diff --git a/.gitattributes b/.gitattributes index 1d876f217..c7d23ccb5 100644 --- a/.gitattributes +++ b/.gitattributes @@ -15,3 +15,10 @@ refactor/baselines/multiple-subtitles-vendor/* text eol=lf whitespace=-blank-at- refactor/baselines/site-vendor/*.txt text eol=lf whitespace=-blank-at-eof docs/licenses/** text eol=lf whitespace=-blank-at-eof docs/THIRD_PARTY_NOTICES.md text eol=lf + +# Preserve historical Codicons archive notice bytes, including CRLF. +refactor/baselines/site-vendor/codicons-0.0.26/LICENSE* -text whitespace=-trailing-space,cr-at-eol +refactor/baselines/site-vendor/codicons-0.0.26/README.txt -text whitespace=-trailing-space,cr-at-eol +docs/licenses/monaco-editor/codicons/LICENSE* -text whitespace=-trailing-space,cr-at-eol +docs/licenses/monaco-editor/codicons/README.md -text whitespace=-trailing-space,cr-at-eol +refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt text eol=lf diff --git a/docs/THIRD_PARTY_NOTICES.md b/docs/THIRD_PARTY_NOTICES.md index 27fd68e14..c18a3e331 100644 --- a/docs/THIRD_PARTY_NOTICES.md +++ b/docs/THIRD_PARTY_NOTICES.md @@ -16,7 +16,15 @@ The 3.15.0 upstream LICENSE declares MIT but omits the promised full license tex Source: https://registry.npmjs.org/monaco-editor/-/monaco-editor-0.30.1.tgz -The upstream Monaco LICENSE and ThirdPartyNotices are retained in full. The included codicon.ttf still needs matching Codicons version/attribution evidence; the Monaco package license alone does not close that font review. +The complete upstream Monaco LICENSE/ThirdPartyNotices are retained. The unmodified bundled Codicons font exactly matches @vscode/codicons 0.0.26; its historical README, CC BY 4.0 content license, MIT code license and added attribution are distributed below. Other site assets remain subject to their separate provenance reviews. + +Included component: @vscode/codicons 0.0.26 + +Source: https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz - licenses/monaco-editor/LICENSE - licenses/monaco-editor/ThirdPartyNotices.txt +- licenses/monaco-editor/codicons/LICENSE +- licenses/monaco-editor/codicons/LICENSE-CODE +- licenses/monaco-editor/codicons/README.md +- licenses/monaco-editor/codicons/ATTRIBUTION.md diff --git a/docs/licenses/monaco-editor/codicons/ATTRIBUTION.md b/docs/licenses/monaco-editor/codicons/ATTRIBUTION.md new file mode 100644 index 000000000..76be4cc4c --- /dev/null +++ b/docs/licenses/monaco-editor/codicons/ATTRIBUTION.md @@ -0,0 +1,17 @@ +# Codicons font attribution + +The unmodified Codicons font by Microsoft and contributors is included at +`/assets/js/vs/base/browser/ui/codicons/codicon/codicon.ttf`. +Its bytes match `@vscode/codicons@0.0.26`, published November 4, 2021. + +- [Original package archive](https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz) +- [Source revision](https://github.com/microsoft/vscode-codicons/tree/e4d1223d4145fe465db4930aae646ec0e45a4a87) +- [Original README and legal notices](README.md) +- Documentation and other content: [CC BY 4.0](LICENSE) +- Code: [MIT](LICENSE-CODE) + +The license split above is stated in this historical package's README. The font +is distributed unchanged; this attribution file was added by the ArtPlayer project. +The three upstream files alongside it are preserved byte for byte, including line endings. + +Font SHA-256: `ff6b888d65cfd8077d49c6c704c1bfc8f2ce1ed71db9c583c63e0a49f046c79c`. diff --git a/docs/licenses/monaco-editor/codicons/LICENSE b/docs/licenses/monaco-editor/codicons/LICENSE new file mode 100644 index 000000000..085c3ca0c --- /dev/null +++ b/docs/licenses/monaco-editor/codicons/LICENSE @@ -0,0 +1,395 @@ +Attribution 4.0 International + +======================================================================= + +Creative Commons Corporation ("Creative Commons") is not a law firm and +does not provide legal services or legal advice. Distribution of +Creative Commons public licenses does not create a lawyer-client or +other relationship. Creative Commons makes its licenses and related +information available on an "as-is" basis. Creative Commons gives no +warranties regarding its licenses, any material licensed under their +terms and conditions, or any related information. Creative Commons +disclaims all liability for damages resulting from their use to the +fullest extent possible. + +Using Creative Commons Public Licenses + +Creative Commons public licenses provide a standard set of terms and +conditions that creators and other rights holders may use to share +original works of authorship and other material subject to copyright +and certain other rights specified in the public license below. The +following considerations are for informational purposes only, are not +exhaustive, and do not form part of our licenses. + + Considerations for licensors: Our public licenses are + intended for use by those authorized to give the public + permission to use material in ways otherwise restricted by + copyright and certain other rights. Our licenses are + irrevocable. Licensors should read and understand the terms + and conditions of the license they choose before applying it. + Licensors should also secure all rights necessary before + applying our licenses so that the public can reuse the + material as expected. Licensors should clearly mark any + material not subject to the license. This includes other CC- + licensed material, or material used under an exception or + limitation to copyright. More considerations for licensors: + wiki.creativecommons.org/Considerations_for_licensors + + Considerations for the public: By using one of our public + licenses, a licensor grants the public permission to use the + licensed material under specified terms and conditions. If + the licensor's permission is not necessary for any reason--for + example, because of any applicable exception or limitation to + copyright--then that use is not regulated by the license. Our + licenses grant only permissions under copyright and certain + other rights that a licensor has authority to grant. Use of + the licensed material may still be restricted for other + reasons, including because others have copyright or other + rights in the material. A licensor may make special requests, + such as asking that all changes be marked or described. + Although not required by our licenses, you are encouraged