Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .gitleaks.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description = "Reviewed public source hashes in the immutable browser resource p
condition = "AND"
targetRules = ["generic-api-key"]
regexTarget = "line"
paths = ['''^eng/provenance/profiles/browser-resources-r[123]\.json$''']
paths = ['''^eng/provenance/profiles/browser-resources-r[1234]\.json$''']
regexes = [
'''^\s*"(?:apps/site/)?node_modules/@bufbuild/protobuf/dist/esm/wkt/gen/google/protobuf/api_pb\.js": "73e489001027c703bc0224ae73f78ecefe028e88284bd06952e8603c3d81472c",?$''',
'''^\s*"node_modules/@connectrpc/connect-web/dist/esm/assert-fetch-api\.js": "bd56033776818aaa82959c12561dd084d3a730180e6e8f1e681f5d3d439b6474",?$''',
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ The preview serves the actual candidate through local Wrangler at `http://127.0.
| `artifacts/candidate` | Ignored immutable delivery artifact, manifest and SBOMs |
| `win.slnx` / `ArcForges.Web.esproj` | Optional Visual Studio JavaScript project |

Baseline: TypeScript **7.0.2**, React **19.3.0**, React Router **8.4.0**, Vite **8.3.0**, Tailwind **4.3.3**, Wrangler **4.132.0**. One committed npm lockfile covers the entire workspace. Contracts packages are pinned to **1.0.0-ci.25.1**; no submodules or adjacent source references are used.
Baseline: TypeScript **7.0.2**, React **19.3.0**, React Router **8.4.0**, Vite **8.3.0**, Tailwind **4.3.3**, Wrangler **4.135.0**. One committed npm lockfile covers the entire workspace. Contracts packages are pinned to **1.0.0-ci.25.1**; no submodules or adjacent source references are used.

## Delivery

Expand Down
4 changes: 2 additions & 2 deletions eng/provenance/NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@ Web source provenance

Original material retains its recorded licence and full legal text.

browser-resources-r3
https://github.com/ArcForges/Web @ b084254549dcc329bbddecc938cf28f3a37c2aac
browser-resources-r4
https://github.com/ArcForges/Web @ 1fb22004f001ae9b635b6b7bd016a3f551fae290
AGPL-3.0-only
Web generated browser resources: AGPL-3.0-only owned code with permissive React/Router/Buf/Connect runtime and Vite/Rolldown/Tailwind helpers. Retain complete original legal texts, Router turbo-stream/devalue MIT attribution, original Google protobuf BSD schemas and Buf varint BSD notice. The companion punycode notice is retained for a parsed input, not a claim of emitted code. See the immutable profile for each exact source and package identity.

Expand Down
4 changes: 3 additions & 1 deletion eng/provenance/files.json
Original file line number Diff line number Diff line change
Expand Up @@ -62,9 +62,11 @@
"eng/provenance/profiles/browser-resources-r1.json",
"eng/provenance/profiles/browser-resources-r2.json",
"eng/provenance/profiles/browser-resources-r3.json",
"eng/provenance/profiles/browser-resources-r4.json",
"eng/provenance/records/browser-resources-r1.json",
"eng/provenance/records/browser-resources-r2.json",
"eng/provenance/records/browser-resources-r3.json",
"eng/provenance/records/browser-resources-r4.json",
"eng/provenance/records/canonical-agpl-legal-r1.json",
"eng/provenance/records/cloud-build-identity-r1.json",
"eng/provenance/records/cloud-build-identity-r2.json",
Expand Down Expand Up @@ -128,5 +130,5 @@
"tests/provenance/build-identity.test.ts": "cloud-build-identity-r2",
"eng/version-sources.json": "cloud-build-identity-r2"
},
"artifacts": ["browser-resources-r3"]
"artifacts": ["browser-resources-r4"]
}
8,461 changes: 8,461 additions & 0 deletions eng/provenance/profiles/browser-resources-r4.json

Large diffs are not rendered by default.

2,021 changes: 2,021 additions & 0 deletions eng/provenance/records/browser-resources-r4.json

Large diffs are not rendered by default.

68 changes: 34 additions & 34 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@
"typescript": "7.0.2",
"vite": "8.3.0",
"vitest": "5.0.1",
"wrangler": "4.132.0"
"wrangler": "4.135.0"
},
"arcforges": {
"licenceBoundary": "AGPL"
Expand Down
2 changes: 1 addition & 1 deletion tooling/browser-provenance.ts
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ import type { Plugin } from "vite";
import { auditProvenance, hash, parseDocument, readOwned, relative, store } from "./provenance.ts";

const owner = path.resolve(import.meta.dirname, "..");
export const profilePath = "eng/provenance/profiles/browser-resources-r3.json";
export const profilePath = "eng/provenance/profiles/browser-resources-r4.json";
const sha = (value: string | Uint8Array) => createHash("sha256").update(value).digest("hex");
const lf = (value: Buffer) =>
new TextDecoder("utf-8", { fatal: true }).decode(value).replaceAll("\r\n", "\n");
Expand Down
Loading