build(site): [SITE-07] restore Monaco Markdown component notices

This commit is contained in:
Harvey Zhao committed 2026-09-15 10:41:24 +08:00
1 parent 426fee8faa
commit 244695e726
36 files changed
+6943 -9

No files matched your search

+2
View File
@@ -38,3 +38,5 @@ docs/licenses/monaco-editor/language-services/** -text whitespace=-trailing-spac
refactor/baselines/site-vendor/monaco-modes/** -text whitespace=-trailing-space,cr-at-eol
refactor/baselines/site-vendor/monaco-basic/** -text whitespace=-trailing-space,cr-at-eol
refactor/baselines/monaco-basic-fixtures.json text eol=lf
refactor/baselines/site-vendor/monaco-core-origins/** -text whitespace=-trailing-space,cr-at-eol
docs/licenses/monaco-editor/core-origins/** -text whitespace=-trailing-space,cr-at-eol
+12
View File
@@ -109,6 +109,14 @@ Included component: glob-to-regexp (Monaco JSON fork) embedded source in vscode-
Source: https://registry.npmjs.org/vscode-json-languageservice/-/vscode-json-languageservice-4.1.9.tgz
Included component: dompurify (Monaco core) 2.3.1
Source: https://registry.npmjs.org/dompurify/-/dompurify-2.3.1.tgz
Included component: marked (Monaco core) 3.0.2
Source: https://registry.npmjs.org/marked/-/marked-3.0.2.tgz
- licenses/monaco-editor/LICENSE
- licenses/monaco-editor/ThirdPartyNotices.txt
- licenses/monaco-editor/codicons/LICENSE
@@ -131,6 +139,10 @@ Source: https://registry.npmjs.org/vscode-json-languageservice/-/vscode-json-lan
- licenses/monaco-editor/language-services/beautify-css-NOTICE.txt
- licenses/monaco-editor/language-services/beautify-html-NOTICE.txt
- licenses/monaco-editor/language-services/ATTRIBUTION.md
- licenses/monaco-editor/core-origins/DOMPurify-LICENSE
- licenses/monaco-editor/core-origins/marked-LICENSE
- licenses/monaco-editor/core-origins/marked-vscode-license.txt
- licenses/monaco-editor/core-origins/ATTRIBUTION.md
## console legacy-vendor-with-TS-adapter
@@ -0,0 +1,28 @@
# Monaco core Markdown components
The site's unchanged Monaco 0.30.1 editor includes the following components from
VS Code commit 829382514cb1065f5ebb90f436e1c6103e153953. The original Monaco notices
remain in place; this supplement identifies missing or more precise information.
- DOMPurify 2.3.1, Copyright 2015 Mario Heiderich, Cure53 and other contributors.
[Complete original license](./DOMPurify-LICENSE). The upstream text offers a
choice of Apache 2.0 or MPL 2.0; both complete texts are retained verbatim.
Source: https://github.com/cure53/DOMPurify/tree/6cfcdf56269b892550af80baa7c1fa5b680e5db7
- marked 3.0.2, MarkedJS and Christopher Jeffrey.
[Original package license](./marked-LICENSE) and
[VS Code's retained older notice](./marked-vscode-license.txt).
Source: https://github.com/markedjs/marked/tree/d1b7d521c41bcf915f81f0218b0e5acd607c1b72
VS Code adapts DOMPurify's ESM export into an AMD factory and records alternative
ESM exports in comments. It adds commented ESM wrappers to marked. Monaco's build
assigns names to these two AMD definitions. The full adapted sources match their
fixed upstream Git files, the core archive's source map and development bundle.
The shipped editor retains the exact archived core code with its original
editor.main-to-edcore.main entry rename and appended language registrations.
ArtPlayer has not modified either component's runtime in this change.
The original Monaco notice omitted DOMPurify and used less precise marked
information. This supplement does not replace those original records or claim
that the entire Monaco core build, other embedded origins, or all sanitizer
behavior have been audited. Reproduction and browser regression instructions
are maintained in the repository's scripts/site-vendor/monaco/README.md.
@@ -0,0 +1,378 @@
DOMPurify
Copyright 2015 Mario Heiderich
DOMPurify is free software; you can redistribute it and/or modify it under the
terms of either:
a) the Apache License Version 2.0, or
b) the Mozilla Public License Version 2.0
-----------------------------------------------------------------------------
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-----------------------------------------------------------------------------
Mozilla Public License, version 2.0
1. Definitions
1.1. “Contributor”
means each individual or legal entity that creates, contributes to the
creation of, or owns Covered Software.
1.2. “Contributor Version”
means the combination of the Contributions of others (if any) used by a
Contributor and that particular Contributor’s Contribution.
1.3. “Contribution”
means Covered Software of a particular Contributor.
1.4. “Covered Software”
means Source Code Form to which the initial Contributor has attached the
notice in Exhibit A, the Executable Form of such Source Code Form, and
Modifications of such Source Code Form, in each case including portions
thereof.
1.5. “Incompatible With Secondary Licenses”
means
a. that the initial Contributor has attached the notice described in
Exhibit B to the Covered Software; or
b. that the Covered Software was made available under the terms of version
1.1 or earlier of the License, but not also under the terms of a
Secondary License.
1.6. “Executable Form”
means any form of the work other than Source Code Form.
1.7. “Larger Work”
means a work that combines Covered Software with other material, in a separate
file or files, that is not Covered Software.
1.8. “License”
means this document.
1.9. “Licensable”
means having the right to grant, to the maximum extent possible, whether at the
time of the initial grant or subsequently, any and all of the rights conveyed by
this License.
1.10. “Modifications”
means any of the following:
a. any file in Source Code Form that results from an addition to, deletion
from, or modification of the contents of Covered Software; or
b. any new file in Source Code Form that contains any Covered Software.
1.11. “Patent Claims” of a Contributor
means any patent claim(s), including without limitation, method, process,
and apparatus claims, in any patent Licensable by such Contributor that
would be infringed, but for the grant of the License, by the making,
using, selling, offering for sale, having made, import, or transfer of
either its Contributions or its Contributor Version.
1.12. “Secondary License”
means either the GNU General Public License, Version 2.0, the GNU Lesser
General Public License, Version 2.1, the GNU Affero General Public
License, Version 3.0, or any later versions of those licenses.
1.13. “Source Code Form”
means the form of the work preferred for making modifications.
1.14. “You” (or “Your”)
means an individual or a legal entity exercising rights under this
License. For legal entities, “You” includes any entity that controls, is
controlled by, or is under common control with You. For purposes of this
definition, “control” means (a) the power, direct or indirect, to cause
the direction or management of such entity, whether by contract or
otherwise, or (b) ownership of more than fifty percent (50%) of the
outstanding shares or beneficial ownership of such entity.
2. License Grants and Conditions
2.1. Grants
Each Contributor hereby grants You a world-wide, royalty-free,
non-exclusive license:
a. under intellectual property rights (other than patent or trademark)
Licensable by such Contributor to use, reproduce, make available,
modify, display, perform, distribute, and otherwise exploit its
Contributions, either on an unmodified basis, with Modifications, or as
part of a Larger Work; and
b. under Patent Claims of such Contributor to make, use, sell, offer for
sale, have made, import, and otherwise transfer either its Contributions
or its Contributor Version.
2.2. Effective Date
The licenses granted in Section 2.1 with respect to any Contribution become
effective for each Contribution on the date the Contributor first distributes
such Contribution.
2.3. Limitations on Grant Scope
The licenses granted in this Section 2 are the only rights granted under this
License. No additional rights or licenses will be implied from the distribution
or licensing of Covered Software under this License. Notwithstanding Section
2.1(b) above, no patent license is granted by a Contributor:
a. for any code that a Contributor has removed from Covered Software; or
b. for infringements caused by: (i) Your and any other third party’s
modifications of Covered Software, or (ii) the combination of its
Contributions with other software (except as part of its Contributor
Version); or
c. under Patent Claims infringed by Covered Software in the absence of its
Contributions.
This License does not grant any rights in the trademarks, service marks, or
logos of any Contributor (except as may be necessary to comply with the
notice requirements in Section 3.4).
2.4. Subsequent Licenses
No Contributor makes additional grants as a result of Your choice to
distribute the Covered Software under a subsequent version of this License
(see Section 10.2) or under the terms of a Secondary License (if permitted
under the terms of Section 3.3).
2.5. Representation
Each Contributor represents that the Contributor believes its Contributions
are its original creation(s) or it has sufficient rights to grant the
rights to its Contributions conveyed by this License.
2.6. Fair Use
This License is not intended to limit any rights You have under applicable
copyright doctrines of fair use, fair dealing, or other equivalents.
2.7. Conditions
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted in
Section 2.1.
3. Responsibilities
3.1. Distribution of Source Form
All distribution of Covered Software in Source Code Form, including any
Modifications that You create or to which You contribute, must be under the
terms of this License. You must inform recipients that the Source Code Form
of the Covered Software is governed by the terms of this License, and how
they can obtain a copy of this License. You may not attempt to alter or
restrict the recipients’ rights in the Source Code Form.
3.2. Distribution of Executable Form
If You distribute Covered Software in Executable Form then:
a. such Covered Software must also be made available in Source Code Form,
as described in Section 3.1, and You must inform recipients of the
Executable Form how they can obtain a copy of such Source Code Form by
reasonable means in a timely manner, at a charge no more than the cost
of distribution to the recipient; and
b. You may distribute such Executable Form under the terms of this License,
or sublicense it under different terms, provided that the license for
the Executable Form does not attempt to limit or alter the recipients’
rights in the Source Code Form under this License.
3.3. Distribution of a Larger Work
You may create and distribute a Larger Work under terms of Your choice,
provided that You also comply with the requirements of this License for the
Covered Software. If the Larger Work is a combination of Covered Software
with a work governed by one or more Secondary Licenses, and the Covered
Software is not Incompatible With Secondary Licenses, this License permits
You to additionally distribute such Covered Software under the terms of
such Secondary License(s), so that the recipient of the Larger Work may, at
their option, further distribute the Covered Software under the terms of
either this License or such Secondary License(s).
3.4. Notices
You may not remove or alter the substance of any license notices (including
copyright notices, patent notices, disclaimers of warranty, or limitations
of liability) contained within the Source Code Form of the Covered
Software, except that You may alter any license notices to the extent
required to remedy known factual inaccuracies.
3.5. Application of Additional Terms
You may choose to offer, and to charge a fee for, warranty, support,
indemnity or liability obligations to one or more recipients of Covered
Software. However, You may do so only on Your own behalf, and not on behalf
of any Contributor. You must make it absolutely clear that any such
warranty, support, indemnity, or liability obligation is offered by You
alone, and You hereby agree to indemnify every Contributor for any
liability incurred by such Contributor as a result of warranty, support,
indemnity or liability terms You offer. You may include additional
disclaimers of warranty and limitations of liability specific to any
jurisdiction.
4. Inability to Comply Due to Statute or Regulation
If it is impossible for You to comply with any of the terms of this License
with respect to some or all of the Covered Software due to statute, judicial
order, or regulation then You must: (a) comply with the terms of this License
to the maximum extent possible; and (b) describe the limitations and the code
they affect. Such description must be placed in a text file included with all
distributions of the Covered Software under this License. Except to the
extent prohibited by statute or regulation, such description must be
sufficiently detailed for a recipient of ordinary skill to be able to
understand it.
5. Termination
5.1. The rights granted under this License will terminate automatically if You
fail to comply with any of its terms. However, if You become compliant,
then the rights granted under this License from a particular Contributor
are reinstated (a) provisionally, unless and until such Contributor
explicitly and finally terminates Your grants, and (b) on an ongoing basis,
if such Contributor fails to notify You of the non-compliance by some
reasonable means prior to 60 days after You have come back into compliance.
Moreover, Your grants from a particular Contributor are reinstated on an
ongoing basis if such Contributor notifies You of the non-compliance by
some reasonable means, this is the first time You have received notice of
non-compliance with this License from such Contributor, and You become
compliant prior to 30 days after Your receipt of the notice.
5.2. If You initiate litigation against any entity by asserting a patent
infringement claim (excluding declaratory judgment actions, counter-claims,
and cross-claims) alleging that a Contributor Version directly or
indirectly infringes any patent, then the rights granted to You by any and
all Contributors for the Covered Software under Section 2.1 of this License
shall terminate.
5.3. In the event of termination under Sections 5.1 or 5.2 above, all end user
license agreements (excluding distributors and resellers) which have been
validly granted by You or Your distributors under this License prior to
termination shall survive termination.
6. Disclaimer of Warranty
Covered Software is provided under this License on an “as is” basis, without
warranty of any kind, either expressed, implied, or statutory, including,
without limitation, warranties that the Covered Software is free of defects,
merchantable, fit for a particular purpose or non-infringing. The entire
risk as to the quality and performance of the Covered Software is with You.
Should any Covered Software prove defective in any respect, You (not any
Contributor) assume the cost of any necessary servicing, repair, or
correction. This disclaimer of warranty constitutes an essential part of this
License. No use of any Covered Software is authorized under this License
except under this disclaimer.
7. Limitation of Liability
Under no circumstances and under no legal theory, whether tort (including
negligence), contract, or otherwise, shall any Contributor, or anyone who
distributes Covered Software as permitted above, be liable to You for any
direct, indirect, special, incidental, or consequential damages of any
character including, without limitation, damages for lost profits, loss of
goodwill, work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses, even if such party shall have been
informed of the possibility of such damages. This limitation of liability
shall not apply to liability for death or personal injury resulting from such
party’s negligence to the extent applicable law prohibits such limitation.
Some jurisdictions do not allow the exclusion or limitation of incidental or
consequential damages, so this exclusion and limitation may not apply to You.
8. Litigation
Any litigation relating to this License may be brought only in the courts of
a jurisdiction where the defendant maintains its principal place of business
and such litigation shall be governed by laws of that jurisdiction, without
reference to its conflict-of-law provisions. Nothing in this Section shall
prevent a party’s ability to bring cross-claims or counter-claims.
