Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@
<ItemGroup>
<PackageVersion Include="ArcForges.Build.Policy" Version="1.0.0-ci.21.1" />
<PackageVersion Include="ArcForges.Contracts.PublicApi" Version="1.0.0-ci.36.1" />
<PackageVersion Include="Grpc.AspNetCore" Version="2.83.0" />
<PackageVersion Include="Grpc.AspNetCore.Web" Version="2.83.0" />
<PackageVersion Include="Grpc.Net.Client" Version="2.83.0" />
<PackageVersion Include="Grpc.AspNetCore" Version="2.84.0" />
<PackageVersion Include="Grpc.AspNetCore.Web" Version="2.84.0" />
<PackageVersion Include="Grpc.Net.Client" Version="2.84.0" />
<PackageVersion Include="xunit.v3.mtp-v2" Version="4.0.1" />
</ItemGroup>
</Project>
8 changes: 4 additions & 4 deletions eng/provenance/NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -12,13 +12,13 @@ https://github.com/github/choosealicense.com @ 58267f8f2c5c0099810849cfd7677f52a
AGPL-3.0-only
GNU Affero General Public License version 3; Copyright Free Software Foundation, Inc. Complete original licence and its verbatim-copying permission are retained.

cloud-runtime-notices-r8
https://github.com/ArcForges/Cloud @ 4fd33beb59dfabb3db12cda601b7507e82527807
cloud-runtime-notices-r9
https://github.com/ArcForges/Cloud @ 116ae5db1c9f22317e47c15b8f012374db04d881
AGPL-3.0-only
ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.

cloud-worker-bundle-r7
https://github.com/ArcForges/Cloud @ 4fd33beb59dfabb3db12cda601b7507e82527807
cloud-worker-bundle-r8
https://github.com/ArcForges/Cloud @ 116ae5db1c9f22317e47c15b8f012374db04d881
AGPL-3.0-only
Cloud routing: Copyright ArcForges contributors, AGPL-3.0-only. Containers: Copyright Cloudflare, Inc., selected MIT. esbuild helper: Copyright Evan Wallace, MIT. Complete respective terms accompany the actual Worker bundle.

Expand Down
90 changes: 90 additions & 0 deletions eng/provenance/artifact-profiles/cloud-release-r8.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,90 @@
{
"schemaVersion": 1,
"id": "cloud-release-r8",
"ownerCommit": "116ae5db1c9f22317e47c15b8f012374db04d881",
"worker": {
"sha256": "a386a9f90d50f2b297f22e78c460f47e29f4005ec4313980348e4c53b82764e4",
"inputs": {
"node_modules/@cloudflare/containers/dist/lib/helpers.js": "320eae245a1d05a64c8348652f6808fa54c776340bd7c24391c19fe3b9e0f05f",
"node_modules/@cloudflare/containers/dist/lib/container.js": "9dfc5feaa43b2bdec08863c85eb94731237aeb9f19c7b7e58ff426776ec8863c",
"node_modules/@cloudflare/containers/dist/lib/utils.js": "22f96e63b873b10081fc15216bffc8d23a4614516efcb64be99db87372d4011c",
"node_modules/@cloudflare/containers/dist/index.js": "4788f78cbab43389d23feb71c8ef4e6657c01f9eeffe962650310784390bd486",
"worker/router.ts": "8e6fbb57855f0987cdf95dea492ce66184825cc2f5ae127865ff7988f8b57af3",
"worker/index.ts": "5317c8257a4ffcd4e023b08981cf8861d10092984a2664852b0eb55d2f34e50d"
},
"outputInputs": [
"node_modules/@cloudflare/containers/dist/index.js",
"node_modules/@cloudflare/containers/dist/lib/container.js",