to + respect those requests where reasonable. More_considerations + for the public: + wiki.creativecommons.org/Considerations_for_licensees + +======================================================================= + +Creative Commons Attribution 4.0 International Public License + +By exercising the Licensed Rights (defined below), You accept and agree +to be bound by the terms and conditions of this Creative Commons +Attribution 4.0 International Public License ("Public License"). To the +extent this Public License may be interpreted as a contract, You are +granted the Licensed Rights in consideration of Your acceptance of +these terms and conditions, and the Licensor grants You such rights in +consideration of benefits the Licensor receives from making the +Licensed Material available under these terms and conditions. + + +Section 1 -- Definitions. + + a. Adapted Material means material subject to Copyright and Similar + Rights that is derived from or based upon the Licensed Material + and in which the Licensed Material is translated, altered, + arranged, transformed, or otherwise modified in a manner requiring + permission under the Copyright and Similar Rights held by the + Licensor. For purposes of this Public License, where the Licensed + Material is a musical work, performance, or sound recording, + Adapted Material is always produced where the Licensed Material is + synched in timed relation with a moving image. + + b. Adapter's License means the license You apply to Your Copyright + and Similar Rights in Your contributions to Adapted Material in + accordance with the terms and conditions of this Public License. + + c. Copyright and Similar Rights means copyright and/or similar rights + closely related to copyright including, without limitation, + performance, broadcast, sound recording, and Sui Generis Database + Rights, without regard to how the rights are labeled or + categorized. For purposes of this Public License, the rights + specified in Section 2(b)(1)-(2) are not Copyright and Similar + Rights. + + d. Effective Technological Measures means those measures that, in the + absence of proper authority, may not be circumvented under laws + fulfilling obligations under Article 11 of the WIPO Copyright + Treaty adopted on December 20, 1996, and/or similar international + agreements. + + e. Exceptions and Limitations means fair use, fair dealing, and/or + any other exception or limitation to Copyright and Similar Rights + that applies to Your use of the Licensed Material. + + f. Licensed Material means the artistic or literary work, database, + or other material to which the Licensor applied this Public + License. + + g. Licensed Rights means the rights granted to You subject to the + terms and conditions of this Public License, which are limited to + all Copyright and Similar Rights that apply to Your use of the + Licensed Material and that the Licensor has authority to license. + + h. Licensor means the individual(s) or entity(ies) granting rights + under this Public License. + + i. Share means to provide material to the public by any means or + process that requires permission under the Licensed Rights, such + as reproduction, public display, public performance, distribution, + dissemination, communication, or importation, and to make material + available to the public including in ways that members of the + public may access the material from a place and at a time + individually chosen by them. + + j. Sui Generis Database Rights means rights other than copyright + resulting from Directive 96/9/EC of the European Parliament and of + the Council of 11 March 1996 on the legal protection of databases, + as amended and/or succeeded, as well as other essentially + equivalent rights anywhere in the world. + + k. You means the individual or entity exercising the Licensed Rights + under this Public License. Your has a corresponding meaning. + + +Section 2 -- Scope. + + a. License grant. + + 1. Subject to the terms and conditions of this Public License, + the Licensor hereby grants You a worldwide, royalty-free, + non-sublicensable, non-exclusive, irrevocable license to + exercise the Licensed Rights in the Licensed Material to: + + a. reproduce and Share the Licensed Material, in whole or + in part; and + + b. produce, reproduce, and Share Adapted Material. + + 2. Exceptions and Limitations. For the avoidance of doubt, where + Exceptions and Limitations apply to Your use, this Public + License does not apply, and You do not need to comply with + its terms and conditions. + + 3. Term. The term of this Public License is specified in Section + 6(a). + + 4. Media and formats; technical modifications allowed. The + Licensor authorizes You to exercise the Licensed Rights in + all media and formats whether now known or hereafter created, + and to make technical modifications necessary to do so. The + Licensor waives and/or agrees not to assert any right or + authority to forbid You from making technical modifications + necessary to exercise the Licensed Rights, including + technical modifications necessary to circumvent Effective + Technological Measures. For purposes of this Public License, + simply making modifications authorized by this Section 2(a) + (4) never produces Adapted Material. + + 5. Downstream recipients. + + a. Offer from the Licensor -- Licensed Material. Every + recipient of the Licensed Material automatically + receives an offer from the Licensor to exercise the + Licensed Rights under the terms and conditions of this + Public License. + + b. No downstream restrictions. You may not offer or impose + any additional or different terms or conditions on, or + apply any Effective Technological Measures to, the + Licensed Material if doing so restricts exercise of the + Licensed Rights by any recipient of the Licensed + Material. + + 6. No endorsement. Nothing in this Public License constitutes or + may be construed as permission to assert or imply that You + are, or that Your use of the Licensed Material is, connected + with, or sponsored, endorsed, or granted official status by, + the Licensor or others designated to receive attribution as + provided in Section 3(a)(1)(A)(i). + + b. Other rights. + + 1. Moral rights, such as the right of integrity, are not + licensed under this Public