9. Miscellaneous
This License represents the complete agreement concerning the subject matter
hereof. If any provision of this License is held to be unenforceable, such
provision shall be reformed only to the extent necessary to make it
enforceable. Any law or regulation which provides that the language of a
contract shall be construed against the drafter shall not be used to construe
this License against a Contributor.
10. Versions of the License
10.1. New Versions
Mozilla Foundation is the license steward. Except as provided in Section
10.3, no one other than the license steward has the right to modify or
publish new versions of this License. Each version will be given a
distinguishing version number.
10.2. Effect of New Versions
You may distribute the Covered Software under the terms of the version of
the License under which You originally received the Covered Software, or
under the terms of any subsequent version published by the license
steward.
10.3. Modified Versions
If you create software not governed by this License, and you want to
create a new license for such software, you may create and use a modified
version of this License if you rename the license and remove any
references to the name of the license steward (except to note that such
modified license differs from this License).
10.4. Distributing Source Code Form that is Incompatible With Secondary Licenses
If You choose to distribute Source Code Form that is Incompatible With
Secondary Licenses under the terms of this version of the License, the
notice described in Exhibit B of this License must be attached.
Exhibit A - Source Code Form License Notice
This Source Code Form is subject to the
terms of the Mozilla Public License, v.
2.0. If a copy of the MPL was not
distributed with this file, You can
obtain one at
http://mozilla.org/MPL/2.0/.
If it is not possible or desirable to put the notice in a particular file, then
You may include the notice in a location (such as a LICENSE file in a relevant
directory) where a recipient would be likely to look for such a notice.
You may add additional accurate notices of copyright ownership.
Exhibit B - “Incompatible With Secondary Licenses” Notice
This Source Code Form is “Incompatible
With Secondary Licenses”, as defined by
the Mozilla Public License, v. 2.0.
@@ -0,0 +1,44 @@
# License information
## Contribution License Agreement
If you contribute code to this project, you are implicitly allowing your code
to be distributed under the MIT license. You are also implicitly verifying that
all code is your original work. `</legalese>`
## Marked
Copyright (c) 2018+, MarkedJS (https://github.com/markedjs/)
Copyright (c) 2011-2018, Christopher Jeffrey (https://github.com/chjj/)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
## Markdown
Copyright © 2004, John Gruber
http://daringfireball.net/
All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
* Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
* Neither the name “Markdown” nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.
This software is provided by the copyright holders and contributors “as is” and any express or implied warranties, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose are disclaimed. In no event shall the copyright owner or contributors be liable for any direct, indirect, incidental, special, exemplary, or consequential damages (including, but not limited to, procurement of substitute goods or services; loss of use, data, or profits; or business interruption) however caused and on any theory of liability, whether in contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use of this software, even if advised of the possibility of such damage.
@@ -0,0 +1,19 @@
Copyright (c) 2011-2014, Christopher Jeffrey (https://github.com/chjj/)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
+2 -1
View File
@@ -168,7 +168,8 @@
"verify:monaco-typescript-source": "node scripts/site-vendor/monaco/reproduce-typescript.ts",
"verify:monaco-language-sources": "node scripts/site-vendor/monaco/reproduce-languages.ts",
"verify:monaco-mode-sources": "node scripts/site-vendor/monaco/reproduce-modes.ts",
"verify:monaco-basic-sources": "node scripts/site-vendor/monaco/reproduce-basic.ts"
"verify:monaco-basic-sources": "node scripts/site-vendor/monaco/reproduce-basic.ts",
"verify:monaco-core-origins": "node scripts/site-vendor/monaco/reproduce-core-origins.ts"
},
"browserslist": "last 1 Chrome version",
"devDependencies": {
@@ -0,0 +1,197 @@
{
"schemaVersion": 1,
"task": "SITE-07",
"commit": "829382514cb1065f5ebb90f436e1c6103e153953",
"archives": [
{
"name": "monaco-editor",
"version": "0.30.1",
"tarball": "https://registry.npmjs.org/monaco-editor/-/monaco-editor-0.30.1.tgz",
"integrity": "sha512-B/y4+b2O5G2gjuxIFtCE2EkM17R2NM7/3F8x0qcPsqy4V83bitJTIO4TIeZpYlzu/xy6INiY/+84BEm6+7Cmzg==",
"sha256": "d7872ab742036036eca48cd54e43d751bede56742f0689bcf4049bcf701468c7"
},
{
"name": "monaco-editor-core",
"version": "0.30.1",
"tarball": "https://registry.npmjs.org/monaco-editor-core/-/monaco-editor-core-0.30.1.tgz",
"integrity": "sha512-WNxfchYafMZXVfysqg/ESW4MtOpYLPaIKrzudNlgwYvfYID+O/nwSZI5X+KxW84roVzHsNgFGyOOesfHFZwYUA==",
"sha256": "a3b004061373a7f6217eba6399f1a1de31970bee2eee693aada289035198c5ec"
},
{
"name": "dompurify",
"version": "2.3.1",
"tarball": "https://registry.npmjs.org/dompurify/-/dompurify-2.3.1.tgz",
"integrity": "sha512-xGWt+NHAQS+4tpgbOAI08yxW0Pr256Gu/FNE2frZVTbgrBUn8M7tz7/ktS/LZ2MHeGqz6topj0/xY+y8R5FBFw==",
"sha256": "ed6eb587561135a9f2860073bd81d9a25c8071d4567a338cbbd6baa3345b23db"
},
{
"name": "marked",
"version": "3.0.2",
"tarball": "https://registry.npmjs.org/marked/-/marked-3.0.2.tgz",
"integrity": "sha512-TMJQQ79Z0e3rJYazY0tIoMsFzteUGw9fB3FD+gzuIT3zLuG9L9ckIvUfF51apdJkcqc208jJN2KbtPbOvXtbjA==",
"sha256": "25d241753561b472915b4a233e0854b3ecf8d9202eab8a98d003afa1cb3537a1"
}
],
"remotes": [
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-browser-dompurify-dompurify.js.txt",
"sha256": "e6a37eb4085ce5f00f61e5365731f39e4d9a4c88460bff1fdc1fb6b01a890c8a",
"gitBlobSha": "08e22e087aaf02f8cc312bfc8b8a0afdae27acb2",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/browser/dompurify/dompurify.js?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-browser-dompurify-cgmanifest.json.txt",
"sha256": "06ecacbd8f1e384c6093a2c4974da3de9294cc541a4d100ef26efe262e88db40",
"gitBlobSha": "eac506db4b671b0f0afc954fe352dbd4bb869b10",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/browser/dompurify/cgmanifest.json?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-browser-dompurify-dompurify.license.txt.txt",
"sha256": "125e902252d137a2ce6902726d340b9e4f76b7f0466794c9b68b3cbd955449ce",
"gitBlobSha": "484aa7365ed0dde11b296bf4e456f62c31d5991d",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/browser/dompurify/dompurify.license.txt?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-common-marked-marked.js.txt",
"sha256": "801d3dbd78c3f11356cde8fbed21ad002bde76680537e3768620f79b9f7521e0",
"gitBlobSha": "b7a725a1bcac3e402a386a72da2eeb2f55af2072",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/common/marked/marked.js?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-common-marked-cgmanifest.json.txt",
"sha256": "fc14925f671675a55ee33d9d86db456c65ecec2f6720848c47518e9cfc3e4637",
"gitBlobSha": "47100d82d7f4d9ee4eac675d1082fbd27a9eb480",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/common/marked/cgmanifest.json?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/marked-vscode-license.txt",
"sha256": "43624283832b560f19539ec6d5766b7281acd4a63ada62e494c4e63c7a849bdb",
"gitBlobSha": "3bbf4af73ca9b4f955aa11cb9990a789a0c01d82",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/common/marked/marked.license.txt?ref=829382514cb1065f5ebb90f436e1c6103e153953"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-browser-markdownRenderer.ts.txt",
"sha256": "743ccdc11ea28a520f7b6fd2a3ad7ca65c9b6799a67f5e67f2ab72cb414bf3b5",
"gitBlobSha": "709959843525697eeafe094f124bc64da6a0d199",
"apiUrl": "https://api.github.com/repos/microsoft/vscode/contents/src/vs/base/browser/markdownRenderer.ts?ref=829382514cb1065f5ebb90f436e1c6103e153953"
}
],
"members": [
{
"archive": "monaco-editor-core-0.30.1",
"member": "package/dev/vs/editor/editor.main.js.map",
"sha256": "22a1b5ff5f423adc4575004d2ae0ae231ba59516e6aa9c2fabe8a006c2730316"
},
{
"archive": "monaco-editor-core-0.30.1",
"member": "package/dev/vs/editor/editor.main.js",
"sha256": "483348c3a73e86f201bc0df26ceee2c3ef610fe56c344993410fc093bac228a7"
},
{
"archive": "monaco-editor-core-0.30.1",
"member": "package/min/vs/editor/editor.main.js",
"sha256": "829b80acaafd97ed55fc008c4e937e60b1e197568c653fc9c391beb283abfc19"
}
],
"modules": [
{
"id": "vs/base/browser/dompurify/dompurify",
"archive": "dompurify-2.3.1",
"member": "package/dist/purify.es.js",
"sha256": "7b2bb6e42fcaae803c270660a5cc845c5e9a8d68313df56ea4d6fd53c0747974",
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-browser-dompurify-dompurify.js.txt",
"edits": [
{
"before": "export default purify;\n",
"after": "// ESM-comment-begin\ndefine(function () { return purify; });\n// ESM-comment-end\n\n// ESM-uncomment-begin\n// export default purify;\n// export const version = purify.version;\n// export const isSupported = purify.isSupported;\n// export const sanitize = purify.sanitize;\n// export const setConfig = purify.setConfig;\n// export const clearConfig = purify.clearConfig;\n// export const isValidAttribute = purify.isValidAttribute;\n// export const addHook = purify.addHook;\n// export const removeHook = purify.removeHook;\n// export const removeHooks = purify.removeHooks;\n// export const removeAllHooks = purify.removeAllHooks;\n// ESM-uncomment-end\n\n"
}
],
"naming": {
"before": "define(function",
"after": "define(\"vs/base/browser/dompurify/dompurify\", function"
}
},
{
"id": "vs/base/common/marked/marked",
"archive": "marked-3.0.2",
"member": "package/lib/marked.js",
"sha256": "2cb738415c26e90029833739348b353b0e8d1f632a4a60da067d2894a98b7030",
"source": "refactor/baselines/site-vendor/monaco-core-origins/src-vs-base-common-marked-marked.js.txt",
"edits": [
{
"before": "(function (global, factory) {",
"after": "// ESM-uncomment-begin\n// let __marked_exports;\n// (function() {\n// function define(factory) {\n// __marked_exports = factory();\n// }\n// define.amd = true;\n// ESM-uncomment-end\n\n (function (global, factory) {"
},
{
"before": "\n})));\n",
"after": "\n})));\n\n// ESM-uncomment-begin\n// })();\n// export var marked = __marked_exports;\n// export var Parser = __marked_exports.Parser;\n// export var parser = __marked_exports.parser;\n// export var Renderer = __marked_exports.Renderer;\n// export var TextRenderer = __marked_exports.TextRenderer;\n// export var Lexer = __marked_exports.Lexer;\n// export var lexer = __marked_exports.lexer;\n// export var Tokenizer = __marked_exports.Tokenizer;\n// export var Slugger = __marked_exports.Slugger;\n// export var parse = __marked_exports.parse;\n// ESM-uncomment-end\n"
}
],
"naming": {
"before": "define(factory) :",
"after": "define(\"vs/base/common/marked/marked\", factory) :"
}
}
],
"components": [
{
"name": "dompurify (Monaco core)",
"version": "2.3.1",
"tarball": "https://registry.npmjs.org/dompurify/-/dompurify-2.3.1.tgz",
"assets": [
"docs/assets/js/vs/editor/editor.main.js"
],
"notices": [
"docs/licenses/monaco-editor/core-origins/DOMPurify-LICENSE",
"docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md"
]
},
{
"name": "marked (Monaco core)",
"version": "3.0.2",
"tarball": "https://registry.npmjs.org/marked/-/marked-3.0.2.tgz",
"assets": [
"docs/assets/js/vs/editor/editor.main.js"
],
"notices": [
"docs/licenses/monaco-editor/core-origins/marked-LICENSE",
"docs/licenses/monaco-editor/core-origins/marked-vscode-license.txt",
"docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md"
]
}
],
"notices": [
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/DOMPurify-LICENSE",
"target": "docs/licenses/monaco-editor/core-origins/DOMPurify-LICENSE",
"sha256": "8b6902e953e2eb2876412a4ba75291758b77e88e220962e3423af4d080db1a59",
"archive": "dompurify-2.3.1",
"member": "package/LICENSE"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/marked-LICENSE",
"target": "docs/licenses/monaco-editor/core-origins/marked-LICENSE",
"sha256": "8e3a3f82f59a60958f56ca08f445647c32a4733dc7ca6c2c46f6eb898471ab9c",
"archive": "marked-3.0.2",
"member": "package/LICENSE.md"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/marked-vscode-license.txt",
"target": "docs/licenses/monaco-editor/core-origins/marked-vscode-license.txt",
"sha256": "43624283832b560f19539ec6d5766b7281acd4a63ada62e494c4e63c7a849bdb"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/ATTRIBUTION.md",
"target": "docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md",
"sha256": "3a0ab7f1036d6b1397bf94ff2700375b97db2db3bd576d195dc6d8a88e1a758e"
}
],
"target": {
"path": "docs/assets/js/vs/editor/editor.main.js",
"sha256": "05a50ed50bb013b6e7a82d25686186aa7bdff8b8209c7badab00e046b5e99618"
},
"limits": [
"Proof covers two embedded sources and the archived core prefix, not a complete core source build.",
"Remaining core/loader/localization and other embedded origins stay open."