"node_modules/@cloudflare/containers/dist/lib/helpers.js",
"worker/index.ts",
"worker/router.ts"
],
"externalImports": [
"cloudflare:workers"
],
"exports": [
"CloudContainer",
"default"
],
"packages": {
"@cloudflare/containers": {
"version": "0.3.7",
"integrity": "sha512-DM9dm3FnIBSyiSJ1FLavKwl/lk3oAmTaynCzZQ9pZR0ncRPquSxkxd8Nu2MFILxmDDsPkxKsSNEh9mHHMty4Fw=="
},
"wrangler": {
"version": "4.132.0",
"integrity": "sha512-61HD7Unw3g7h9zSQoqldzfL3MEbCKUVfwtlMgfSQtjYwMjBD8z83K/EXnYGv75R5hczx3grFfjYH+tdmJm5PHg=="
},
"esbuild": {
"version": "0.28.1",
"integrity": "sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw=="
}
},
"legalFiles": [
"LICENSE",
"NOTICE",
"eng/provenance/NOTICE.txt",
"third-party/Containers.LICENSE.txt",
"third-party/Esbuild.LICENSE.txt"
]
},
"image": {
"baseImage": "mcr.microsoft.com/dotnet/runtime-deps:10.0.12-noble-chiseled@sha256:18d4848091a40d13dbfdd6a8340c1657dc3e2f2d7fa2f042e9d162e68669dbc9",
"baseLegal": {
"/usr/share/doc/base-files/copyright": "fd7e4aae7e7b05f217bcf2d02322825c360e66c52c4c2f1b28d784d6297a1c23",
"/usr/share/doc/ca-certificates/copyright": "e85e1bcad3a915dc7e6f41412bc5bdeba275cadd817896ea0451f2140a93967c",
"/usr/share/doc/gcc-14-base/copyright": "20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79",
"/usr/share/doc/libc6/copyright": "d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265",
"/usr/share/doc/libssl3t64/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35",
"/usr/share/doc/openssl/copyright": "6a7da622fe0637a334d2a8fc470852d2ffb77d9a2b2f930f854e32a41ad6ef35"
},
"legalFiles": [
"LICENSE",
"NOTICE",
"eng/provenance/NOTICE.txt",
"third-party/DotNet.AspNetCore.NOTICES.txt",
"third-party/DotNet.LICENSE.txt",
"third-party/DotNet.Runtime.NOTICES.txt",
"third-party/Grpc.LICENSE.txt",
"third-party/Protobuf.LICENSE.txt"
],
"inputs": {
"Directory.Build.props": "594fe799ea787c02d4406e14360c4b1902a5aee8679b76c8ac797ae34a9e792c",
"Directory.Build.targets": "fa4bf35487140fecd21b71a2fb524792631a292df2313f9440f8c6e7e90a82d2",
"Directory.Packages.props": "bd428b5fd151458ac4ae0a8914dfe7a6ff34f6741b3b75c2a57e123e2d0f31bb",
"NuGet.Config": "cb93c65e28718aa9075fce221e9f9cea9e72d3fe1b30462383448a591f5b3aa1",
"global.json": "67381be18aa807c04218165844967cf58235875477f30495ba98c3648248a9d4",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj": "d2b84581970f81643c43207cb1e24557cd44abb7867e2ddfca6c18b6ed5c7851",
"src/ArcForges.Cloud/HealthStatus.cs": "984e22e7e2473e186e39e9db156b3c1b1275dd32af5d64e5591438785438739b",
"src/ArcForges.Cloud/HelloEndpoint.cs": "15ed003e7867e8131a8fa32ae74ffe2b6347f970d8ca679e0e538409aeb76598",
"src/ArcForges.Cloud/Program.cs": "5591a3562e67d399234b4ccd74e2f72e46dcff141e08f43c26dc87448ace534c",
"src/ArcForges.Cloud/packages.lock.json": "d37f1d76d1793d3b91d09acffdf305bec34f1e57246e84e9e9c72dd5f606e04c",
"Dockerfile": "cbe3e60d8b49be36901370e80b5171832642dd30680af83356431910edb07537",
".dockerignore": "1bbebcf664aad8b96ed8e57799f555ea44ff8a99e526bf8eee0111a8ec1444ae",