License, nor are publicity, + privacy, and/or other similar personality rights; however, to + the extent possible, the Licensor waives and/or agrees not to + assert any such rights held by the Licensor to the limited + extent necessary to allow You to exercise the Licensed + Rights, but not otherwise. + + 2. Patent and trademark rights are not licensed under this + Public License. + + 3. To the extent possible, the Licensor waives any right to + collect royalties from You for the exercise of the Licensed + Rights, whether directly or through a collecting society + under any voluntary or waivable statutory or compulsory + licensing scheme. In all other cases the Licensor expressly + reserves any right to collect such royalties. + + +Section 3 -- License Conditions. + +Your exercise of the Licensed Rights is expressly made subject to the +following conditions. + + a. Attribution. + + 1. If You Share the Licensed Material (including in modified + form), You must: + + a. retain the following if it is supplied by the Licensor + with the Licensed Material: + + i. identification of the creator(s) of the Licensed + Material and any others designated to receive + attribution, in any reasonable manner requested by + the Licensor (including by pseudonym if + designated); + + ii. a copyright notice; + + iii. a notice that refers to this Public License; + + iv. a notice that refers to the disclaimer of + warranties; + + v. a URI or hyperlink to the Licensed Material to the + extent reasonably practicable; + + b. indicate if You modified the Licensed Material and + retain an indication of any previous modifications; and + + c. indicate the Licensed Material is licensed under this + Public License, and include the text of, or the URI or + hyperlink to, this Public License. + + 2. You may satisfy the conditions in Section 3(a)(1) in any + reasonable manner based on the medium, means, and context in + which You Share the Licensed Material. For example, it may be + reasonable to satisfy the conditions by providing a URI or + hyperlink to a resource that includes the required + information. + + 3. If requested by the Licensor, You must remove any of the + information required by Section 3(a)(1)(A) to the extent + reasonably practicable. + + 4. If You Share Adapted Material You produce, the Adapter's + License You apply must not prevent recipients of the Adapted + Material from complying with this Public License. + + +Section 4 -- Sui Generis Database Rights. + +Where the Licensed Rights include Sui Generis Database Rights that +apply to Your use of the Licensed Material: + + a. for the avoidance of doubt, Section 2(a)(1) grants You the right + to extract, reuse, reproduce, and Share all or a substantial + portion of the contents of the database; + + b. if You include all or a substantial portion of the database + contents in a database in which You have Sui Generis Database + Rights, then the database in which You have Sui Generis Database + Rights (but not its individual contents) is Adapted Material; and + + c. You must comply with the conditions in Section 3(a) if You Share + all or a substantial portion of the contents of the database. + +For the avoidance of doubt, this Section 4 supplements and does not +replace Your obligations under this Public License where the Licensed +Rights include other Copyright and Similar Rights. + + +Section 5 -- Disclaimer of Warranties and Limitation of Liability. + + a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE + EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS + AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF + ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS, + IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION, + WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR + PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS, + ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT + KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT + ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU. + + b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE + TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION, + NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT, + INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES, + COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR + USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN + ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR + DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR + IN PART, THIS LIMITATION MAY NOT APPLY TO YOU. + + c. The disclaimer of warranties and limitation of liability provided + above shall be interpreted in a manner that, to the extent + possible, most closely approximates an absolute disclaimer and + waiver of all liability. + + +Section 6 -- Term and Termination. + + a. This Public License applies for the term of the Copyright and + Similar Rights licensed here. However, if You fail to comply with + this Public License, then Your rights under this Public License + terminate automatically. + + b. Where Your right to use the Licensed Material has terminated under + Section 6(a), it reinstates: + + 1. automatically as of the date the violation is cured, provided + it is cured within 30 days of Your discovery of the + violation; or + + 2. upon express reinstatement by the Licensor. + + For the avoidance of doubt, this Section 6(b) does not affect any + right the Licensor may have to seek remedies for Your violations + of this Public License. + + c. For the avoidance of doubt, the Licensor may also offer the + Licensed Material under separate terms or conditions or stop + distributing the Licensed Material at any time; however, doing so + will not terminate this Public License. + + d. Sections 1, 5, 6, 7, and 8 survive termination of this Public + License. + + +Section 7 -- Other Terms and Conditions. + + a. The Licensor shall not be bound by any additional or different + terms or conditions communicated by You unless expressly agreed. + + b. Any arrangements, understandings, or agreements regarding the + Licensed Material not stated herein are separate from and + independent of the terms and conditions of this Public License. + + +Section 8 -- Interpretation. + + a. For the avoidance of doubt, this Public License does not, and + shall not be