]
}
@@ -0,0 +1,212 @@
{
"schemaVersion": 1,
"task": "SITE-07",
"status": "checkpoint-incomplete",
"recordedAt": "2026-09-15T02:39:48.757Z",
"baseCommit": "426fee8faa7d4fe183fb3b5911d8b515f5f34bab",
"node": "v24.21.0",
"yarn": "1.22.22",
"fingerprints": {
"refactor/baselines/monaco-core-origins-provenance.json": "d5b86ae1d8351f5852c0ba6906213339e06c47816e100e1d16f2d71ae4a66973",
"scripts/site-vendor/manifest.json": "0df294c8b335fb43911612f72a9af235343b7a89753746b73f75055a2958ab1c",
"scripts/site-vendor/monaco/core-origins.ts": "455683490eb77b325e63db1fdb9f092379804f657b59f654558ac47e7ceba832",
"scripts/site-vendor/monaco/reproduce-core-origins.ts": "b28bdf05a502e9adfc45896302ec5334cbfcc8f8f8ae84e4a6e2d8cc53077e1a",
"test/browser/editor-markdown.spec.js": "5f672e9322bac4f85ba2396adfef7e5605c436a9eeb274f4e30228fa54088e6c",
"test/browser/site-vendor.spec.js": "4880a1b0d2afdc94a9f5f48679308ffb840e3410daabf00122779c86eb6b56b4"
},
"reproduction": {
"result": {
"archives": 4,
"gitSources": 7,
"modules": [
{
"id": "vs/base/browser/dompurify/dompurify",
"bytes": 52931,
"offset": 46157,
"exactNpmAdaptation": true,
"exactGitAndDevelopment": true
},
{
"id": "vs/base/common/marked/marked",
"bytes": 95547,
"offset": 225102,
"exactNpmAdaptation": true,
"exactGitAndDevelopment": true
}
],
"notices": 4,
"archivedCorePrefix": true,
"completeCoreBuild": false,
"otherEmbeddedOriginsReviewed": false
},
"offline": {
"exitCode": 0,
"log": "refactor/.cache/monaco-core-origins-offline.log"
},
"network": {
"exitCode": 0,
"log": "refactor/.cache/monaco-core-origins-network.log"
}
},
"unit": {
"passed": 18,
"log": "refactor/.cache/monaco-core-origins-unit.log"
},
"typecheck": {
"exitCode": 0,
"log": "refactor/.cache/monaco-core-origins-types.log"
},
"lint": {
"exitCode": 0,
"log": "refactor/.cache/monaco-core-origins-lint.log"
},
"notices": {
"files": 85,
"outputs": 86,
"generated": true,
"readOnlyCheck": true
},
"browser": {
"report": "refactor/.cache/browser/report.json",
"sha256": "46153e56b1ab9e6122191726b9313bb70382008569845d702962b037c638882b",
"stats": {
"startTime": "2026-09-15T02:35:58.801Z",
"duration": 14608.404,
"expected": 6,
"skipped": 0,
"unexpected": 0,
"flaky": 0
},
"tests": [
{
"title": "docs Monaco renders Markdown with its bundled parser and sanitizer",
"project": "chromium",
"status": "passed",
"browser": "153.0.8010.12",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [],
"media": null,
"markdown": {
"version": "2.3.1",
"strong": "Player",
"code": "art.play()",
"cells": [
"play",
"Promise"
],
"link": "https://artplayer.org/document/",
"text": "Player and art.play()\n\n\nAPI\nResult\n\n\n\nplay\nPromise\n\n\nDocssafe text",
"scripts": 0,
"handlers": 0,
"executed": false,
"afterDispose": "<div style=\"color:red\">next</div>"
}
},
{
"title": "docs Monaco renders Markdown with its bundled parser and sanitizer",
"project": "firefox",
"status": "passed",
"browser": "155.0",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [],
"media": null,
"markdown": {
"version": "2.3.1",
"strong": "Player",
"code": "art.play()",
"cells": [
"play",
"Promise"
],
"link": "https://artplayer.org/document/",
"text": "Player and art.play()\n\n\nAPI\nResult\n\n\n\nplay\nPromise\n\n\nDocssafe text",
"scripts": 0,
"handlers": 0,
"executed": false,
"afterDispose": "<div style=\"color:red\">next</div>"
}
},
{
"title": "docs Monaco renders Markdown with its bundled parser and sanitizer",
"project": "webkit",
"status": "passed",
"browser": "26.6",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [],
"media": null,
"markdown": {
"version": "2.3.1",
"strong": "Player",
"code": "art.play()",
"cells": [
"play",
"Promise"
],
"link": "https://artplayer.org/document/",
"text": "Player and art.play()\n\n\nAPI\nResult\n\n\n\nplay\nPromise\n\n\nDocssafe text",
"scripts": 0,
"handlers": 0,
"executed": false,
"afterDispose": "<div style=\"color:red\">next</div>"
}
},
{
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"project": "chromium",
"status": "passed",
"browser": "153.0.8010.12",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [
{
"url": "http://127.0.0.1:8084/test/pattern.mp4",
"resourceType": "media",
"failure": {
"errorText": "net::ERR_ABORTED"
}
}
],
"media": null,
"noticeCount": 85
},
{
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"project": "firefox",
"status": "passed",
"browser": "155.0",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [],
"media": null,
"noticeCount": 85
},
{
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
"project": "webkit",
"status": "passed",
"browser": "26.6",
"platform": "win32",
"errors": [],
"consoleErrors": [],
"failedRequests": [],
"media": null,
"noticeCount": 85
}
]
},
"limitations": [
"Only two complete embedded-source adaptations and the archived core distribution prefix are proven; the entire core compiler pipeline is not reconstructed.",
"Runtime assets and public APIs unchanged; broader embedded origins, loader and localization remain open.",
"Selected Markdown filtering tests are not an exhaustive sanitizer audit.",
"Physical devices, external SDKs, remote CI, global release reviews and publication are not verified here.",
"Thumbnail default policy remains pending."
]
}
@@ -0,0 +1,28 @@
# Monaco core Markdown components
The site's unchanged Monaco 0.30.1 editor includes the following components from
VS Code commit 829382514cb1065f5ebb90f436e1c6103e153953. The original Monaco notices
remain in place; this supplement identifies missing or more precise information.
- DOMPurify 2.3.1, Copyright 2015 Mario Heiderich, Cure53 and other contributors.
[Complete original license](./DOMPurify-LICENSE). The upstream text offers a
choice of Apache 2.0 or MPL 2.0; both complete texts are retained verbatim.
Source: https://github.com/cure53/DOMPurify/tree/6cfcdf56269b892550af80baa7c1fa5b680e5db7
- marked 3.0.2, MarkedJS and Christopher Jeffrey.
[Original package license](./marked-LICENSE) and
[VS Code's retained older notice](./marked-vscode-license.txt).
Source: https://github.com/markedjs/marked/tree/d1b7d521c41bcf915f81f0218b0e5acd607c1b72
VS Code adapts DOMPurify's ESM export into an AMD factory and records alternative
ESM exports in comments. It adds commented ESM wrappers to marked. Monaco's build
assigns names to these two AMD definitions. The full adapted sources match their
fixed upstream Git files, the core archive's source map and development bundle.
The shipped editor retains the exact archived core code with its original
editor.main-to-edcore.main entry rename and appended language registrations.
ArtPlayer has not modified either component's runtime in this change.
The original Monaco notice omitted DOMPurify and used less precise marked
information. This supplement does not replace those original records or claim
that the entire Monaco core build, other embedded origins, or all sanitizer
behavior have been audited. Reproduction and browser regression instructions
are maintained in the repository's scripts/site-vendor/monaco/README.md.
@@ -0,0 +1,378 @@
DOMPurify
Copyright 2015 Mario Heiderich
DOMPurify is free software; you can redistribute it and/or modify it under the
terms of either:
a) the Apache License Version 2.0, or
b) the Mozilla Public License Version 2.0
-----------------------------------------------------------------------------
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-----------------------------------------------------------------------------
Mozilla Public License, version 2.0
1. Definitions
1.1. “Contributor”
means each individual or legal entity that creates, contributes to the
creation of, or owns Covered Software.
1.2. “Contributor Version”
means the combination of the Contributions of others (if any) used by a
Contributor and that particular Contributor’s Contribution.
1.3. “Contribution”
means Covered Software of a particular Contributor.
1.4. “Covered Software”
means Source Code Form to which the initial Contributor has attached the
notice in Exhibit A, the Executable Form of such Source Code Form, and
Modifications of such Source Code Form, in each case including portions
thereof.
1.5. “Incompatible With Secondary Licenses”
means
a. that the initial Contributor has attached the notice described in
Exhibit B to the Covered Software; or
b. that the Covered Software was made available under the terms of version
1.1 or earlier of the License, but not also under the terms of a
Secondary License.
1.6. “Executable Form”
means any form of the work other than Source Code Form.
1.7. “Larger Work”
means a work that combines Covered Software with other material, in a separate
file or files, that is not Covered Software.
1.8. “License”
means this document.
1.9. “Licensable”
means having the right to grant, to the maximum extent possible, whether at the
time of the initial grant or subsequently, any and all of the rights conveyed by
this License.
1.10. “Modifications”
means any of the following:
a. any file in Source Code Form that results from an addition to, deletion
from, or modification of the contents of Covered Software; or
b. any new file in Source Code Form that contains any Covered Software.
1.11. “Patent Claims” of a Contributor
means any patent claim(s), including without limitation, method, process,
and apparatus claims, in any patent Licensable by such Contributor that
would be infringed, but for the grant of the License, by the making,
using, selling, offering for sale, having made, import, or transfer of
either its Contributions or its Contributor Version.
1.12. “Secondary License”
means either the GNU General Public License, Version 2.0, the GNU Lesser
General Public License, Version 2.1, the GNU Affero General Public
License, Version 3.0, or any later versions of those licenses.
1.13. “Source Code Form”
means the form of the work preferred for making modifications.
1.14. “You” (or “Your”)
means an individual or a legal entity exercising rights under this
License. For legal entities, “You” includes any entity that controls, is
controlled by, or is under common control with You. For purposes of this
definition, “control” means (a) the power, direct or indirect, to cause
the direction or management of such entity, whether by contract or
otherwise, or (b) ownership of more than fifty percent (50%) of the
outstanding shares or beneficial ownership of such entity.
2. License Grants and Conditions
2.1. Grants
Each Contributor hereby grants You a world-wide, royalty-free,
non-exclusive license:
a. under intellectual property rights (other than patent or trademark)
Licensable by such Contributor to use, reproduce, make available,
modify, display, perform, distribute, and otherwise exploit its
Contributions, either on an unmodified basis, with Modifications, or as
part of a Larger Work; and
b. under Patent Claims of such Contributor to make, use, sell, offer for
sale, have made, import, and otherwise transfer either its Contributions
or its Contributor Version.
2.2. Effective Date
The licenses granted in Section 2.1 with respect to any Contribution become
effective for each Contribution on the date the Contributor first distributes
such Contribution.
2.3. Limitations on Grant Scope
The licenses granted in this Section 2 are the only rights granted under this
License. No additional rights or licenses will be implied from the distribution
or licensing of Covered Software under this License. Notwithstanding Section
2.1(b) above, no patent license is granted by a Contributor:
a. for any code that a Contributor has removed from Covered Software; or
b. for infringements caused by: (i) Your and any other third party’s
modifications of Covered Software, or (ii) the combination of its
Contributions with other software (except as part of its Contributor
Version); or
c. under Patent Claims infringed by Covered Software in the absence of its
Contributions.
This License does not grant any rights in the trademarks, service marks, or
logos of any Contributor (except as may be necessary to comply with the
notice requirements in Section 3.4).
2.4. Subsequent Licenses
No Contributor makes additional grants as a result of Your choice to
distribute the Covered Software under a subsequent version of this License
(see Section 10.2) or under the terms of a Secondary License (if permitted
under the terms of Section 3.3).
2.5. Representation
Each Contributor represents that the Contributor believes its Contributions
are its original creation(s) or it has sufficient rights to grant the
rights to its Contributions conveyed by this License.
2.6. Fair Use
This License is not intended to limit any rights You have under applicable
copyright doctrines of fair use, fair dealing, or other equivalents.
2.7. Conditions
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted in
Section 2.1.
3. Responsibilities
3.1. Distribution of Source Form
All distribution of Covered Software in Source Code Form, including any
Modifications that You create or to which You contribute, must be under the
terms of this License. You must inform recipients that the Source Code Form
of the Covered Software is governed by the terms of this License, and how
they can obtain a copy of this License. You may not attempt to alter or
restrict the recipients’ rights in the Source Code Form.
3.2. Distribution of Executable Form
If You distribute Covered Software in Executable Form then:
a. such Covered Software must also be made available in Source Code Form,
as described in Section 3.1, and You must inform recipients of the
Executable Form how they can obtain a copy of such Source Code Form by
reasonable means in a timely manner, at a charge no more than the cost
of distribution to the recipient; and
b. You may distribute such Executable Form under the terms of this License,
or sublicense it under different terms, provided that the license for
the Executable Form does not attempt to limit or alter the recipients’
rights in the Source Code Form under this License.
3.3. Distribution of a Larger Work
You may create and distribute a Larger Work under terms of Your choice,
provided that You also comply with the requirements of this License for the
Covered Software. If the Larger Work is a combination of Covered Software
with a work governed by one or more Secondary Licenses, and the Covered
Software is not Incompatible With Secondary Licenses, this License permits
You to additionally distribute such Covered Software under the terms of
such Secondary License(s), so that the recipient of the Larger Work may, at
their option, further distribute the Covered Software under the terms of
either this License or such Secondary License(s).
3.4. Notices
You may not remove or alter the substance of any license notices (including
copyright notices, patent notices, disclaimers of warranty, or limitations
of liability) contained within the Source Code Form of the Covered
Software, except that You may alter any license notices to the extent
required to remedy known factual inaccuracies.