"eng/version-sources.json": "9a848f211b5b64ce5b75ff398e991e16adc5f20fa716c5b46ccc71ddab210766",
"package-lock.json": "dfde7727091be40081633f6e80e594db1c6526629e04fca448b7a4167642139f",
"src/ArcForges.Cloud/BuildIdentity.cs": "203f8d8fd30df0cfd1bf9ea68fb38ffa48403aa5c653bb09db29e5d752976e85"
},
"buildImage": "mcr.microsoft.com/dotnet/sdk:10.0.401-noble-aot@sha256:96f3b7d45f53eb05990f05b89ce61c4e23d07a5098521c2f20b018630e34f298"
}
}
5 changes: 4 additions & 1 deletion eng/provenance/files.json
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@
"eng/provenance/artifact-profiles/cloud-release-r5.json",
"eng/provenance/artifact-profiles/cloud-release-r6.json",
"eng/provenance/artifact-profiles/cloud-release-r7.json",
"eng/provenance/artifact-profiles/cloud-release-r8.json",
"eng/provenance/files.json",
"eng/provenance/records/arcnotes-build-identity-r1.json",
"eng/provenance/records/canonical-agpl-legal-r1.json",
Expand All @@ -61,13 +62,15 @@
"eng/provenance/records/cloud-runtime-notices-r6.json",
"eng/provenance/records/cloud-runtime-notices-r7.json",
"eng/provenance/records/cloud-runtime-notices-r8.json",
"eng/provenance/records/cloud-runtime-notices-r9.json",
"eng/provenance/records/cloud-worker-bundle-r1.json",
"eng/provenance/records/cloud-worker-bundle-r2.json",
"eng/provenance/records/cloud-worker-bundle-r3.json",
"eng/provenance/records/cloud-worker-bundle-r4.json",
"eng/provenance/records/cloud-worker-bundle-r5.json",
"eng/provenance/records/cloud-worker-bundle-r6.json",
"eng/provenance/records/cloud-worker-bundle-r7.json",
"eng/provenance/records/cloud-worker-bundle-r8.json",
"eng/provenance/records/containers-mit-legal-r1.json",
"eng/provenance/records/dotnet-aspnetcore-legal-r1.json",
"eng/provenance/records/dotnet-license-legal-r1.json",
Expand Down Expand Up @@ -140,5 +143,5 @@
"eng/version-sources.json": "arcnotes-build-identity-r1",
"tests/ArcForges.Cloud.Tests/BuildMetadataTests.cs": "arcnotes-build-identity-r1"
},
"artifacts": ["cloud-runtime-notices-r8", "cloud-worker-bundle-r7"]
"artifacts": ["cloud-runtime-notices-r9", "cloud-worker-bundle-r8"]
}
221 changes: 221 additions & 0 deletions eng/provenance/records/cloud-runtime-notices-r9.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,221 @@
{
"schemaVersion": 1,
"id": "cloud-runtime-notices-r9",
"kind": "generated",
"sourceRepository": "https://github.com/ArcForges/Cloud",
"sourceCommit": "116ae5db1c9f22317e47c15b8f012374db04d881",
"sourcePaths": [
"Directory.Build.props",
"Directory.Build.targets",
"Directory.Packages.props",
"NuGet.Config",
"global.json",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"src/ArcForges.Cloud/HealthStatus.cs",
"src/ArcForges.Cloud/HelloEndpoint.cs",
"src/ArcForges.Cloud/Program.cs",
"src/ArcForges.Cloud/packages.lock.json",
"Dockerfile",
".dockerignore",
"eng/version-sources.json",
"package-lock.json",
"src/ArcForges.Cloud/BuildIdentity.cs"
],
"licence": {
"spdx": "AGPL-3.0-only",
"category": "agpl-compatible",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile."