interpreted to, reduce, limit, restrict, or impose + conditions on any use of the Licensed Material that could lawfully + be made without permission under this Public License. + + b. To the extent possible, if any provision of this Public License is + deemed unenforceable, it shall be automatically reformed to the + minimum extent necessary to make it enforceable. If the provision + cannot be reformed, it shall be severed from this Public License + without affecting the enforceability of the remaining terms and + conditions. + + c. No term or condition of this Public License will be waived and no + failure to comply consented to unless expressly agreed to by the + Licensor. + + d. Nothing in this Public License constitutes or may be interpreted + as a limitation upon, or waiver of, any privileges and immunities + that apply to the Licensor or You, including from the legal + processes of any jurisdiction or authority. + + +======================================================================= + +Creative Commons is not a party to its public +licenses. Notwithstanding, Creative Commons may elect to apply one of +its public licenses to material it publishes and in those instances +will be considered the “Licensor.” The text of the Creative Commons +public licenses is dedicated to the public domain under the CC0 Public +Domain Dedication. Except for the limited purpose of indicating that +material is shared under a Creative Commons public license or as +otherwise permitted by the Creative Commons policies published at +creativecommons.org/policies, Creative Commons does not authorize the +use of the trademark "Creative Commons" or any other trademark or logo +of Creative Commons without its prior written consent including, +without limitation, in connection with any unauthorized modifications +to any of its public licenses or any other arrangements, +understandings, or agreements concerning use of licensed material. For +the avoidance of doubt, this paragraph does not form part of the +public licenses. + +Creative Commons may be contacted at creativecommons.org. \ No newline at end of file diff --git a/docs/licenses/monaco-editor/codicons/LICENSE-CODE b/docs/licenses/monaco-editor/codicons/LICENSE-CODE new file mode 100644 index 000000000..3d8b93bc7 --- /dev/null +++ b/docs/licenses/monaco-editor/codicons/LICENSE-CODE @@ -0,0 +1,21 @@ + MIT License + + Copyright (c) Microsoft Corporation. + + Permission is hereby granted, free of charge, to any person obtaining a copy + of this software and associated documentation files (the "Software"), to deal + in the Software without restriction, including without limitation the rights + to use, copy, modify, merge, publish, distribute, sublicense, and/or sell + copies of the Software, and to permit persons to whom the Software is + furnished to do so, subject to the following conditions: + + The above copyright notice and this permission notice shall be included in all + copies or substantial portions of the Software. + + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE + SOFTWARE diff --git a/docs/licenses/monaco-editor/codicons/README.md b/docs/licenses/monaco-editor/codicons/README.md new file mode 100644 index 000000000..346a5e027 --- /dev/null +++ b/docs/licenses/monaco-editor/codicons/README.md @@ -0,0 +1,108 @@ +# Codicons + +[](https://www.npmjs.com/package/@vscode/codicons) +[](https://www.npmjs.com/package/@vscode/codicons) +[](https://github.com/microsoft/vscode-codicons/actions/workflows/build.yml) +[](https://github.com/microsoft/vscode-codicons/actions/workflows/build.yml) + + + +This tool takes the Visual Studio Code icons and converts them into an icon font using [fantasticon](https://github.com/tancredi/fantasticon). + +## Install +You can use the [npm package](https://www.npmjs.com/package/@vscode/codicons) and install into your project via: + +``` +npm i @vscode/codicons +``` + +_Note: We've deprecated `vscode-codicons` in favor of `@vscode/codicons`_ + +If you're building a VS Code extension, see this [webview extension sample](https://github.com/microsoft/vscode-extension-samples/tree/master/webview-codicons-sample) on how to integrate. + +# Building Locally + +All icons are stored under `src > icons`. The mappings of the class names and unicode characters are stored in `src/template/mapping.json` as well as the default styles under `src/template/styles.hbs`. + +## Install dependencies +After cloning this repo, install dependencies by running: + +``` +npm install +``` + +## Build + +``` +npm run build +``` + +Output will be exported to a `dist` folder. We track this folder so that we can see the updated changes to the unicode characters. + +## Update packages + +You can run `npm outdated` to see if there are any package updates. To update packages, run: + +``` +npm update +``` + +## Add icons + +Export your icons (svg) to the `src/icons` folder and add an entry into `src/template/mapping.json` with a new codepoint key (this gets converted into a unicode key) and run the the build command. The build command will also remove any subfolders in the `icons` folder to keep the folder structure consistent. + +Next, update the [codicons file](https://github.com/microsoft/vscode/blob/master/src/vs/base/common/codicons.ts) on the vscode repository, ensuring that the unicode characters are the same (you can reference the [css file](https://github.com/microsoft/vscode-codicons/blob/master/dist/codicon.css)). + + +## Using CSS Classes + +If you're building a VS Code extension, see this [webview extension sample](https://github.com/microsoft/vscode-extension-samples/tree/master/webview-codicons-sample) on how to integrate. + +When needing to reference an icon in the [Visual Studio Code source code](https://github.com/microsoft/vscode) via CSS classes, simply create a dom element/container that contains `codicon` and the [icon name](https://microsoft.github.io/vscode-codicons/dist/codicon.html) like: + +```html +