3.5. Application of Additional Terms
You may choose to offer, and to charge a fee for, warranty, support,
indemnity or liability obligations to one or more recipients of Covered
Software. However, You may do so only on Your own behalf, and not on behalf
of any Contributor. You must make it absolutely clear that any such
warranty, support, indemnity, or liability obligation is offered by You
alone, and You hereby agree to indemnify every Contributor for any
liability incurred by such Contributor as a result of warranty, support,
indemnity or liability terms You offer. You may include additional
disclaimers of warranty and limitations of liability specific to any
jurisdiction.
4. Inability to Comply Due to Statute or Regulation
If it is impossible for You to comply with any of the terms of this License
with respect to some or all of the Covered Software due to statute, judicial
order, or regulation then You must: (a) comply with the terms of this License
to the maximum extent possible; and (b) describe the limitations and the code
they affect. Such description must be placed in a text file included with all
distributions of the Covered Software under this License. Except to the
extent prohibited by statute or regulation, such description must be
sufficiently detailed for a recipient of ordinary skill to be able to
understand it.
5. Termination
5.1. The rights granted under this License will terminate automatically if You
fail to comply with any of its terms. However, if You become compliant,
then the rights granted under this License from a particular Contributor
are reinstated (a) provisionally, unless and until such Contributor
explicitly and finally terminates Your grants, and (b) on an ongoing basis,
if such Contributor fails to notify You of the non-compliance by some
reasonable means prior to 60 days after You have come back into compliance.
Moreover, Your grants from a particular Contributor are reinstated on an
ongoing basis if such Contributor notifies You of the non-compliance by
some reasonable means, this is the first time You have received notice of
non-compliance with this License from such Contributor, and You become
compliant prior to 30 days after Your receipt of the notice.
5.2. If You initiate litigation against any entity by asserting a patent
infringement claim (excluding declaratory judgment actions, counter-claims,
and cross-claims) alleging that a Contributor Version directly or
indirectly infringes any patent, then the rights granted to You by any and
all Contributors for the Covered Software under Section 2.1 of this License
shall terminate.
5.3. In the event of termination under Sections 5.1 or 5.2 above, all end user
license agreements (excluding distributors and resellers) which have been
validly granted by You or Your distributors under this License prior to
termination shall survive termination.
6. Disclaimer of Warranty
Covered Software is provided under this License on an “as is” basis, without
warranty of any kind, either expressed, implied, or statutory, including,
without limitation, warranties that the Covered Software is free of defects,
merchantable, fit for a particular purpose or non-infringing. The entire
risk as to the quality and performance of the Covered Software is with You.
Should any Covered Software prove defective in any respect, You (not any
Contributor) assume the cost of any necessary servicing, repair, or
correction. This disclaimer of warranty constitutes an essential part of this
License. No use of any Covered Software is authorized under this License
except under this disclaimer.
7. Limitation of Liability
Under no circumstances and under no legal theory, whether tort (including
negligence), contract, or otherwise, shall any Contributor, or anyone who
distributes Covered Software as permitted above, be liable to You for any
direct, indirect, special, incidental, or consequential damages of any
character including, without limitation, damages for lost profits, loss of
goodwill, work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses, even if such party shall have been
informed of the possibility of such damages. This limitation of liability
shall not apply to liability for death or personal injury resulting from such
party’s negligence to the extent applicable law prohibits such limitation.
Some jurisdictions do not allow the exclusion or limitation of incidental or
consequential damages, so this exclusion and limitation may not apply to You.
8. Litigation
Any litigation relating to this License may be brought only in the courts of
a jurisdiction where the defendant maintains its principal place of business
and such litigation shall be governed by laws of that jurisdiction, without
reference to its conflict-of-law provisions. Nothing in this Section shall
prevent a party’s ability to bring cross-claims or counter-claims.
9. Miscellaneous
This License represents the complete agreement concerning the subject matter
hereof. If any provision of this License is held to be unenforceable, such
provision shall be reformed only to the extent necessary to make it
enforceable. Any law or regulation which provides that the language of a
contract shall be construed against the drafter shall not be used to construe
this License against a Contributor.
10. Versions of the License
10.1. New Versions
Mozilla Foundation is the license steward. Except as provided in Section
10.3, no one other than the license steward has the right to modify or
publish new versions of this License. Each version will be given a
distinguishing version number.
10.2. Effect of New Versions
You may distribute the Covered Software under the terms of the version of
the License under which You originally received the Covered Software, or
under the terms of any subsequent version published by the license
steward.
10.3. Modified Versions
If you create software not governed by this License, and you want to
create a new license for such software, you may create and use a modified
version of this License if you rename the license and remove any
references to the name of the license steward (except to note that such
modified license differs from this License).
10.4. Distributing Source Code Form that is Incompatible With Secondary Licenses
If You choose to distribute Source Code Form that is Incompatible With
Secondary Licenses under the terms of this version of the License, the
notice described in Exhibit B of this License must be attached.
Exhibit A - Source Code Form License Notice
This Source Code Form is subject to the
terms of the Mozilla Public License, v.
2.0. If a copy of the MPL was not
distributed with this file, You can
obtain one at
http://mozilla.org/MPL/2.0/.
If it is not possible or desirable to put the notice in a particular file, then
You may include the notice in a location (such as a LICENSE file in a relevant
directory) where a recipient would be likely to look for such a notice.
You may add additional accurate notices of copyright ownership.
Exhibit B - “Incompatible With Secondary Licenses” Notice
This Source Code Form is “Incompatible
With Secondary Licenses”, as defined by
the Mozilla Public License, v. 2.0.
@@ -0,0 +1,44 @@
# License information
## Contribution License Agreement
If you contribute code to this project, you are implicitly allowing your code
to be distributed under the MIT license. You are also implicitly verifying that
all code is your original work. `</legalese>`
## Marked
Copyright (c) 2018+, MarkedJS (https://github.com/markedjs/)
Copyright (c) 2011-2018, Christopher Jeffrey (https://github.com/chjj/)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
## Markdown
Copyright © 2004, John Gruber
http://daringfireball.net/
All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
* Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
* Neither the name “Markdown” nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.
This software is provided by the copyright holders and contributors “as is” and any express or implied warranties, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose are disclaimed. In no event shall the copyright owner or contributors be liable for any direct, indirect, incidental, special, exemplary, or consequential damages (including, but not limited to, procurement of substitute goods or services; loss of use, data, or profits; or business interruption) however caused and on any theory of liability, whether in contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use of this software, even if advised of the possibility of such damage.
@@ -0,0 +1,19 @@
Copyright (c) 2011-2014, Christopher Jeffrey (https://github.com/chjj/)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
@@ -0,0 +1,17 @@
{
"registrations": [
{
"component": {
"type": "git",
"git": {
"name": "dompurify",
"repositoryUrl": "https://github.com/cure53/DOMPurify",
"commitHash": "6cfcdf56269b892550af80baa7c1fa5b680e5db7"
}
},
"license": "Apache 2.0",
"version": "2.3.1"
}
],
"version": 1
}
@@ -0,0 +1,377 @@
DOMPurify
Copyright 2015 Mario Heiderich
DOMPurify is free software; you can redistribute it and/or modify it under the
terms of either:
a) the Apache License Version 2.0, or
b) the Mozilla Public License Version 2.0
-----------------------------------------------------------------------------
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-----------------------------------------------------------------------------
Mozilla Public License, version 2.0
1. Definitions
1.1. “Contributor”
means each individual or legal entity that creates, contributes to the
creation of, or owns Covered Software.
1.2. “Contributor Version”
means the combination of the Contributions of others (if any) used by a
Contributor and that particular Contributor’s Contribution.
1.3. “Contribution”
means Covered Software of a particular Contributor.
1.4. “Covered Software”
means Source Code Form to which the initial Contributor has attached the
notice in Exhibit A, the Executable Form of such Source Code Form, and
Modifications of such Source Code Form, in each case including portions
thereof.
1.5. “Incompatible With Secondary Licenses”
means
a. that the initial Contributor has attached the notice described in
Exhibit B to the Covered Software; or
b. that the Covered Software was made available under the terms of version
1.1 or earlier of the License, but not also under the terms of a
Secondary License.
1.6. “Executable Form”
means any form of the work other than Source Code Form.
1.7. “Larger Work”
means a work that combines Covered Software with other material, in a separate
file or files, that is not Covered Software.
1.8. “License”
means this document.
1.9. “Licensable”
means having the right to grant, to the maximum extent possible, whether at the
time of the initial grant or subsequently, any and all of the rights conveyed by
this License.
1.10. “Modifications”
means any of the following:
a. any file in Source Code Form that results from an addition to, deletion
from, or modification of the contents of Covered Software; or
b. any new file in Source Code Form that contains any Covered Software.
1.11. “Patent Claims” of a Contributor
means any patent claim(s), including without limitation, method, process,
and apparatus claims, in any patent Licensable by such Contributor that
would be infringed, but for the grant of the License, by the making,
using, selling, offering for sale, having made, import, or transfer of
either its Contributions or its Contributor Version.
1.12. “Secondary License”
means either the GNU General Public License, Version 2.0, the GNU Lesser
General Public License, Version 2.1, the GNU Affero General Public
License, Version 3.0, or any later versions of those licenses.
1.13. “Source Code Form”
means the form of the work preferred for making modifications.
1.14. “You” (or “Your”)
means an individual or a legal entity exercising rights under this
License. For legal entities, “You” includes any entity that controls, is
controlled by, or is under common control with You. For purposes of this
definition, “control” means (a) the power, direct or indirect, to cause
the direction or management of such entity, whether by contract or
otherwise, or (b) ownership of more than fifty percent (50%) of the
outstanding shares or beneficial ownership of such entity.
2. License Grants and Conditions
2.1. Grants
Each Contributor hereby grants You a world-wide, royalty-free,
non-exclusive license:
a. under intellectual property rights (other than patent or trademark)
Licensable by such Contributor to use, reproduce, make available,
modify, display, perform, distribute, and otherwise exploit its
Contributions, either on an unmodified basis, with Modifications, or as
part of a Larger Work; and
b. under Patent Claims of such Contributor to make, use, sell, offer for
sale, have made, import, and otherwise transfer either its Contributions
or its Contributor Version.
2.2. Effective Date
The licenses granted in Section 2.1 with respect to any Contribution become
effective for each Contribution on the date the Contributor first distributes
such Contribution.
2.3. Limitations on Grant Scope
The licenses granted in this Section 2 are the only rights granted under this
License. No additional rights or licenses will be implied from the distribution
or licensing of Covered Software under this License. Notwithstanding Section
2.1(b) above, no patent license is granted by a Contributor:
a. for any code that a Contributor has removed from Covered Software; or
b. for infringements caused by: (i) Your and any other third party’s
modifications of Covered Software, or (ii) the combination of its
Contributions with other software (except as part of its Contributor
Version); or
c. under Patent Claims infringed by Covered Software in the absence of its
Contributions.
This License does not grant any rights in the trademarks, service marks, or
logos of any Contributor (except as may be necessary to comply with the
notice requirements in Section 3.4).
2.4. Subsequent Licenses
No Contributor makes additional grants as a result of Your choice to
distribute the Covered Software under a subsequent version of this License
(see Section 10.2) or under the terms of a Secondary License (if permitted
under the terms of Section 3.3).
2.5. Representation
Each Contributor represents that the Contributor believes its Contributions
are its original creation(s) or it has sufficient rights to grant the
rights to its Contributions conveyed by this License.
2.6. Fair Use
This License is not intended to limit any rights You have under applicable
copyright doctrines of fair use, fair dealing, or other equivalents.
2.7. Conditions
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted in
Section 2.1.
3. Responsibilities
3.1. Distribution of Source Form
All distribution of Covered Software in Source Code Form, including any
Modifications that You create or to which You contribute, must be under the
terms of this License. You must inform recipients that the Source Code Form
of the Covered Software is governed by the terms of this License, and how
they can obtain a copy of this License. You may not attempt to alter or
restrict the recipients’ rights in the Source Code Form.
3.2. Distribution of Executable Form
If You distribute Covered Software in Executable Form then:
a. such Covered Software must also be made available in Source Code Form,
as described in Section 3.1, and You must inform recipients of the
Executable Form how they can obtain a copy of such Source Code Form by
reasonable means in a timely manner, at a charge no more than the cost
of distribution to the recipient; and
b. You may distribute such Executable Form under the terms of this License,
or sublicense it under different terms, provided that the license for
the Executable Form does not attempt to limit or alter the recipients’
rights in the Source Code Form under this License.
3.3. Distribution of a Larger Work
You may create and distribute a Larger Work under terms of Your choice,
provided that You also comply with the requirements of this License for the
Covered Software. If the Larger Work is a combination of Covered Software
with a work governed by one or more Secondary Licenses, and the Covered
Software is not Incompatible With Secondary Licenses, this License permits
You to additionally distribute such Covered Software under the terms of
such Secondary License(s), so that the recipient of the Larger Work may, at
their option, further distribute the Covered Software under the terms of
either this License or such Secondary License(s).
3.4. Notices
You may not remove or alter the substance of any license notices (including
copyright notices, patent notices, disclaimers of warranty, or limitations
of liability) contained within the Source Code Form of the Covered
Software, except that You may alter any license notices to the extent
required to remedy known factual inaccuracies.
3.5. Application of Additional Terms
You may choose to offer, and to charge a fee for, warranty, support,
indemnity or liability obligations to one or more recipients of Covered
Software. However, You may do so only on Your own behalf, and not on behalf
of any Contributor. You must make it absolutely clear that any such
warranty, support, indemnity, or liability obligation is offered by You
alone, and You hereby agree to indemnify every Contributor for any
liability incurred by such Contributor as a result of warranty, support,
indemnity or liability terms You offer. You may include additional
disclaimers of warranty and limitations of liability specific to any
jurisdiction.