}
],
"scope": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image.",
"copyingPermission": null
},
"attribution": [
"ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files."
],
"targets": [],
"artifactTargets": [
{
"project": "src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"package": "arcforges-cloud-container",
"kind": "native-image-notices",
"profile": "eng/provenance/artifact-profiles/cloud-release-r8.json",
"sha256": "068799910704cc70a2fa2730c1dca579bf173136da51b5dfcfbb1d340c9d5b52"
}
],
"disposition": "Copy",
"verification": {
"kind": "actual-image",
"command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.",
"expected": "The declared build inputs and unchanged full legal texts match the reviewed profile. Worker inputs, generator versions and expected bytes are unchanged from the predecessor. The sealed candidate preserves the inspected image and Worker identities.",
"artifacts": []
},
"notice": {
"required": true,
"text": "ArcForges application: AGPL-3.0-only. Published Contracts: Apache-2.0; copyright ArcForges contributors. .NET/ASP.NET Core, gRPC and Protocol Buffers retain their full recorded notices and separate licences. The unchanged official Ubuntu base retains its six original copyright files.",
"files": [
"eng/provenance/NOTICE.txt"
],
"distribution": "source-and-applicable-artifacts",
"reason": "Current Native AOT image preserves the immutable official base and its six full Ubuntu copyright files. Full .NET runtime/ASP.NET, gRPC, Protobuf and Apache Contracts legal texts accompany the owned application. Base/system components retain their original licences. No build-only wrapper/tool implementation is introduced into the runtime image."
},
"lifetime": {
"status": "permanent",
"owner": "Cloud Licensing and Provenance Owner",
"removalTrigger": null
},
"generation": {
"generators": [
{
"repository": "https://github.com/dotnet/dotnet",
"commit": "95017c711e6afc1085133d440e42b4bd78155701",
"paths": [
"src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs"
],
"spdx": "MIT",
"evidence": [
{
"path": "LICENSE.TXT",
"sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b",
"finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term."
},
{
"path": "src/runtime/src/coreclr/tools/aot/ILCompiler/Program.cs",
"sha256": "fdd1e2c6cb47d67b7f920a449d155434f8ad07a5779a574e9fcb1f52a5db37b6",
"finding": "Exact ILCompiler entry point independently fetched at the locked .NET commit. Its own file header explicitly grants MIT. Compiler implementation is a generator, not copied runtime application source."
}
]
}
],
"inputs": [
{
"repository": "https://github.com/ArcForges/Cloud",
"commit": "116ae5db1c9f22317e47c15b8f012374db04d881",
"paths": [
"Directory.Build.props",
"Directory.Build.targets",
"Directory.Packages.props",
"NuGet.Config",
"global.json",
"src/ArcForges.Cloud/ArcForges.Cloud.csproj",
"src/ArcForges.Cloud/HealthStatus.cs",
"src/ArcForges.Cloud/HelloEndpoint.cs",
"src/ArcForges.Cloud/Program.cs",
"src/ArcForges.Cloud/packages.lock.json",
"Dockerfile",
".dockerignore",
"eng/version-sources.json",
"package-lock.json",
"src/ArcForges.Cloud/BuildIdentity.cs"
],
"spdx": "AGPL-3.0-only",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Current authored Cloud inputs; exact source bytes and immutable dependency identities are bound by the profile."
}
]
},
{
"repository": "https://github.com/grpc/grpc-dotnet",
"commit": "4c6997a214601422dd66c5c74c1969db749479e9",
"paths": [
"LICENSE"
],
"spdx": "Apache-2.0",
"evidence": [
{
"path": "LICENSE",
"sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
"finding": "The restored Grpc 2.84.0 NuGet packages identify this official release source commit. Its complete Apache-2.0 LICENSE matches the retained full legal text."