+``` + +It's recommended to use a single dom element for each icon and not to add children elements to it. + +## Using SVG Sprites + +When needing to use the `codicon.svg` sprite file, you can reference icons using the following method: + +```html + +``` + +# Contributing + +This project welcomes contributions and suggestions. Most contributions require you to agree to a +Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us +the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com. + +When you submit a pull request, a CLA bot will automatically determine whether you need to provide +a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions +provided by the bot. You will only need to do this once across all repos using our CLA. + +This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/). +For more information see the [Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/) or +contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with any additional questions or comments. + +# Legal Notices + +Microsoft and any contributors grant you a license to the Microsoft documentation and other content +in this repository under the [Creative Commons Attribution 4.0 International Public License](https://creativecommons.org/licenses/by/4.0/legalcode), +see the [LICENSE](LICENSE) file, and grant you a license to any code in the repository under the [MIT License](https://opensource.org/licenses/MIT), see the +[LICENSE-CODE](LICENSE-CODE) file. + +Microsoft, Windows, Microsoft Azure and/or other Microsoft products and services referenced in the documentation +may be either trademarks or registered trademarks of Microsoft in the United States and/or other countries. +The licenses for this project do not grant you rights to use any Microsoft names, logos, or trademarks. +Microsoft's general trademark guidelines can be found at http://go.microsoft.com/fwlink/?LinkID=254653. + +Privacy information can be found at https://privacy.microsoft.com/en-us/ + +Microsoft and any contributors reserve all other rights, whether under their respective copyrights, patents, +or trademarks, whether by implication, estoppel or otherwise. diff --git a/refactor/baselines/site-codicons-provenance.json b/refactor/baselines/site-codicons-provenance.json new file mode 100644 index 000000000..04758776a --- /dev/null +++ b/refactor/baselines/site-codicons-provenance.json @@ -0,0 +1,70 @@ +{ + "schemaVersion": 1, + "recordedAt": "2026-09-14T21:01:12.866Z", + "source": "Official npm registry tarballs; sha512 integrity and sha1 verified before reading members; SHA-256 and direct Buffer equality establish the font match. Pinned GitHub pages were unavailable through web browsing and are not the evidence basis.", + "package": "@vscode/codicons", + "fontPath": "docs/assets/js/vs/base/browser/ui/codicons/codicon/codicon.ttf", + "comparisons": [ + { + "version": "0.0.26", + "gitHead": "e4d1223d4145fe465db4930aae646ec0e45a4a87", + "published": "2021-11-04T18:10:09.013Z", + "tarball": "https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz", + "integrity": "sha512-GrYFJPbZ+hRM3NUVdAIpDepWkYCizVb13a6pJDAhckElDvaf4UCmNpuBS4MSydXNK63Ccts0XpvJ6JOW+/aU1g==", + "archiveSha256": "174dde2f6751999ed239ecc37cd25cb28d18f27d516594fd6221bb5b21e38c66", + "fontMember": "package/dist/codicon.ttf", + "fontSha256": "ff6b888d65cfd8077d49c6c704c1bfc8f2ce1ed71db9c583c63e0a49f046c79c", + "siteFontSha256": "ff6b888d65cfd8077d49c6c704c1bfc8f2ce1ed71db9c583c63e0a49f046c79c", + "exactMatch": true, + "noticeMembers": [ + "package/LICENSE", + "package/LICENSE-CODE", + "package/README.md" + ] + }, + { + "version": "0.0.25", + "gitHead": "4476b59e2764186d33b4d360f1d85f791df2d565", + "published": "2021-10-04T17:02:44.924Z", + "tarball": "https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.25.tgz", + "integrity": "sha512-uqPhTdADjwoCh5Ufbv0M6TZiiP2mqbfJVB4grhVx1k+YeP03LDMOHBWPsNwGKn4/0S5Mq9o1w1GeftvR031Gzg==", + "archiveSha256": "e9775cbf2d1fb972b55872657749a786397fb3299eee8e927e079841b13e21b5", + "fontMember": "package/dist/codicon.ttf", + "fontSha256": "d86f69b1b7b8c99ce1ce613286cbc226a4c7562dd90ec6c89dd2b55f639feb6e", + "siteFontSha256": "ff6b888d65cfd8077d49c6c704c1bfc8f2ce1ed71db9c583c63e0a49f046c79c", + "exactMatch": false, + "noticeMembers": [ + "package/LICENSE", + "package/LICENSE-CODE", + "package/README.md" + ] + } + ], + "notices": [ + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/LICENSE", + "target": "docs/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f", + "member": "package/LICENSE" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/LICENSE-CODE", + "target": "docs/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b", + "member": "package/LICENSE-CODE" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/README.txt", + "target": "docs/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689", + "member": "package/README.md" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt", + "target": "docs/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f", + "member": null + } + ], + "runtimeChanged": false +} diff --git a/refactor/baselines/site-codicons-validation.json b/refactor/baselines/site-codicons-validation.json new file mode 100644 index 000000000..a19d81b26 --- /dev/null +++ b/refactor/baselines/site-codicons-validation.json @@ -0,0 +1,278 @@ +{ + "schemaVersion": 1, + "task": "SITE-07", + "baseCommit": "a4234230e68cb74ea3bfe061e86449fced79eddd", + "node": "24.21.0", + "yarn": "1.22.22", + "browser": { + "command": "node node_modules/@playwright/test/cli.js test test/browser/site-vendor.spec.js test/browser/site-editor.spec.js --grep 'mobile vConsole|desktop TypeScript mode' --workers=1", + "exitCode": 0, + "reportPath": "refactor/.cache/site07-codicons-browser-report/report.json", + "reportSha256": "bda7191e7c528d5966a3b67bdb38422ea66bf597eb36db01c86a13277afc4fc3", + "stats": { + "startTime": "2026-09-14T21:02:17.295Z", + "duration": 22720.412999999997, + "expected": 6, + "skipped": 0, + "unexpected": 0, + "flaky": 0 + }, + "cases": [ + { + "title": "desktop TypeScript mode emits and runs typed code, Ctrl-S reruns and invalid syntax keeps the current player", + "project": "chromium", + "status": "passed", + "retry": 0, + "browser": "153.0.8010.12", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": null + }, + { + "title": "desktop TypeScript mode emits and runs typed code, Ctrl-S reruns and invalid syntax keeps the current player", + "project": "firefox", + "status": "passed", + "retry": 0, + "browser": "155.0", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": null + }, + { + "title": "desktop TypeScript mode emits and runs typed code, Ctrl-S reruns and invalid syntax