4. Inability to Comply Due to Statute or Regulation
If it is impossible for You to comply with any of the terms of this License
with respect to some or all of the Covered Software due to statute, judicial
order, or regulation then You must: (a) comply with the terms of this License
to the maximum extent possible; and (b) describe the limitations and the code
they affect. Such description must be placed in a text file included with all
distributions of the Covered Software under this License. Except to the
extent prohibited by statute or regulation, such description must be
sufficiently detailed for a recipient of ordinary skill to be able to
understand it.
5. Termination
5.1. The rights granted under this License will terminate automatically if You
fail to comply with any of its terms. However, if You become compliant,
then the rights granted under this License from a particular Contributor
are reinstated (a) provisionally, unless and until such Contributor
explicitly and finally terminates Your grants, and (b) on an ongoing basis,
if such Contributor fails to notify You of the non-compliance by some
reasonable means prior to 60 days after You have come back into compliance.
Moreover, Your grants from a particular Contributor are reinstated on an
ongoing basis if such Contributor notifies You of the non-compliance by
some reasonable means, this is the first time You have received notice of
non-compliance with this License from such Contributor, and You become
compliant prior to 30 days after Your receipt of the notice.
5.2. If You initiate litigation against any entity by asserting a patent
infringement claim (excluding declaratory judgment actions, counter-claims,
and cross-claims) alleging that a Contributor Version directly or
indirectly infringes any patent, then the rights granted to You by any and
all Contributors for the Covered Software under Section 2.1 of this License
shall terminate.
5.3. In the event of termination under Sections 5.1 or 5.2 above, all end user
license agreements (excluding distributors and resellers) which have been
validly granted by You or Your distributors under this License prior to
termination shall survive termination.
6. Disclaimer of Warranty
Covered Software is provided under this License on an “as is” basis, without
warranty of any kind, either expressed, implied, or statutory, including,
without limitation, warranties that the Covered Software is free of defects,
merchantable, fit for a particular purpose or non-infringing. The entire
risk as to the quality and performance of the Covered Software is with You.
Should any Covered Software prove defective in any respect, You (not any
Contributor) assume the cost of any necessary servicing, repair, or
correction. This disclaimer of warranty constitutes an essential part of this
License. No use of any Covered Software is authorized under this License
except under this disclaimer.
7. Limitation of Liability
Under no circumstances and under no legal theory, whether tort (including
negligence), contract, or otherwise, shall any Contributor, or anyone who
distributes Covered Software as permitted above, be liable to You for any
direct, indirect, special, incidental, or consequential damages of any
character including, without limitation, damages for lost profits, loss of
goodwill, work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses, even if such party shall have been
informed of the possibility of such damages. This limitation of liability
shall not apply to liability for death or personal injury resulting from such
party’s negligence to the extent applicable law prohibits such limitation.
Some jurisdictions do not allow the exclusion or limitation of incidental or
consequential damages, so this exclusion and limitation may not apply to You.
8. Litigation
Any litigation relating to this License may be brought only in the courts of
a jurisdiction where the defendant maintains its principal place of business
and such litigation shall be governed by laws of that jurisdiction, without
reference to its conflict-of-law provisions. Nothing in this Section shall
prevent a party’s ability to bring cross-claims or counter-claims.
9. Miscellaneous
This License represents the complete agreement concerning the subject matter
hereof. If any provision of this License is held to be unenforceable, such
provision shall be reformed only to the extent necessary to make it
enforceable. Any law or regulation which provides that the language of a
contract shall be construed against the drafter shall not be used to construe
this License against a Contributor.
10. Versions of the License
10.1. New Versions
Mozilla Foundation is the license steward. Except as provided in Section
10.3, no one other than the license steward has the right to modify or
publish new versions of this License. Each version will be given a
distinguishing version number.
10.2. Effect of New Versions
You may distribute the Covered Software under the terms of the version of
the License under which You originally received the Covered Software, or
under the terms of any subsequent version published by the license
steward.
10.3. Modified Versions
If you create software not governed by this License, and you want to
create a new license for such software, you may create and use a modified
version of this License if you rename the license and remove any
references to the name of the license steward (except to note that such
modified license differs from this License).
10.4. Distributing Source Code Form that is Incompatible With Secondary Licenses
If You choose to distribute Source Code Form that is Incompatible With
Secondary Licenses under the terms of this version of the License, the
notice described in Exhibit B of this License must be attached.
Exhibit A - Source Code Form License Notice
This Source Code Form is subject to the
terms of the Mozilla Public License, v.
2.0. If a copy of the MPL was not
distributed with this file, You can
obtain one at
http://mozilla.org/MPL/2.0/.
If it is not possible or desirable to put the notice in a particular file, then
You may include the notice in a location (such as a LICENSE file in a relevant
directory) where a recipient would be likely to look for such a notice.
You may add additional accurate notices of copyright ownership.
Exhibit B - “Incompatible With Secondary Licenses” Notice
This Source Code Form is “Incompatible
With Secondary Licenses”, as defined by
the Mozilla Public License, v. 2.0.
@@ -0,0 +1,445 @@
/*---------------------------------------------------------------------------------------------
* Copyright (c) Microsoft Corporation. All rights reserved.
* Licensed under the MIT License. See License.txt in the project root for license information.
*--------------------------------------------------------------------------------------------*/
import * as DOM from 'vs/base/browser/dom';
import * as dompurify from 'vs/base/browser/dompurify/dompurify';
import { DomEmitter } from 'vs/base/browser/event';
import { createElement, FormattedTextRenderOptions } from 'vs/base/browser/formattedTextRenderer';
import { StandardMouseEvent } from 'vs/base/browser/mouseEvent';
import { renderLabelWithIcons } from 'vs/base/browser/ui/iconLabel/iconLabels';
import { raceCancellation } from 'vs/base/common/async';
import { CancellationTokenSource } from 'vs/base/common/cancellation';
import { onUnexpectedError } from 'vs/base/common/errors';
import { Event } from 'vs/base/common/event';
import { IMarkdownString, parseHrefAndDimensions, removeMarkdownEscapes } from 'vs/base/common/htmlContent';
import { markdownEscapeEscapedIcons } from 'vs/base/common/iconLabels';
import { defaultGenerator } from 'vs/base/common/idGenerator';
import { DisposableStore } from 'vs/base/common/lifecycle';
import * as marked from 'vs/base/common/marked/marked';
import { parse } from 'vs/base/common/marshalling';
import { FileAccess, Schemas } from 'vs/base/common/network';
import { cloneAndChange } from 'vs/base/common/objects';
import { resolvePath } from 'vs/base/common/resources';
import { escape } from 'vs/base/common/strings';
import { URI } from 'vs/base/common/uri';
export interface MarkedOptions extends marked.MarkedOptions {
baseUrl?: never;
}
export interface MarkdownRenderOptions extends FormattedTextRenderOptions {
codeBlockRenderer?: (languageId: string, value: string) => Promise<HTMLElement>;
asyncRenderCallback?: () => void;
baseUrl?: URI;
}
/**
* Low-level way create a html element from a markdown string.
*
* **Note** that for most cases you should be using [`MarkdownRenderer`](./src/vs/editor/browser/core/markdownRenderer.ts)
* which comes with support for pretty code block rendering and which uses the default way of handling links.
*/
export function renderMarkdown(markdown: IMarkdownString, options: MarkdownRenderOptions = {}, markedOptions: MarkedOptions = {}): { element: HTMLElement, dispose: () => void } {
const disposables = new DisposableStore();
let isDisposed = false;
const cts = disposables.add(new CancellationTokenSource());
const element = createElement(options);
const _uriMassage = function (part: string): string {
let data: any;
try {
data = parse(decodeURIComponent(part));
} catch (e) {
// ignore
}
if (!data) {
return part;
}
data = cloneAndChange(data, value => {
if (markdown.uris && markdown.uris[value]) {
return URI.revive(markdown.uris[value]);
} else {
return undefined;
}
});
return encodeURIComponent(JSON.stringify(data));
};
const _href = function (href: string, isDomUri: boolean): string {
const data = markdown.uris && markdown.uris[href];
if (!data) {
return href; // no uri exists
}
let uri = URI.revive(data);
if (isDomUri) {
if (href.startsWith(Schemas.data + ':')) {
return href;
}
// this URI will end up as "src"-attribute of a dom node
// and because of that special rewriting needs to be done
// so that the URI uses a protocol that's understood by
// browsers (like http or https)
return FileAccess.asBrowserUri(uri).toString(true);
}
if (URI.parse(href).toString() === uri.toString()) {
return href; // no transformation performed
}
if (uri.query) {
uri = uri.with({ query: _uriMassage(uri.query) });
}
return uri.toString();
};
// signal to code-block render that the
// element has been created
let signalInnerHTML: () => void;
const withInnerHTML = new Promise<void>(c => signalInnerHTML = c);
const renderer = new marked.Renderer();
renderer.image = (href: string, title: string, text: string) => {
let dimensions: string[] = [];
let attributes: string[] = [];
if (href) {
({ href, dimensions } = parseHrefAndDimensions(href));
href = _href(href, true);
try {
const hrefAsUri = URI.parse(href);
if (options.baseUrl && hrefAsUri.scheme === Schemas.file) { // absolute or relative local path, or file: uri
href = resolvePath(options.baseUrl, href).toString();
}
} catch (err) { }
attributes.push(`src="${href}"`);
}
if (text) {
attributes.push(`alt="${text}"`);
}
if (title) {
attributes.push(`title="${title}"`);
}
if (dimensions.length) {
attributes = attributes.concat(dimensions);
}
return '<img ' + attributes.join(' ') + '>';
};
renderer.link = (href, title, text): string => {
// Remove markdown escapes. Workaround for https://github.com/chjj/marked/issues/829
if (href === text) { // raw link case
text = removeMarkdownEscapes(text);
}
href = _href(href, false);
if (options.baseUrl) {
const hasScheme = /^\w[\w\d+.-]*:/.test(href);
if (!hasScheme) {
href = resolvePath(options.baseUrl, href).toString();
}
}
title = removeMarkdownEscapes(title);
href = removeMarkdownEscapes(href);
if (
!href
|| href.match(/^data:|javascript:/i)
|| (href.match(/^command:/i) && !markdown.isTrusted)
|| href.match(/^command:(\/\/\/)?_workbench\.downloadResource/i)
) {
// drop the link
return text;
} else {
// HTML Encode href
href = href.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
return `<a href="#" data-href="${href}" title="${title || href}">${text}</a>`;
}
};
renderer.paragraph = (text): string => {
return `<p>${text}</p>`;
};
if (options.codeBlockRenderer) {
renderer.code = (code, lang) => {
const value = options.codeBlockRenderer!(lang, code);
// when code-block rendering is async we return sync
// but update the node with the real result later.
const id = defaultGenerator.nextId();
raceCancellation(Promise.all([value, withInnerHTML]), cts.token).then(values => {
if (!isDisposed && values) {
const span = <HTMLDivElement>element.querySelector(`div[data-code="${id}"]`);
if (span) {
DOM.reset(span, values[0]);
}
options.asyncRenderCallback?.();
}
}).catch(() => {
// ignore
});
return `<div class="code" data-code="${id}">${escape(code)}</div>`;
};
}
if (options.actionHandler) {
const onClick = options.actionHandler.disposables.add(new DomEmitter(element, 'click'));
const onAuxClick = options.actionHandler.disposables.add(new DomEmitter(element, 'auxclick'));
options.actionHandler.disposables.add(Event.any(onClick.event, onAuxClick.event)(e => {
const mouseEvent = new StandardMouseEvent(e);
if (!mouseEvent.leftButton && !mouseEvent.middleButton) {
return;
}
let target: HTMLElement | null = mouseEvent.target;
if (target.tagName !== 'A') {
target = target.parentElement;
if (!target || target.tagName !== 'A') {
return;
}
}
try {
const href = target.dataset['href'];
if (href) {
options.actionHandler!.callback(href, mouseEvent);
}
} catch (err) {
onUnexpectedError(err);
} finally {
mouseEvent.preventDefault();
}
}));
}
if (!markdown.supportHtml) {
// TODO: Can we deprecated this in favor of 'supportHtml'?
// Use our own sanitizer so that we can let through only spans.
// Otherwise, we'd be letting all html be rendered.
// If we want to allow markdown permitted tags, then we can delete sanitizer and sanitize.