}
]
},
{
"repository": "https://github.com/protocolbuffers/protobuf",
"commit": "f377bfefc5e2cfab68b816903c25b23e091c439d",
"paths": [
"LICENSE"
],
"spdx": "BSD-3-Clause",
"evidence": [
{
"path": "LICENSE",
"sha256": "6e5e117324afd944dcf67f36cf329843bc1a92229a8cd9bb573d7a83130fea7d",
"finding": "Exact source commit is recorded by Google.Protobuf 3.36.1; this is the full upstream licence."
}
]
},
{
"repository": "https://github.com/ArcForges/Contracts",
"commit": "d77aefabe0676dbe32845cbcf50aee361eb3fe7e",
"paths": [
"LICENSE"
],
"spdx": "Apache-2.0",
"evidence": [
{
"path": "LICENSE",
"sha256": "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30",
"finding": "NuGet 1.0.0-ci.36.1 binds this producer source; standard Apache legal text is identical and retained in full."
}
]
},
{
"repository": "https://github.com/dotnet/dotnet",
"commit": "95017c711e6afc1085133d440e42b4bd78155701",
"paths": [
"LICENSE.TXT",
"src/runtime/THIRD-PARTY-NOTICES.TXT",
"src/aspnetcore/THIRD-PARTY-NOTICES.txt"
],
"spdx": "MIT",
"evidence": [
{
"path": "LICENSE.TXT",
"sha256": "ae48df11a335dc1a615f4f938b69cba73bcf4485c4f97af49b38efb0f216353b",
"finding": "Locked .NET 10.0.12 runtime/compiler and ASP.NET Core packages identify this source commit. Their subordinate full notice documents retain every original term."
},
{
"path": "src/runtime/THIRD-PARTY-NOTICES.TXT",
"sha256": "66f1d4e44973185519bb4aa8a9718eb22fc7af2cc532e3ae9cfc4c127ee7fc54",
"finding": "Full original legal document. This record permits required unmodified notice reproduction only; it does not relicense listed components or admit their implementation."
}
]
},
{
"repository": "https://github.com/ArcForges/ArcNotes",
"commit": "0c797e30690a10d8798ddca19ca7f37b16cecf01",
"paths": [
"src/ArcForges.ArcNotes.Core/BuildIdentity.cs",
"eng/version-sources.json"
],
"spdx": "AGPL-3.0-only",
"evidence": [
{
"path": "LICENSE",
"sha256": "8486a10c4393cee1c25392769ddd3b2d6c242d6ec7928e1414efff7dfb2f07ef",
"finding": "Complete AGPL terms retained; owner-specific adaptation and exact targets are reviewed in arcnotes-build-identity-r1."
}
]
}
],
"command": "Build the locked Dockerfile Native AOT application with the reviewed SDK image digest; preserve the pinned runtime base and its full legal files. Inspect the stopped final image and source receipt under /app/notices. Promote the sealed candidate by its recorded identity without executing the application.",
"outputSpdx": "AGPL-3.0-only"
},
"review": {
"owner": "Licensing and Provenance Owner",
"reviewer": "Codex, acting under the maintainer's implementation/review authorization",
"reviewedOn": "2026-09-21",
"decision": "approved",
"rationale": "PR15 aligns Grpc.AspNetCore, Grpc.AspNetCore.Web and Grpc.Net.Client at 2.84.0 and regenerates every project lock with the normal NuGet resolver, including required transitive Microsoft.Extensions patch updates in the test graph. Restored gRPC nuspec metadata identifies official source 4c6997a214601422dd66c5c74c1969db749479e9; its full Apache licence matches the retained legal text. The central declaration and host lock are the only changed image-profile inputs. Both Docker pins, .NET/Protobuf/Contracts versions, Worker inputs/generators/expected bytes and full legal documents remain unchanged. Release compilation and all 16 offline C# tests passed; hosted Native AOT/Worker checks remain required under P2-017.",
"baselineCommit": "da2c123098a583efbe6770876914021d9e87509a",
"reconciliation": false
},
"supersedes": "cloud-runtime-notices-r8"
}
Loading
Loading