keeps the current player", + "project": "webkit", + "status": "passed", + "retry": 0, + "browser": "26.6", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": null + }, + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "chromium", + "status": "passed", + "retry": 0, + "browser": "153.0.8010.12", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + }, + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "firefox", + "status": "passed", + "retry": 0, + "browser": "155.0", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + }, + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "webkit", + "status": "passed", + "retry": 0, + "browser": "26.6", + "platform": "win32", + "errors": [], + "core": { + "source": { + "kind": "workspace-build", + "entry": "packages\\artplayer\\src\\index.ts" + }, + "sha256": "5139cabd5abf9b92684ee2dcdaa620c4db7f67c0cb1aa3f654435d739468bf9d", + "bytes": 378931 + }, + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + } + ] + }, + "unit": { + "command": "node --test test/site-notices.test.js test/vconsole-lifecycle.test.js test/pages-artifact.test.js", + "exitCode": 0, + "passed": 16, + "durationMs": 470.0127, + "log": "refactor/.cache/site07-codicons-tests.log" + }, + "checks": [ + "strict docs-tools TypeScript", + "scoped source/test ESLint", + "build:site-notices", + "check:site-notices" + ], + "limitations": [ + "Source-built core; not a new full installed package run", + "Windows automated engines; not physical mobile or remote CI/Pages evidence", + "Codicons source/attribution gap addressed; broader site component notices and fonts/media remain under SITE-07" + ] +} diff --git a/refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt b/refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt new file mode 100644 index 000000000..76be4cc4c --- /dev/null +++ b/refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt @@ -0,0 +1,17 @@ +# Codicons font attribution + +The unmodified Codicons font by Microsoft and contributors is included at +`/assets/js/vs/base/browser/ui/codicons/codicon/codicon.ttf`. +Its bytes match `@vscode/codicons@0.0.26`, published November 4, 2021. + +- [Original package archive](https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz) +- [Source revision](https://github.com/microsoft/vscode-codicons/tree/e4d1223d4145fe465db4930aae646ec0e45a4a87) +- [Original README and legal notices](README.md) +- Documentation and other content: [CC BY 4.0](LICENSE) +- Code: [MIT](LICENSE-CODE) + +The license split above is stated in this historical package's README. The font +is distributed unchanged; this attribution file was added by the ArtPlayer project. +The three upstream files alongside it are preserved byte for byte, including line endings. + +Font SHA-256: `ff6b888d65cfd8077d49c6c704c1bfc8f2ce1ed71db9c583c63e0a49f046c79c`. diff --git a/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE b/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE new file mode 100644 index 000000000..085c3ca0c --- /dev/null +++ b/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE @@ -0,0 +1,395 @@ +Attribution 4.0 International + +======================================================================= + +Creative Commons Corporation ("Creative Commons") is not a law firm and +does not provide legal services or legal advice. Distribution of +Creative Commons public licenses does not create a lawyer-client or +other relationship. Creative Commons makes its licenses and related +information available on an "as-is" basis. Creative Commons gives no +warranties regarding its licenses, any material licensed under their +terms and conditions, or any related information. Creative Commons +disclaims all liability for damages resulting from their use to the +fullest extent possible. + +Using Creative Commons Public Licenses + +Creative Commons public licenses provide a standard set of terms and +conditions that creators and other rights holders may use to share +original works of authorship and other material subject to copyright +and certain other rights specified in the public license below. The +following considerations are for informational purposes only, are not +exhaustive, and do not form part of our licenses. + + Considerations for licensors: Our public licenses are + intended for use by those authorized to give the public + permission to use material in ways otherwise restricted by + copyright and certain other rights. Our licenses are + irrevocable. Licensors should read and understand the terms + and conditions of the license they choose before applying it. + Licensors should also secure all rights necessary before + applying our licenses so that the public can reuse the + material as expected. Licensors should clearly mark any + material not subject to the license. This includes other CC- + licensed material, or material used under an exception or + limitation to copyright. More considerations for licensors: + wiki.creativecommons.org/Considerations_for_licensors + + Considerations for the public: By using one of our public + licenses, a licensor grants the public permission to use the + licensed material under specified terms and conditions. If + the licensor's permission is not necessary for any reason--for + example, because of any applicable exception or limitation to + copyright--then that use is not regulated by the license. Our + licenses grant only permissions under copyright and certain + other rights that a licensor has authority to grant. Use of + the licensed material may still be restricted for other + reasons, including because others have copyright or other + rights in the material. A licensor may make special requests, + such as asking that all changes be marked or described. + Although not required by our licenses, you are encouraged to + respect those requests where reasonable. More_considerations + for the public: + wiki.creativecommons.org/Considerations_for_licensees + +======================================================================= + +Creative Commons Attribution 4.0 International Public License + +By exercising the Licensed Rights (defined below), You accept and agree +to be bound by the terms and conditions of this Creative Commons +Attribution 4.0 International Public License ("Public License"). To the +extent this Public