// We always pass the output through dompurify after this so that we don't rely on
// marked for sanitization.
markedOptions.sanitizer = (html: string): string => {
const match = markdown.isTrusted ? html.match(/^(<span[^>]+>)|(<\/\s*span>)$/) : undefined;
return match ? html : '';
};
markedOptions.sanitize = true;
markedOptions.silent = true;
}
markedOptions.renderer = renderer;
// values that are too long will freeze the UI
let value = markdown.value ?? '';
if (value.length > 100_000) {
value = `${value.substr(0, 100_000)}…`;
}
// escape theme icons
if (markdown.supportThemeIcons) {
value = markdownEscapeEscapedIcons(value);
}
let renderedMarkdown = marked.parse(value, markedOptions);
// Rewrite theme icons
if (markdown.supportThemeIcons) {
const elements = renderLabelWithIcons(renderedMarkdown);
renderedMarkdown = elements.map(e => typeof e === 'string' ? e : e.outerHTML).join('');
}
element.innerHTML = sanitizeRenderedMarkdown(markdown, renderedMarkdown) as unknown as string;
// signal that async code blocks can be now be inserted
signalInnerHTML!();
// signal size changes for image tags
if (options.asyncRenderCallback) {
for (const img of element.getElementsByTagName('img')) {
const listener = disposables.add(DOM.addDisposableListener(img, 'load', () => {
listener.dispose();
options.asyncRenderCallback!();
}));
}
}
return {
element,
dispose: () => {
isDisposed = true;
cts.cancel();
disposables.dispose();
}
};
}
function sanitizeRenderedMarkdown(
options: { isTrusted?: boolean },
renderedMarkdown: string,
): TrustedHTML {
const { config, allowedSchemes } = getSanitizerOptions(options);
dompurify.addHook('uponSanitizeAttribute', (element, e) => {
if (e.attrName === 'style' || e.attrName === 'class') {
if (element.tagName === 'SPAN') {
if (e.attrName === 'style') {
e.keepAttr = /^(color\:#[0-9a-fA-F]+;)?(background-color\:#[0-9a-fA-F]+;)?$/.test(e.attrValue);
return;
} else if (e.attrName === 'class') {
e.keepAttr = /^codicon codicon-[a-z\-]+( codicon-modifier-[a-z\-]+)?$/.test(e.attrValue);
return;
}
}
e.keepAttr = false;
return;
}
});
// build an anchor to map URLs to
const anchor = document.createElement('a');
// https://github.com/cure53/DOMPurify/blob/main/demos/hooks-scheme-allowlist.html
dompurify.addHook('afterSanitizeAttributes', (node) => {
// check all href/src attributes for validity
for (const attr of ['href', 'src']) {
if (node.hasAttribute(attr)) {
anchor.href = node.getAttribute(attr) as string;
if (!allowedSchemes.includes(anchor.protocol.replace(/:$/, ''))) {
node.removeAttribute(attr);
}
}
}
});
try {
return dompurify.sanitize(renderedMarkdown, { ...config, RETURN_TRUSTED_TYPE: true });
} finally {
dompurify.removeHook('uponSanitizeAttribute');
dompurify.removeHook('afterSanitizeAttributes');
}
}
function getSanitizerOptions(options: { readonly isTrusted?: boolean }): { config: dompurify.Config, allowedSchemes: string[] } {
const allowedSchemes = [
Schemas.http,
Schemas.https,
Schemas.mailto,
Schemas.data,
Schemas.file,
Schemas.vscodeFileResource,
Schemas.vscodeRemote,
Schemas.vscodeRemoteResource,
];
if (options.isTrusted) {
allowedSchemes.push(Schemas.command);
}
return {
config: {
// allowedTags should included everything that markdown renders to.
// Since we have our own sanitize function for marked, it's possible we missed some tag so let dompurify make sure.
// HTML tags that can result from markdown are from reading https://spec.commonmark.org/0.29/
// HTML table tags that can result from markdown are from https://github.github.com/gfm/#tables-extension-
ALLOWED_TAGS: ['ul', 'li', 'p', 'b', 'i', 'code', 'blockquote', 'ol', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'em', 'pre', 'table', 'thead', 'tbody', 'tr', 'th', 'td', 'div', 'del', 'a', 'strong', 'br', 'img', 'span'],
ALLOWED_ATTR: ['href', 'data-href', 'target', 'title', 'src', 'alt', 'class', 'style', 'data-code', 'width', 'height', 'align'],
ALLOW_UNKNOWN_PROTOCOLS: true,
},
allowedSchemes
};
}
/**
* Strips all markdown from `string`, if it's an IMarkdownString. For example
* `# Header` would be output as `Header`. If it's not, the string is returned.
*/
export function renderStringAsPlaintext(string: IMarkdownString | string) {
return typeof string === 'string' ? string : renderMarkdownAsPlaintext(string);
}
/**
* Strips all markdown from `markdown`. For example `# Header` would be output as `Header`.
*/
export function renderMarkdownAsPlaintext(markdown: IMarkdownString) {
const renderer = new marked.Renderer();
renderer.code = (code: string): string => {
return code;
};
renderer.blockquote = (quote: string): string => {
return quote;
};
renderer.html = (_html: string): string => {
return '';
};
renderer.heading = (text: string, _level: 1 | 2 | 3 | 4 | 5 | 6, _raw: string): string => {
return text + '\n';
};
renderer.hr = (): string => {
return '';
};
renderer.list = (body: string, _ordered: boolean): string => {
return body;
};
renderer.listitem = (text: string): string => {
return text + '\n';
};
renderer.paragraph = (text: string): string => {
return text + '\n';
};
renderer.table = (header: string, body: string): string => {
return header + body + '\n';
};
renderer.tablerow = (content: string): string => {
return content;
};
renderer.tablecell = (content: string, _flags: {
header: boolean;
align: 'center' | 'left' | 'right' | null;
}): string => {
return content + ' ';
};
renderer.strong = (text: string): string => {
return text;
};
renderer.em = (text: string): string => {
return text;
};
renderer.codespan = (code: string): string => {
return code;
};
renderer.br = (): string => {
return '\n';
};
renderer.del = (text: string): string => {
return text;
};
renderer.image = (_href: string, _title: string, _text: string): string => {
return '';
};
renderer.text = (text: string): string => {
return text;
};
renderer.link = (_href: string, _title: string, text: string): string => {
return text;
};
// values that are too long will freeze the UI
let value = markdown.value ?? '';
if (value.length > 100_000) {
value = `${value.substr(0, 100_000)}…`;
}
const unescapeInfo = new Map<string, string>([
['&quot;', '"'],
['&nbsp;', ' '],
['&amp;', '&'],
['&#39;', '\''],
['&lt;', '<'],
['&gt;', '>'],
]);
const html = marked.parse(value, { renderer }).replace(/&(#\d+|[a-zA-Z]+);/g, m => unescapeInfo.get(m) ?? m);
return sanitizeRenderedMarkdown({ isTrusted: false }, html).toString();
}
@@ -0,0 +1,17 @@
{
"registrations": [
{
"component": {
"type": "git",
"git": {
"name": "marked",
"repositoryUrl": "https://github.com/markedjs/marked",
"commitHash": "d1b7d521c41bcf915f81f0218b0e5acd607c1b72"
}
},
"license": "MIT",
"version": "3.0.2"
}
],
"version": 1
}
@@ -0,0 +1,44 @@
# SITE-07 Monaco 核心 Markdown 来源与许可补全
修改前 HEAD:426fee8faa7d4fe183fb3b5911d8b515f5f34bab。
## 实际发现和处理
核对 Monaco core 0.30.1 的原始 source map 和开发产物,发现 DOMPurify 2.3.1
未列入已交付的 Monaco ThirdPartyNotices。同一路径的 marked 版本由 VS Code
固定提交 829382514cb1065f5ebb90f436e1c6103e153953 的 cgmanifest 确认为 3.0.2,
并由完整源码匹配验证;不能仅凭相似代码选择其他 3.x 版本。
新增四个 npm 归档、七个固定 Git 文件的来源记录和可重跑脚本。npm DOMPurify
的 export 被替换为 AMD factory 及 ESM 注释;marked 增加 ESM 包装注释。明确的
适配边界再加 AMD 名称后,与 Git、source map 及开发产物中的完整片段精确相等。
两个片段分别为 52,931 / 95,547 字节。站点完整 editor.main.js 与原 Monaco
归档相等,其中 core 前缀及 source map 尾部与原 core 包相等。
这证明两个内嵌组件及现有 core 分发边界,不声称重新构建了整个 VS Code 编译
流水线。编辑器 core 的其他模块、loader、翻译及后续内嵌来源继续留在 SITE-07。
新增四份站点文件:DOMPurify 原始完整许可、marked npm 原始许可、VS Code 保留
的旧 marked 许可、版本与适配说明。DOMPurify 原文同时保留 Apache/MPL 两种
上游许可全文;VS Code 副本只比 npm 少一个末尾换行,脚本精确验证该差异,
分发完整 npm 字节。原 Monaco 第三方说明没有被改写或删去。
core-origins.ts 管理来源和 notice 绑定,普通站点生成前拒绝漏发、互换许可或
版本错误;完整复验另外验证归档、Git、npm 适配、source map 和产物边界。
新的 yarn verify:monaco-core-origins 支持离线与 --fetch,不安装新依赖、不改锁。
完整维护入口见 [Monaco README](../../scripts/site-vendor/monaco/README.md)。
## 验证和限制
- 四归档/七 Git 来源联网复验与离线复验均通过;生成及只读 notices 检查通过。
- 18/18 单元通过,含遗漏四份补充文件、错误许可绑定、重复适配边界等反例。
- 严格 docs-tools 类型检查和本批 lint 通过。
- 三引擎 Markdown 渲染检查表格、代码、链接、指定过滤行为和临时 hook 清理。
- 三引擎移动实际播放、日志、销毁及全站 85 份 notice HTTP 字节/说明链接通过。
两组共 6/6 浏览器测试,无跳过或重试;具体浏览器版本和诊断保留在
[验证记录](../baselines/monaco-core-origins-validation.json)。
上述用例不构成对 sanitizer 的穷尽安全审计,也不替代设备/外部 SDK/远端 CI/
全部站点内容/三轮复盘。SITE-07 doing / VENDOR-06 open,整体 199/265 不变。
Thumbnail 默认策略仍待用户决定。可独立回退本批脚本、基线、测试和新增 notices;
没有改播放器/编辑器运行产物或公开 API。独立本地提交,不推送、部署或发布。
+1 -1
View File
@@ -653,7 +653,7 @@
- SITE-AI-DOCS-01: [记录](changes/2026-09-14-SITE-AI-DOCS-01-documentation-pipeline.md) [记录](baselines/documentation-pipeline-validation.json)
- SITE-BUILD-01: [记录](changes/2026-09-14-SITE-BUILD-01-staged-builds.md) [记录](baselines/site-build-validation.json)
- SITE-03: [记录](changes/2026-09-14-SITE-03-desktop-editor.md) [记录](baselines/site-editor-validation.json)
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md) [记录](baselines/console-embedded-notices.json) [记录](baselines/console-notices-validation.json) [记录](changes/2026-09-15-SITE-07-console-notices.md) [记录](baselines/console-embedded-sources.json) [记录](baselines/console-embedded-validation.json) [记录](changes/2026-09-15-SITE-07-console-embedded-sources.md) [记录](baselines/console-derived-attribution.json) [记录](baselines/console-derived-validation.json) [记录](changes/2026-09-15-SITE-07-console-derived-attribution.md) [记录](baselines/console-stackoverflow-provenance.json) [记录](baselines/console-stackoverflow-validation.json) [记录](changes/2026-09-15-SITE-07-console-stackoverflow.md) [记录](baselines/console-shallowequal-validation.json) [记录](changes/2026-09-15-SITE-07-console-shallowequal.md) [记录](console-notice-review.md) [记录](baselines/console-notice-review-validation.json) [记录](changes/2026-09-15-SITE-07-console-notice-review.md) [记录](baselines/monaco-typescript-provenance.json) [记录](baselines/monaco-typescript-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-typescript.md) [记录](baselines/monaco-languages-provenance.json) [记录](baselines/monaco-languages-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-languages.md) [记录](baselines/monaco-language-notices.json) [记录](baselines/monaco-language-notices-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-language-notices.md) [记录](baselines/monaco-modes-provenance.json) [记录](baselines/monaco-modes-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-modes.md) [记录](baselines/monaco-basic-provenance.json) [记录](baselines/monaco-basic-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-basic.md)
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md) [记录](baselines/console-embedded-notices.json) [记录](baselines/console-notices-validation.json) [记录](changes/2026-09-15-SITE-07-console-notices.md) [记录](baselines/console-embedded-sources.json) [记录](baselines/console-embedded-validation.json) [记录](changes/2026-09-15-SITE-07-console-embedded-sources.md) [记录](baselines/console-derived-attribution.json) [记录](baselines/console-derived-validation.json) [记录](changes/2026-09-15-SITE-07-console-derived-attribution.md) [记录](baselines/console-stackoverflow-provenance.json) [记录](baselines/console-stackoverflow-validation.json) [记录](changes/2026-09-15-SITE-07-console-stackoverflow.md) [记录](baselines/console-shallowequal-validation.json) [记录](changes/2026-09-15-SITE-07-console-shallowequal.md) [记录](console-notice-review.md) [记录](baselines/console-notice-review-validation.json) [记录](changes/2026-09-15-SITE-07-console-notice-review.md) [记录](baselines/monaco-typescript-provenance.json) [记录](baselines/monaco-typescript-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-typescript.md) [记录](baselines/monaco-languages-provenance.json) [记录](baselines/monaco-languages-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-languages.md) [记录](baselines/monaco-language-notices.json) [记录](baselines/monaco-language-notices-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-language-notices.md) [记录](baselines/monaco-modes-provenance.json) [记录](baselines/monaco-modes-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-modes.md) [记录](baselines/monaco-basic-provenance.json) [记录](baselines/monaco-basic-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-basic.md) [记录](baselines/monaco-core-origins-provenance.json) [记录](baselines/monaco-core-origins-validation.json) [记录](changes/2026-09-15-SITE-07-monaco-core-origins.md)
- EX-01: [记录](changes/2026-09-14-EX-01-react-consumer.md) [记录](baselines/react-consumer-validation.json) [记录](scripts/react-consumer.mjs)
- EX-02: [记录](changes/2026-09-14-EX-02-vue-consumer.md) [记录](baselines/vue-consumer-validation.json) [记录](scripts/vue-consumer.mjs)
- MOD-01: [记录](changes/2026-09-15-MOD-01-bun-evaluation.md) [记录](baselines/bun-install-validation.json) [记录](bun-evaluation.md)
+9
View File
@@ -1,5 +1,14 @@
# 进度与证据
## SITE-07 Monaco Markdown 来源与遗漏许可
核实 DOMPurify 2.3.1 / marked 3.0.2 的固定来源及完整模块适配,发现并补齐
原 Monaco notice 未列出的 DOMPurify 许可。新增四份说明后全站 85 份 notice;
联网/离线来源验证、18/18 单元、严格类型/lint、三引擎 Markdown 与移动实播/
通知交付 6/6 通过,见[记录](changes/2026-09-15-SITE-07-monaco-core-origins.md)。
运行代码不变;其余 core/loader/翻译/内嵌来源仍需验证,SITE-07/VENDOR-06
开放、199/265,Thumbnail 默认策略仍待答。
## SITE-07 Monaco 基础语言
76 份语言源码与全部 76 个压缩文件精确复现,77 个模块实例;156 个归档成员有
+5 -2
View File
@@ -646,11 +646,14 @@
"scripts/site-vendor/monaco/reproduce-modes.ts",
"refactor/baselines/monaco-basic-provenance.json",
"refactor/baselines/monaco-basic-validation.json",
"refactor/changes/2026-09-15-SITE-07-monaco-basic.md"
"refactor/changes/2026-09-15-SITE-07-monaco-basic.md",
"refactor/baselines/monaco-core-origins-provenance.json",
"refactor/baselines/monaco-core-origins-validation.json",
"refactor/changes/2026-09-15-SITE-07-monaco-core-origins.md"
],
"compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.",
"closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。",
"workspaceState": "Monaco 0.30.1 TypeScript worker identifies 4.4.4, unlike the original stale 2.7.2 notice. Fixed Git lock/recipes and four archives prove the 9698327-character adapted service segment and exact minified worker. Three original TypeScript notices plus a version/modification explanation are delivered. Unit 10/10 and three-engine editor/notice checks 6/6 pass. Other language services, shim, core embedded libraries and language definitions remain under review; VENDOR-06 is open. CSS/HTML/JSON complete workers now have exact source coverage for 119 module instances from 91 npm sources, 8 aliases, a shared Monaco-owned nls shim and three adapters; 11 archives/13 Git sources and all three minified outputs match. Four unit tests and three real-engine diagnostics/completion/formatting checks pass. Service notices, embedded attribution, mode bundles, core and basic languages remain open. Seven language-service packages now deliver nine original notices, two complete formatter source headers and attribution. JSON glob BSD terms and the HTML formatter author-year difference are preserved. Component/source/notice bindings and all 81 site notice HTTP bytes/links pass; unit 14/14 and three-engine language/mobile suites 6/6. Broader Monaco origin review remains open. All four mode bundles now reproduce exactly from 14 Monaco sources, 6 npm modules and 2 aliases (26 instances), with 6 archives/23 Git files. jsonc-parser declarations drive const enum emission; mode assets are included in license bindings. Automatic editor diagnostics/formatting/model-switch/cleanup checks pass in three engines, unit 15/15 and all three worker source regressions pass. Core/basic-language and remaining origin review remain open. All 76 basic-language bundles now reproduce byte-for-byte from 76 original grammar sources (77 module instances). The pinned repository archive verifies 156 members; 2511 unchanged upstream token cases plus 12 explicit gap cases pass in three engines with all 76 URLs loaded. Unit 16/16 and strict type/lint checks pass. Core and remaining embedded origins are still open."
