Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .gitleaks.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description = "Reviewed public source hashes in the immutable browser resource p
condition = "AND"
targetRules = ["generic-api-key"]
regexTarget = "line"
paths = ['''^eng/provenance/profiles/browser-resources-r[1234]\.json$''']
paths = ['''^eng/provenance/profiles/browser-resources-r[12345]\.json$''']
regexes = [
'''^\s*"(?:apps/site/)?node_modules/@bufbuild/protobuf/dist/esm/wkt/gen/google/protobuf/api_pb\.js": "73e489001027c703bc0224ae73f78ecefe028e88284bd06952e8603c3d81472c",?$''',
'''^\s*"node_modules/@connectrpc/connect-web/dist/esm/assert-fetch-api\.js": "bd56033776818aaa82959c12561dd084d3a730180e6e8f1e681f5d3d439b6474",?$''',
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ The preview serves the actual candidate through local Wrangler at `http://127.0.
| `artifacts/candidate` | Ignored immutable delivery artifact, manifest and SBOMs |
| `win.slnx` / `ArcForges.Web.esproj` | Optional Visual Studio JavaScript project |

Baseline: TypeScript **7.0.2**, React **19.3.0**, React Router **8.4.0**, Vite **8.3.0**, Tailwind **4.3.3**, Wrangler **4.135.0**. One committed npm lockfile covers the entire workspace. Contracts packages are pinned to **1.0.0-ci.25.1**; no submodules or adjacent source references are used.
Baseline: TypeScript **7.0.2**, React **19.3.0**, React Router **8.4.0**, Vite **8.3.0**, Tailwind **4.3.3**, Wrangler **4.135.0**. One committed npm lockfile covers the entire workspace. Contracts packages are pinned to **1.0.0-ci.44.1**; no submodules or adjacent source references are used.

## Delivery

Expand Down
4 changes: 2 additions & 2 deletions apps/site/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@
"typecheck": "react-router typegen && tsc -p tsconfig.json"
},
"dependencies": {
"@arcforges/api-client": "1.0.0-ci.25.1",
"@arcforges/proto": "1.0.0-ci.25.1",
"@arcforges/api-client": "1.0.0-ci.44.1",
"@arcforges/proto": "1.0.0-ci.44.1",
"@arcforges/web-ui": "0.0.0",
"@bufbuild/protobuf": "2.15.0",
"react": "19.3.0",
Expand Down
2 changes: 2 additions & 0 deletions docs/provenance.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,4 +36,6 @@ WP02.04 appends `browser-resources-r2` for the independently sourced build-info

## Current validation boundary

The active browser profile is `browser-resources-r5`. Revisions r3/r4 admit only reviewed development/deployment-tool lock changes. Revision r5 consumes Contracts `1.0.0-ci.44.1` and one protobuf `2.15.0` installation: the previously admitted implementations are unchanged, while duplicate module paths and emitted placements are removed. Its module/import graph was derived before compilation; one source-mapped compilation accounted for the three changed protobuf consumer/shared chunks, and the remaining fifteen normalized templates stayed unchanged. The same compiled files passed the final exact profile checks. Earlier profiles and their historical evidence remain immutable.

[Validation policy](validation-policy.md) supersedes earlier automatic browser/live/public-byte gates. Normal checks run offline source-policy/resolver tests; `test:artifact` is a separate opt-in investigation. Candidate construction retains required provenance, and the deployment entry point performs one trust-handoff check. Neither path launches a browser or downloads public assets to repeat verification.
4 changes: 2 additions & 2 deletions eng/provenance/NOTICE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@ Web source provenance

Original material retains its recorded licence and full legal text.

browser-resources-r4
https://github.com/ArcForges/Web @ 1fb22004f001ae9b635b6b7bd016a3f551fae290
browser-resources-r5
https://github.com/ArcForges/Web @ 160ac88477f1ad569e86a702af5fde033fe56590
AGPL-3.0-only
Web generated browser resources: AGPL-3.0-only owned code with permissive React/Router/Buf/Connect runtime and Vite/Rolldown/Tailwind helpers. Retain complete original legal texts, Router turbo-stream/devalue MIT attribution, original Google protobuf BSD schemas and Buf varint BSD notice. The companion punycode notice is retained for a parsed input, not a claim of emitted code. See the immutable profile for each exact source and package identity.

Expand Down
4 changes: 3 additions & 1 deletion eng/provenance/files.json
Original file line number Diff line number Diff line change
Expand Up @@ -63,10 +63,12 @@
"eng/provenance/profiles/browser-resources-r2.json",
"eng/provenance/profiles/browser-resources-r3.json",
"eng/provenance/profiles/browser-resources-r4.json",
"eng/provenance/profiles/browser-resources-r5.json",
"eng/provenance/records/browser-resources-r1.json",
"eng/provenance/records/browser-resources-r2.json",
"eng/provenance/records/browser-resources-r3.json",
"eng/provenance/records/browser-resources-r4.json",
"eng/provenance/records/browser-resources-r5.json",
"eng/provenance/records/canonical-agpl-legal-r1.json",
"eng/provenance/records/cloud-build-identity-r1.json",
"eng/provenance/records/cloud-build-identity-r2.json",
Expand Down Expand Up @@ -130,5 +132,5 @@
"tests/provenance/build-identity.test.ts": "cloud-build-identity-r2",
"eng/version-sources.json": "cloud-build-identity-r2"
},
"artifacts": ["browser-resources-r4"]
"artifacts": ["browser-resources-r5"]
}
Loading
Loading