License may be interpreted as a contract, You are +granted the Licensed Rights in consideration of Your acceptance of +these terms and conditions, and the Licensor grants You such rights in +consideration of benefits the Licensor receives from making the +Licensed Material available under these terms and conditions. + + +Section 1 -- Definitions. + + a. Adapted Material means material subject to Copyright and Similar + Rights that is derived from or based upon the Licensed Material + and in which the Licensed Material is translated, altered, + arranged, transformed, or otherwise modified in a manner requiring + permission under the Copyright and Similar Rights held by the + Licensor. For purposes of this Public License, where the Licensed + Material is a musical work, performance, or sound recording, + Adapted Material is always produced where the Licensed Material is + synched in timed relation with a moving image. + + b. Adapter's License means the license You apply to Your Copyright + and Similar Rights in Your contributions to Adapted Material in + accordance with the terms and conditions of this Public License. + + c. Copyright and Similar Rights means copyright and/or similar rights + closely related to copyright including, without limitation, + performance, broadcast, sound recording, and Sui Generis Database + Rights, without regard to how the rights are labeled or + categorized. For purposes of this Public License, the rights + specified in Section 2(b)(1)-(2) are not Copyright and Similar + Rights. + + d. Effective Technological Measures means those measures that, in the + absence of proper authority, may not be circumvented under laws + fulfilling obligations under Article 11 of the WIPO Copyright + Treaty adopted on December 20, 1996, and/or similar international + agreements. + + e. Exceptions and Limitations means fair use, fair dealing, and/or + any other exception or limitation to Copyright and Similar Rights + that applies to Your use of the Licensed Material. + + f. Licensed Material means the artistic or literary work, database, + or other material to which the Licensor applied this Public + License. + + g. Licensed Rights means the rights granted to You subject to the + terms and conditions of this Public License, which are limited to + all Copyright and Similar Rights that apply to Your use of the + Licensed Material and that the Licensor has authority to license. + + h. Licensor means the individual(s) or entity(ies) granting rights + under this Public License. + + i. Share means to provide material to the public by any means or + process that requires permission under the Licensed Rights, such + as reproduction, public display, public performance, distribution, + dissemination, communication, or importation, and to make material + available to the public including in ways that members of the + public may access the material from a place and at a time + individually chosen by them. + + j. Sui Generis Database Rights means rights other than copyright + resulting from Directive 96/9/EC of the European Parliament and of + the Council of 11 March 1996 on the legal protection of databases, + as amended and/or succeeded, as well as other essentially + equivalent rights anywhere in the world. + + k. You means the individual or entity exercising the Licensed Rights + under this Public License. Your has a corresponding meaning. + + +Section 2 -- Scope. + + a. License grant. + + 1. Subject to the terms and conditions of this Public License, + the Licensor hereby grants You a worldwide, royalty-free, + non-sublicensable, non-exclusive, irrevocable license to + exercise the Licensed Rights in the Licensed Material to: + + a. reproduce and Share the Licensed Material, in whole or + in part; and + + b. produce, reproduce, and Share Adapted Material. + + 2. Exceptions and Limitations. For the avoidance of doubt, where + Exceptions and Limitations apply to Your use, this Public + License does not apply, and You do not need to comply with + its terms and conditions. + + 3. Term. The term of this Public License is specified in Section + 6(a). + + 4. Media and formats; technical modifications allowed. The + Licensor authorizes You to exercise the Licensed Rights in + all media and formats whether now known or hereafter created, + and to make technical modifications necessary to do so. The + Licensor waives and/or agrees not to assert any right or + authority to forbid You from making technical modifications + necessary to exercise the Licensed Rights, including + technical modifications necessary to circumvent Effective + Technological Measures. For purposes of this Public License, + simply making modifications authorized by this Section 2(a) + (4) never produces Adapted Material. + + 5. Downstream recipients. + + a. Offer from the Licensor -- Licensed Material. Every + recipient of the Licensed Material automatically + receives an offer from the Licensor to exercise the + Licensed Rights under the terms and conditions of this + Public License. + + b. No downstream restrictions. You may not offer or impose + any additional or different terms or conditions on, or + apply any Effective Technological Measures to, the + Licensed Material if doing so restricts exercise of the + Licensed Rights by any recipient of the Licensed + Material. + + 6. No endorsement. Nothing in this Public License constitutes or + may be construed as permission to assert or imply that You + are, or that Your use of the Licensed Material is, connected + with, or sponsored, endorsed, or granted official status by, + the Licensor or others designated to receive attribution as + provided in Section 3(a)(1)(A)(i). + + b. Other rights. + + 1. Moral rights, such as the right of integrity, are not + licensed under this Public License, nor are publicity, + privacy, and/or other similar personality rights; however, to + the extent possible, the Licensor waives and/or agrees not to + assert any such rights held by the Licensor to the limited + extent necessary to allow You to exercise the Licensed + Rights, but not otherwise. + + 2. Patent and trademark rights are not licensed under this + Public License. + + 3. To the extent possible, the Licensor waives any right to + collect royalties from You for the exercise of the Licensed + Rights, whether