"workspaceState": "Monaco 0.30.1 remains byte-pinned (the known CSS newline-only difference is preserved). Codicons 0.0.26 and the actual TypeScript 4.4.4 worker have original notice supplements. CSS/HTML/JSON workers, four mode bundles and all 76 basic-language bundles reproduce exactly; 2511 upstream plus 12 supplemental tokenizer cases pass in three engines. DOMPurify 2.3.1 and marked 3.0.2 now have exact npm-to-Git/source-map/development adaptations; the missing DOMPurify terms and original/legacy marked licenses are delivered. All 85 site notices and attribution links pass three-engine HTTP/mobile playback checks; Markdown formatting/filtering/hook cleanup also passes. Latest unit 18/18, strict type/lint and four-archive/seven-Git offline/network checks pass. The complete core compiler pipeline, other core/loader/localization and further embedded origins remain open; this is not an exhaustive sanitizer audit or release approval."
},
{
"id": "VENDOR-07",
+9 -3
View File
@@ -1,14 +1,20 @@
# 文档站、示例与生成链清单
当前补充:Monaco 四种 mode 与 76 种基础语言的完整产物复现、三引擎语法验证
已完成。核心 Markdown 内嵌 DOMPurify 2.3.1 / marked 3.0.2 的固定来源和模块
适配已匹配;补齐四份说明后站点共交付 85 份 notice。核心其余源码与内嵌来源
仍开放,见[记录](changes/2026-09-15-SITE-07-monaco-core-origins.md)。下文较早的
未分发/未迁移描述保留为历史发现,不作为当前状态。
2026-09-15 Monaco 后续:CSS/HTML/JSON 完整 worker 已由固定源码和压缩配方复现,
七个依赖的九份原始许可、两个格式器署名和补充说明已实际交付。全站 81 份
notice 的 HTTP 字节、链接及三引擎功能检查通过,见
[记录](changes/2026-09-15-SITE-07-monaco-language-notices.md)。Monaco core/mode/
语言定义及其余来源细节仍开放,不能按本检查点认为整个站点已可发布。
console.js 后续已冻结 102 个模块和实际 React/ReactDOM/Parcel/返回组件契约;
三个浏览器复现卸载回调、多容器丢日志和 Error 消息丢失。源码尚未替换,依赖许可
仍开放;下一实现任务为 SITE-CONSOLE-01,见[迁移边界](console-modernization.md)。
console.js 的 102 个模块基线发现了卸载回调、多容器丢日志和 Error 消息丢失。
SITE-CONSOLE-01 已迁移自有 TS 入口和修复生命周期,100 个保留模块的来源与
47 份说明也已核对,见[当前维护入口](../scripts/site-vendor/console/README.md)。
2026-09-15后续:vConsole 3.15.0 已由固定源码/锁文件精确重建,补原始声明所引用的
MIT 正文和九个运行时组件的完整通知;VENDOR-07 关闭。三引擎真实播放/日志/销毁及
+4 -1
View File
@@ -4528,7 +4528,10 @@
"changes/2026-09-15-SITE-07-monaco-modes.md",
"baselines/monaco-basic-provenance.json",
"baselines/monaco-basic-validation.json",
"changes/2026-09-15-SITE-07-monaco-basic.md"
"changes/2026-09-15-SITE-07-monaco-basic.md",
"baselines/monaco-core-origins-provenance.json",
"baselines/monaco-core-origins-validation.json",
"changes/2026-09-15-SITE-07-monaco-core-origins.md"
]
},
{
+4
View File
@@ -2,6 +2,7 @@ import assert from 'node:assert/strict'
import fs from 'node:fs'
import process from 'node:process'
import { verifyConsoleNoticeSources } from './site-vendor/console/notices.ts'
import { verifyMonacoCoreNotices } from './site-vendor/monaco/core-origins.ts'
import { verifyMonacoLanguageNotices } from './site-vendor/monaco/notices.ts'
import { writeOrCheckNotices } from './site-vendor/notices.ts'
@@ -15,9 +16,11 @@ assert.deepEqual(manifest.groups.filter(group => group.name !== 'console').flatM
'copy-text-to-clipboard',
'core-js',
'css-loader',
'dompurify (Monaco core)',
'glob-to-regexp (Monaco JSON fork)',
'js-beautify (Monaco HTML embedded)',
'jsonc-parser',
'marked (Monaco core)',
'mutation-observer',
'regenerator-runtime',
'style-loader',
@@ -85,6 +88,7 @@ assert.deepEqual(typeScriptNotices?.map(target => target.split('/').pop()).sort(
for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md'])
assert(vconsoleNotices?.includes(`docs/licenses/vconsole/${name}`), `Missing vConsole notice: ${name}`)
verifyConsoleNoticeSources(process.cwd(), manifest)
verifyMonacoCoreNotices(process.cwd(), manifest)
verifyMonacoLanguageNotices(process.cwd(), manifest)
const count = writeOrCheckNotices(process.cwd(), manifest, process.argv.includes('--check'))
console.log(`Verified site notices: ${count} outputs; Monaco/vConsole/console inventories, embedded and other provenance gates remain open.`)
+7 -1
View File
@@ -22,7 +22,7 @@ files retain their exact upstream bytes, including final blank lines.
`../build-site-notices.mjs` provides `yarn build:site-notices` and read-only
`yarn check:site-notices`. The write command cannot bless altered vendor assets;
review the new archive and license evidence before changing the manifest. The
CLI prevents accidentally dropping any of the three groups, the eleven reviewed
CLI prevents accidentally dropping any of the three groups, the reviewed
Monaco/vConsole components, the 44 identified console components or their notice
count, and vConsole's original license, supplemental MIT body and attribution.
Component references require their runtime assets and every notice before writing.
@@ -73,3 +73,9 @@ Monaco's actual TypeScript 4.4.4 worker now has a separate source proof and noti
supplement; its original notice's 2.7.2 label is retained and explained. See
[Monaco maintenance](monaco/README.md) for the fixed six source adaptations,
minifier reconstruction, exact-byte checks and remaining component review scope.
Monaco's core Markdown path additionally identifies DOMPurify 2.3.1 and marked
3.0.2. Four supplemental files preserve DOMPurify's missing complete license,
marked's original and legacy notices, and module-adaptation attribution. Their
asset/source/notice bindings are checked before output writes; full source matching
and real renderer/HTTP tests are documented in `monaco/README.md`.
+45
View File
@@ -1000,6 +1000,26 @@
"source": "refactor/baselines/site-vendor/monaco-language-notices/ATTRIBUTION.txt",
"target": "docs/licenses/monaco-editor/language-services/ATTRIBUTION.md",
"sha256": "432cca135809edabcd9ccedd05576138b64b167445999005a6e1550132391d98"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/DOMPurify-LICENSE",
"target": "docs/licenses/monaco-editor/core-origins/DOMPurify-LICENSE",
"sha256": "8b6902e953e2eb2876412a4ba75291758b77e88e220962e3423af4d080db1a59"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/marked-LICENSE",
"target": "docs/licenses/monaco-editor/core-origins/marked-LICENSE",
"sha256": "8e3a3f82f59a60958f56ca08f445647c32a4733dc7ca6c2c46f6eb898471ab9c"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/marked-vscode-license.txt",
"target": "docs/licenses/monaco-editor/core-origins/marked-vscode-license.txt",
"sha256": "43624283832b560f19539ec6d5766b7281acd4a63ada62e494c4e63c7a849bdb"
},
{
"source": "refactor/baselines/site-vendor/monaco-core-origins/ATTRIBUTION.md",
"target": "docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md",
"sha256": "3a0ab7f1036d6b1397bf94ff2700375b97db2db3bd576d195dc6d8a88e1a758e"
}
],
"review": "The complete upstream Monaco LICENSE/ThirdPartyNotices are retained. The unmodified bundled Codicons font exactly matches @vscode/codicons 0.0.26; its historical README, CC BY 4.0 content license, MIT code license and added attribution are distributed below. Other site assets remain subject to their separate provenance reviews.",
@@ -1154,6 +1174,31 @@
"docs/licenses/monaco-editor/language-services/vscode-json-languageservice/LICENSE.md",
"docs/licenses/monaco-editor/language-services/ATTRIBUTION.md"
]
},
{
"name": "dompurify (Monaco core)",
"version": "2.3.1",
"tarball": "https://registry.npmjs.org/dompurify/-/dompurify-2.3.1.tgz",
"assets": [
"docs/assets/js/vs/editor/editor.main.js"
],
"notices": [
"docs/licenses/monaco-editor/core-origins/DOMPurify-LICENSE",
"docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md"
]
},
{
"name": "marked (Monaco core)",
"version": "3.0.2",
"tarball": "https://registry.npmjs.org/marked/-/marked-3.0.2.tgz",
"assets": [
"docs/assets/js/vs/editor/editor.main.js"
],
"notices": [
"docs/licenses/monaco-editor/core-origins/marked-LICENSE",
"docs/licenses/monaco-editor/core-origins/marked-vscode-license.txt",
"docs/licenses/monaco-editor/core-origins/ATTRIBUTION.md"
]
}
]
},
+33
View File
@@ -162,3 +162,36 @@ language definitions and remaining upstream data/origin details stay
under VENDOR-06. Revalidate editor-types and site-vendor tests when changing
declarations or delivered notices. Whole-site, physical-device and remote release
gates remain separate.
## Core Markdown origins
`core-origins.ts` keeps component/asset/license bindings separate from the full
source reproducer. The ordinary notice build rejects missing or swapped DOMPurify
and marked terms. `reproduce-core-origins.ts` verifies four npm archives and seven
fixed VS Code Git files. The original component registrations identify DOMPurify
2.3.1 and marked 3.0.2. Exact export/wrapper edits reproduce their Git sources;
named AMD forms match complete source-map entries and development-bundle spans.
The shipped editor matches the pinned Monaco archive and retains its core prefix
and map suffix. This is not a full reconstruction of the core compiler pipeline.
DOMPurify was missing from Monaco's supplied notice index. Its entire npm license
is now delivered, including both upstream license alternatives. VS Code's copy
differs by exactly one final newline; no body text is normalized or discarded.
marked's complete npm license and older VS Code license are both retained with an
explanation of the package versions and module adaptations. Four additional files
bring the site total to 85 notices plus the generated index.
```sh
yarn verify:monaco-core-origins --fetch
yarn verify:monaco-core-origins
yarn build:site-notices
yarn check:site-notices
yarn test:browser test/browser/editor-markdown.spec.js test/browser/site-vendor.spec.js --workers=1
```
The Markdown test loads the actual bundled parser/sanitizer and renderer. It checks
formatting, table cells, link targets, selected filtering behavior and removal of
temporary sanitizer hooks. The site test checks every delivered notice byte and
relative attribution link while exercising mobile playback/logging/disposal.
Neither is an exhaustive sanitizer audit. Loader, other core modules, localization,
and further embedded-origin details remain under SITE-07/VENDOR-06.
