/records/containers-mit-legal-r1.json", "eng/provenance/records/dotnet-aspnetcore-legal-r1.json", "eng/provenance/records/dotnet-license-legal-r1.json", @@ -143,5 +146,5 @@ "eng/version-sources.json": "arcnotes-build-identity-r1", "tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1" }, - "artifacts": ["cloud-runtime-notices-r9", "cloud-worker-bundle-r8"] + "artifacts": ["cloud-runtime-notices-r10", "cloud-worker-bundle-r9"] } diff --git a/eng/provenance/records/cloud-runtime-notices-r10.json b/eng/provenance/records/cloud-runtime-notices-r10.json new file mode 100644 index 0000000..9f52d04 --- /dev/null +++ b/eng/provenance/records/cloud-runtime-notices-r10.json @@ -0,0 +1,221 @@ +{ + "schemaVersion": 1, + "id": "cloud-runtime-notices-r10", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "3ccb15362196cbe9009998ab876317ed355ef762", + "sourcePaths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image.", + "copyingPermission": null + }, + "attribution": [ + "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files." + ], + "targets": [], + "artifactTargets": [ + { + "project": "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "package": "arcforges-cloud-container", + "kind": "native-image-notices", + "profile": "eng/provenance/artifact-profiles/cloud-release-r9.json", + "sha256": "3d2e57c3c41d07488fad0d2eb41979a57600f1adc05658b9131e89338829819f" + } + ], + "disposition": "Copy", + "verification": { + "kind": "actual-image", + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs", + "sha256": "fdd1e2c6cb47d67b7f920a449d155434f8ad07a5779a574e9fcb1f52a5db37b6", + "finding": "Exact ILCompiler entry point independently fetched at the locked .NET commit. Its own file header explicitly grants MIT. Compiler implementation is a generator, not copied runtime application source." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "3ccb15362196cbe9009998ab876317ed355ef762", + "paths": [ + "Directory.Build.props", + "Directory.Build.targets", + "Directory.Packages.props", + "NuGet.Config", + "global.json", + "src/ArcForges.Cloud/ArcForges.Cloud.csproj", + "src/ArcForges.Cloud/HealthStatus.cs", + "src/ArcForges.Cloud/HelloEndpoint.cs", + "src/ArcForges.Cloud/Program.cs", + "src/ArcForges.Cloud/packages.lock.json", + "Dockerfile", + ".dockerignore", + "eng/version-sources.json", + "package-lock.json", + "src/ArcForges.Cloud/BuildIdentity.cs" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/grpc/grpc-dotnet", + "commit": "4c6997a214601422dd66c5c74c1969db749479e9", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "The restored Grpc 2.84.0 NuGet packages identify this official release source commit. Its complete Apache-2.0 LICENSE matches the retained full legal text." + } + ] + }, + { + "repository": "https://github.com/protocolbuffers/protobuf", + "commit": "f377bfefc5e2cfab68b816903c25b23e091c439d", + "paths": [ + "LICENSE" + ], + "spdx": "BSD-3-Clause", + "evidence": [ + { + "path": "LICENSE", + "sha256": "6e5e117324afd944dcf67f36cf329843bc1a92229a8cd9bb573d7a83130fea7d", + "finding": "Exact source commit is recorded by Google.Protobuf 3.36.1; this is the full upstream licence." + } + ] + }, + { + "repository": "https://github.com/ArcForges/Contracts", + "commit": "d77aefabe0676dbe32845cbcf50aee361eb3fe7e", + "paths": [ + "LICENSE" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE", + "sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30", + "finding": "NuGet 1.0.0-ci.36.1 binds this producer source; standard Apache legal text is identical and retained in full." + } + ] + }, + { + "repository": "https://github.com/dotnet/dotnet", + "commit": "95017c711e6afc1085133d440e42b4bd78155701", + "paths": [ + "LICENSE.TXT", + "src/runtime/THIRD-PARTY-NOTICES.TXT", + "src/aspnetcore/THIRD-PARTY-NOTICES.txt" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.TXT", + "sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b", + "finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term." + }, + { + "path": "src/runtime/THIRD-PARTY-NOTICES.TXT", + "sha256": "66f1d4e44973185519bb4aa8a9718eb22fc7af2cc532e3ae9cfc4c127ee7fc54", + "finding": "Full original legal document. This record permits required unmodified notice reproduction only; it does not relicense listed components or admit their implementation." + } + ] + }, + { + "repository": "https://github.com/ArcForges/ArcNotes", + "commit": "0c797e30690a10d8798ddca19ca7f37b16cecf01", + "paths": [ + "src/ArcForges.ArcNotes.Core/BuildIdentity.cs", + "eng/version-sources.json" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Complete AGPL terms retained; owner-specific adaptation and exact targets are reviewed in arcnotes-build-identity-r1." + } + ] + } + ], + "command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "PR13 patches build-only Biome 2.5.13 to 2.5.14 and Prettier 3.9.6 to 3.9.8, and aligns the Biome schema declaration. The npm lock is embedded as package inventory in the application build identity, so the image profile admits that changed input. Native dependencies, both Docker pins, all Worker inputs and generator versions, independently reviewed Worker output and full legal texts remain unchanged. No third-party source is copied into owned code; retained static, offline and candidate checks apply under P2-017.", + "baselineCommit": "c536b2db4dc062800e86fda8f26a8a9ef556b77e", + "reconciliation": false + }, + "supersedes": "cloud-runtime-notices-r9" +} diff --git a/eng/provenance/records/cloud-worker-bundle-r9.json b/eng/provenance/records/cloud-worker-bundle-r9.json new file mode 100644 index 0000000..03442bb --- /dev/null +++ b/eng/provenance/records/cloud-worker-bundle-r9.json @@ -0,0 +1,155 @@ +{ + "schemaVersion": 1, + "id": "cloud-worker-bundle-r9", + "kind": "generated", + "sourceRepository": "https://github.com/ArcForges/Cloud", + "sourceCommit": "3ccb15362196cbe9009998ab876317ed355ef762", + "sourcePaths": [ + "worker/index.ts", + "worker/router.ts" + ], + "licence": { + "spdx": "AGPL-3.0-only", + "category": "agpl-compatible", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ], + "scope": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced.", + "copyingPermission": null + }, + "attribution": [ + "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle." + ], + "targets": [], + "artifactTargets": [ + { + "project": "package.json", + "package": "arcforges-cloud-worker", + "kind": "worker-bundle", + "profile": "eng/provenance/artifact-profiles/cloud-release-r9.json", + "sha256": "3d2e57c3c41d07488fad0d2eb41979a57600f1adc05658b9131e89338829819f" + } + ], + "disposition": "Rewrite", + "verification": { + "kind": "regeneration", + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.", + "artifacts": [] + }, + "notice": { + "required": true, + "text": "Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle.", + "files": [ + "eng/provenance/NOTICE.txt" + ], + "distribution": "source-and-applicable-artifacts", + "reason": "Current Worker bundle includes reviewed Cloudflare Containers and an esbuild helper under MIT alongside AGPL-owned routing. Exact locks, all source inputs, closed output membership and full legal texts are required. Browser/client UI is not introduced." + }, + "lifetime": { + "status": "permanent", + "owner": "Cloud Licensing and Provenance Owner", + "removalTrigger": null + }, + "generation": { + "generators": [ + { + "repository": "https://github.com/cloudflare/workers-sdk", + "commit": "bbf2f794365bcce20131aa05f6a11f2ed0f18463", + "paths": [ + "packages/wrangler/src/deployment-bundle/bundle.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Wrangler MIT choice is compatible; its implementation is a build tool, not bundled Worker code." + } + ] + }, + { + "repository": "https://github.com/evanw/esbuild", + "commit": "bb9db84c02433fbe37b3509f53f9f3e3cc48725e", + "paths": [ + "internal/runtime/runtime.go" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE.md", + "sha256": "b40ec5baec7bb34fa5b1c09521fa3cd52d5fad7adafed74932a2010d3612a681", + "finding": "Only the actual generated __defProp/__name helper is inserted; its MIT licence accompanies the Worker." + } + ] + }, + { + "repository": "https://github.com/microsoft/TypeScript", + "commit": "050880ce59e30b356b686bd3144efe24f875ebc8", + "paths": [ + "src/compiler/transformers/ts.ts" + ], + "spdx": "Apache-2.0", + "evidence": [ + { + "path": "LICENSE.txt", + "sha256": "a7d00bfd54525bc694b6e32f64c7ebcf5e6b7ae3657be5cc12767bce74654a47", + "finding": "Upstream exact lock selects 6.0.3. Independent transpilation reproduced all four Containers JavaScript files byte-for-byte; compiler implementation is not bundled." + } + ] + } + ], + "inputs": [ + { + "repository": "https://github.com/ArcForges/Cloud", + "commit": "3ccb15362196cbe9009998ab876317ed355ef762", + "paths": [ + "worker/index.ts", + "worker/router.ts" + ], + "spdx": "AGPL-3.0-only", + "evidence": [ + { + "path": "LICENSE", + "sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef", + "finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile." + } + ] + }, + { + "repository": "https://github.com/cloudflare/containers", + "commit": "298169f4aaba82e7b712458b7c6b14fc3e40ad78", + "paths": [ + "src/lib/helpers.ts", + "src/lib/container.ts", + "src/lib/utils.ts", + "src/index.ts" + ], + "spdx": "MIT", + "evidence": [ + { + "path": "LICENSE-MIT", + "sha256": "9bb3b077cc8628334bab25961223dd8207252c8a56aa054195be38f1c042aaf4", + "finding": "Exact source files and generated npm package bytes reviewed; no subordinate licence override; MIT alternative selected, full copyright/terms retained." + } + ] + } + ], + "command": "Restore the locked npm dependencies and build the Worker using wrangler deploy --dry-run --containers-rollout none. Preserve the existing independently reviewed Containers inputs, Worker bundle identity, closed output membership and full MIT/AGPL legal texts. No runtime execution or public artifact download is required.", + "outputSpdx": "AGPL-3.0-only" + }, + "review": { + "owner": "Licensing and Provenance Owner", + "reviewer": "Codex, acting under the maintainer's implementation/review authorization", + "reviewedOn": "2026-09-21", + "decision": "approved", + "rationale": "PR13 patches build-only Biome 2.5.13 to 2.5.14 and Prettier 3.9.6 to 3.9.8, and aligns the Biome schema declaration. The npm lock is embedded as package inventory in the application build identity, so the image profile admits that changed input. Native dependencies, both Docker pins, all Worker inputs and generator versions, independently reviewed Worker output and full legal texts remain unchanged. No third-party source is copied into owned code; retained static, offline and candidate checks apply under P2-017.", + "baselineCommit": "c536b2db4dc062800e86fda8f26a8a9ef556b77e", + "reconciliation": false + }, + "supersedes": "cloud-worker-bundle-r8" +}