@@ -0,0 +1,45 @@
import type { VendorManifest } from '../notices.ts'
import type { Archive, Member, Remote } from './archives.ts'
import assert from 'node:assert/strict'
import fs from 'node:fs'
import path from 'node:path'
export interface CoreOrigins {
archives: Archive[]
remotes: Remote[]
members: Member[]
modules: (Member & { id: string, source: string, edits: { before: string, after: string }[], naming: { before: string, after: string } })[]
components: { name: string, version: string, tarball: string, assets: string[], notices: string[] }[]
notices: { source: string, target: string, sha256: string, archive?: string, member?: string }[]
target: { path: string, sha256: string }
}
export function readCoreOrigins(root: string): CoreOrigins {
return JSON.parse(fs.readFileSync(path.join(root, 'refactor/baselines/monaco-core-origins-provenance.json'), 'utf8'))
}
export function adaptCoreOrigin(source: string, edits: { before: string, after: string }[]): string {
for (const edit of edits) {
assert(edit.before && source.split(edit.before).length === 2, 'Missing or repeated core adaptation boundary')
source = source.replace(edit.before, () => edit.after)
}
return source
}
// Normal site builds enforce source/component/notice bindings without network.
export function verifyMonacoCoreNotices(root: string, manifest: VendorManifest): void {
const record = readCoreOrigins(root)
assert.deepEqual(record.components.map(item => item.name).sort(), ['dompurify (Monaco core)', 'marked (Monaco core)'])
assert.equal(record.notices.length, 4, 'Missing Monaco core notice source')
const group = manifest.groups.find(group => group.name === 'monaco-editor')
assert(group?.components, 'Missing Monaco core group')
for (const component of record.components) {
const archive = record.archives.find(archive => `${archive.name} (Monaco core)` === component.name)
assert(archive && component.version === archive.version && component.tarball === archive.tarball, 'Wrong Monaco core origin')
assert.deepEqual(component.assets, [record.target.path], 'Wrong Monaco core asset')
assert.deepEqual(group.components.filter(item => item.name === component.name), [component], 'Wrong Monaco core notice binding')
}
for (const notice of record.notices) {
assert.deepEqual(group.notices.filter(item => item.target === notice.target), [{ source: notice.source, target: notice.target, sha256: notice.sha256 }], 'Missing or changed Monaco core notice')
}
}
@@ -0,0 +1,59 @@
import assert from 'node:assert/strict'
import fs from 'node:fs'
import path from 'node:path'
import process from 'node:process'
import { fileURLToPath } from 'node:url'
import { ArchiveCache, hash } from './archives.ts'
import { adaptCoreOrigin, readCoreOrigins, verifyMonacoCoreNotices } from './core-origins.ts'
const root = fileURLToPath(new URL('../../../', import.meta.url))
assert(process.argv.slice(2).every(arg => arg === '--fetch'), 'Use reproduce-core-origins.ts [--fetch]')
assert.equal(process.version, `v${fs.readFileSync(path.join(root, '.node-version'), 'utf8').trim()}`, 'Use canonical Node')
const record = readCoreOrigins(root)
const cache = new ArchiveCache(root, path.join(root, 'refactor/.cache/monaco-review'))
await cache.verify(record.archives, record.remotes, process.argv.includes('--fetch'))
verifyMonacoCoreNotices(root, JSON.parse(fs.readFileSync(path.join(root, 'scripts/site-vendor/manifest.json'), 'utf8')))
for (const name of ['dompurify', 'marked']) {
const manifest = record.remotes.find(remote => remote.source.endsWith(`${name}-cgmanifest.json.txt`))
assert(manifest, 'Missing upstream component registration')
const registrations = JSON.parse(fs.readFileSync(path.join(root, manifest.source), 'utf8')).registrations
assert.equal(registrations.length, 1)
assert.equal(registrations[0].component.git.name, name)
assert.equal(registrations[0].version, record.archives.find(archive => archive.name === name)?.version, 'Upstream component version differs')
}
for (const member of record.members)
cache.member(member)
const sourceMap: { sources: string[], sourcesContent: string[] } = JSON.parse(cache.read('monaco-editor-core-0.30.1', 'package/dev/vs/editor/editor.main.js.map').toString('utf8'))
const development = cache.read('monaco-editor-core-0.30.1', 'package/dev/vs/editor/editor.main.js').toString('utf8')
const results = []
for (const module of record.modules) {
assert(record.remotes.some(remote => remote.source === module.source), 'Unverified embedded Git source')
const git = fs.readFileSync(path.join(root, module.source), 'utf8')
assert.equal(adaptCoreOrigin(cache.member(module).toString('utf8'), module.edits), git, 'Embedded npm adaptation differs')
const named = adaptCoreOrigin(git, [module.naming])
assert.equal(sourceMap.sourcesContent[sourceMap.sources.indexOf(`${module.id}.js`)], named, 'Embedded source map differs')
const offset = development.indexOf(named)
assert(offset >= 0 && development.lastIndexOf(named) === offset, 'Missing or repeated complete embedded source')
results.push({ id: module.id, bytes: named.length, offset, exactNpmAdaptation: true, exactGitAndDevelopment: true })
}
for (const notice of record.notices) {
const bytes = fs.readFileSync(path.join(root, notice.source))
assert.equal(hash(bytes), notice.sha256, 'Core notice changed')
if (notice.archive && notice.member)
assert.deepEqual(cache.read(notice.archive, notice.member), bytes, 'Original core notice differs')
}
const purifyNotice = record.remotes.find(remote => remote.source.endsWith('dompurify.license.txt.txt'))
assert(purifyNotice)
const originalLicense = cache.read('dompurify-2.3.1', 'package/LICENSE')
assert.equal(originalLicense.subarray(-2).toString(), '\n\n')
// VS Code drops exactly one final newline; distribute the complete npm bytes.
assert.deepEqual(fs.readFileSync(path.join(root, purifyNotice.source)), originalLicense.subarray(0, -1), 'DOMPurify upstream license differs')
const target = fs.readFileSync(path.join(root, record.target.path))
assert.equal(hash(target), record.target.sha256, 'Core site bytes changed')
assert.deepEqual(target, cache.read('monaco-editor-0.30.1', 'package/min/vs/editor/editor.main.js'), 'Site differs from pinned editor archive')
const core = cache.read('monaco-editor-core-0.30.1', 'package/min/vs/editor/editor.main.js').toString('utf8').replace('"vs/editor/editor.main"', '"vs/editor/edcore.main"')
const mapOffset = core.lastIndexOf('//# sourceMappingURL=')
assert(mapOffset > 0, 'Missing core source map boundary')
assert(target.toString('utf8').startsWith(core.slice(0, mapOffset)), 'Archived core prefix differs')
assert(target.toString('utf8').endsWith(core.slice(mapOffset)), 'Archived core map suffix differs')
console.log(JSON.stringify({ archives: record.archives.length, gitSources: record.remotes.length, modules: results, notices: record.notices.length, archivedCorePrefix: true, completeCoreBuild: false, otherEmbeddedOriginsReviewed: false }))
+5
View File
@@ -1,5 +1,10 @@
# Browser regression entry
`editor-markdown.spec.js` runs the bundled DOMPurify/marked renderer, verifies
formatting, selected filtering and temporary-hook cleanup. `site-vendor.spec.js`
also checks all 85 notice files and the core-origin attribution links over HTTP.
These checks do not constitute exhaustive sanitizer or physical-device validation.
`editor-modes.spec.js` exercises Monaco's actual automatic mode/provider registration
through a real editor. It switches CSS/JSON/TypeScript/HTML models, checks diagnostic
arrival/removal and document formatting, verifies all four mode bundle responses,
+46
View File
@@ -0,0 +1,46 @@
import { expect, test } from './fixtures.js'
test('docs Monaco renders Markdown with its bundled parser and sanitizer', async ({ page }, testInfo) => {
await page.goto('/test/player.html?core=candidate&chapter=published')
await page.addScriptTag({ url: '/assets/js/vs/loader.js' })
const result = await page.evaluate(async () => {
window.require.config({ paths: { vs: '/assets/js/vs' } })
const load = ids => new Promise((resolve, reject) => window.require(ids, (...modules) => resolve(modules), reject))
await load(['vs/editor/editor.main'])
const [renderer, purify] = await load(['vs/base/browser/markdownRenderer', 'vs/base/browser/dompurify/dompurify'])
const rendered = renderer.renderMarkdown({
value: '**Player** and `art.play()`\n\n| API | Result |\n| --- | --- |\n| play | Promise |\n\n[Docs](https://artplayer.org/document/)\n\n<span onclick="window.markdownExecuted=true">safe text</span><script>window.markdownExecuted=true</script>',
supportHtml: true,
isTrusted: false,
})
document.body.appendChild(rendered.element)
const element = rendered.element
const output = {
version: purify.version,
strong: element.querySelector('strong')?.textContent,
code: element.querySelector('code')?.textContent,
cells: [...element.querySelectorAll('td')].map(cell => cell.textContent),
link: element.querySelector('a')?.getAttribute('data-href'),
text: element.textContent,
scripts: element.querySelectorAll('script').length,
handlers: element.querySelectorAll('[onclick]').length,
executed: window.markdownExecuted === true,
}
rendered.dispose()
element.remove()
// Renderer hooks must not leak into a later consumer of the same singleton.
output.afterDispose = purify.sanitize('<div style="color:red">next</div>')
return output
})
await testInfo.attach('monaco-markdown-result', { contentType: 'application/json', body: JSON.stringify(result, null, 2) })
expect(result.version).toBe('2.3.1')
expect(result.strong).toBe('Player')
expect(result.code).toBe('art.play()')
expect(result.cells).toEqual(['play', 'Promise'])
expect(result.link).toBe('https://artplayer.org/document/')
expect(result.text).toContain('safe text')
expect(result.scripts).toBe(0)
expect(result.handlers).toBe(0)
expect(result.executed).toBe(false)
expect(result.afterDispose).toBe('<div style="color:red">next</div>')
})
+3
View File
@@ -24,6 +24,7 @@ test('mobile vConsole shows logs and upstream site notice texts are served uncha
for (const { path, count } of [
{ path: '/licenses/console/react-pure-render/ATTRIBUTION.md', count: 2 },
{ path: '/licenses/monaco-editor/language-services/ATTRIBUTION.md', count: 12 },
{ path: '/licenses/monaco-editor/core-origins/ATTRIBUTION.md', count: 3 },
]) {
const attribution = await request.get(path)
expect(attribution.status()).toBe(200)
@@ -41,6 +42,8 @@ test('mobile vConsole shows logs and upstream site notice texts are served uncha
expect(index.status()).toBe(200)
expect(await index.text()).toContain('Included component: @vscode/codicons 0.0.26')
expect(await index.text()).toContain('Included component: typescript (Monaco worker) 4.4.4')
expect(await index.text()).toContain('Included component: dompurify (Monaco core) 2.3.1')
expect(await index.text()).toContain('Included component: marked (Monaco core) 3.0.2')
expect(await index.text()).toContain('Included component: vscode-html-languageservice 4.1.1')
expect(await index.text()).toContain('Included component: vscode-json-languageservice 4.1.9')
expect(await index.text()).toContain('Included component: js-beautify (Monaco HTML embedded)')
+8
View File
@@ -4,9 +4,17 @@ import test from 'node:test'
import ts from 'typescript'
import { extractBasicFixtures } from '../scripts/site-vendor/monaco/basic-fixtures.ts'
import { emitAmd } from '../scripts/site-vendor/monaco/compiler.ts'
import { adaptCoreOrigin } from '../scripts/site-vendor/monaco/core-origins.ts'
import { aliasModule, moduleIds, nameModule, verifyWorkerSources } from '../scripts/site-vendor/monaco/languages.ts'
import { browserTypeScript, verifyTypeScriptSource } from '../scripts/site-vendor/monaco/typescript.ts'
test('Core origin adaptation rejects duplicate boundaries and preserves replacement bytes', () => {
const edits = [{ before: 'export default purify;', after: 'define(factory); // $&' }]
assert.equal(adaptCoreOrigin('export default purify;', edits), 'define(factory); // $&')
assert.throws(() => adaptCoreOrigin('missing', edits), /boundary/)
assert.throws(() => adaptCoreOrigin('export default purify;export default purify;', edits), /boundary/)
})
test('Monaco fixture extraction retains generated cases and preprocessing but rejects extra imports', () => {
const file = 'monaco-languages/src/scss/scss.test.ts'
const source = `import { testTokenization } from '../test/testRunner';
+18
View File
@@ -8,10 +8,28 @@ import process from 'node:process'
// eslint-disable-next-line test/no-import-node-test -- Verify real notice bytes and failure-before-write behavior.
import test from 'node:test'
import { verifyConsoleNoticeSources } from '../scripts/site-vendor/console/notices.ts'
import { verifyMonacoCoreNotices } from '../scripts/site-vendor/monaco/core-origins.ts'
import { verifyMonacoLanguageNoticeArchives, verifyMonacoLanguageNotices } from '../scripts/site-vendor/monaco/notices.ts'
import { generateNotices, writeOrCheckNotices } from '../scripts/site-vendor/notices.ts'
const hash = bytes => createHash('sha256').update(bytes).digest('hex')
test('Monaco core notices cannot replace DOMPurify terms with the Markdown parser license', () => {
const original = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
assert.doesNotThrow(() => verifyMonacoCoreNotices(process.cwd(), original))
const manifest = structuredClone(original)
const group = manifest.groups.find(group => group.name === 'monaco-editor')
group.components.find(item => item.name === 'dompurify (Monaco core)').notices = group.components.find(item => item.name === 'marked (Monaco core)').notices
assert.doesNotThrow(() => generateNotices(process.cwd(), manifest))
assert.throws(() => verifyMonacoCoreNotices(process.cwd(), manifest), /core notice binding/)
const record = JSON.parse(fs.readFileSync('refactor/baselines/monaco-core-origins-provenance.json', 'utf8'))
for (const notice of record.notices) {
const missing = structuredClone(original)
const group = missing.groups.find(group => group.name === 'monaco-editor')
group.notices = group.notices.filter(item => item.target !== notice.target)
assert.throws(() => verifyMonacoCoreNotices(process.cwd(), missing), /Monaco core notice/)
}
})
test('Monaco language notices bind full original terms to their actual worker sources', () => {
const original = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
assert.equal(verifyMonacoLanguageNotices(process.cwd(), original), 12)