directly or through a collecting society + under any voluntary or waivable statutory or compulsory + licensing scheme. In all other cases the Licensor expressly + reserves any right to collect such royalties. + + +Section 3 -- License Conditions. + +Your exercise of the Licensed Rights is expressly made subject to the +following conditions. + + a. Attribution. + + 1. If You Share the Licensed Material (including in modified + form), You must: + + a. retain the following if it is supplied by the Licensor + with the Licensed Material: + + i. identification of the creator(s) of the Licensed + Material and any others designated to receive + attribution, in any reasonable manner requested by + the Licensor (including by pseudonym if + designated); + + ii. a copyright notice; + + iii. a notice that refers to this Public License; + + iv. a notice that refers to the disclaimer of + warranties; + + v. a URI or hyperlink to the Licensed Material to the + extent reasonably practicable; + + b. indicate if You modified the Licensed Material and + retain an indication of any previous modifications; and + + c. indicate the Licensed Material is licensed under this + Public License, and include the text of, or the URI or + hyperlink to, this Public License. + + 2. You may satisfy the conditions in Section 3(a)(1) in any + reasonable manner based on the medium, means, and context in + which You Share the Licensed Material. For example, it may be + reasonable to satisfy the conditions by providing a URI or + hyperlink to a resource that includes the required + information. + + 3. If requested by the Licensor, You must remove any of the + information required by Section 3(a)(1)(A) to the extent + reasonably practicable. + + 4. If You Share Adapted Material You produce, the Adapter's + License You apply must not prevent recipients of the Adapted + Material from complying with this Public License. + + +Section 4 -- Sui Generis Database Rights. + +Where the Licensed Rights include Sui Generis Database Rights that +apply to Your use of the Licensed Material: + + a. for the avoidance of doubt, Section 2(a)(1) grants You the right + to extract, reuse, reproduce, and Share all or a substantial + portion of the contents of the database; + + b. if You include all or a substantial portion of the database + contents in a database in which You have Sui Generis Database + Rights, then the database in which You have Sui Generis Database + Rights (but not its individual contents) is Adapted Material; and + + c. You must comply with the conditions in Section 3(a) if You Share + all or a substantial portion of the contents of the database. + +For the avoidance of doubt, this Section 4 supplements and does not +replace Your obligations under this Public License where the Licensed +Rights include other Copyright and Similar Rights. + + +Section 5 -- Disclaimer of Warranties and Limitation of Liability. + + a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE + EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS + AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF + ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS, + IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION, + WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR + PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS, + ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT + KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT + ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU. + + b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE + TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION, + NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT, + INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES, + COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR + USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN + ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR + DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR + IN PART, THIS LIMITATION MAY NOT APPLY TO YOU. + + c. The disclaimer of warranties and limitation of liability provided + above shall be interpreted in a manner that, to the extent + possible, most closely approximates an absolute disclaimer and + waiver of all liability. + + +Section 6 -- Term and Termination. + + a. This Public License applies for the term of the Copyright and + Similar Rights licensed here. However, if You fail to comply with + this Public License, then Your rights under this Public License + terminate automatically. + + b. Where Your right to use the Licensed Material has terminated under + Section 6(a), it reinstates: + + 1. automatically as of the date the violation is cured, provided + it is cured within 30 days of Your discovery of the + violation; or + + 2. upon express reinstatement by the Licensor. + + For the avoidance of doubt, this Section 6(b) does not affect any + right the Licensor may have to seek remedies for Your violations + of this Public License. + + c. For the avoidance of doubt, the Licensor may also offer the + Licensed Material under separate terms or conditions or stop + distributing the Licensed Material at any time; however, doing so + will not terminate this Public License. + + d. Sections 1, 5, 6, 7, and 8 survive termination of this Public + License. + + +Section 7 -- Other Terms and Conditions. + + a. The Licensor shall not be bound by any additional or different + terms or conditions communicated by You unless expressly agreed. + + b. Any arrangements, understandings, or agreements regarding the + Licensed Material not stated herein are separate from and + independent of the terms and conditions of this Public License. + + +Section 8 -- Interpretation. + + a. For the avoidance of doubt, this Public License does not, and + shall not be interpreted to, reduce, limit, restrict, or impose + conditions on any use of the Licensed Material that could lawfully + be made without permission under this Public License. + + b. To the extent possible, if any provision of this Public License is + deemed unenforceable, it shall be automatically reformed to the + minimum extent necessary to make it enforceable. If the provision + cannot be reformed, it shall be severed from this Public License + without affecting the enforceability of the remaining terms and + conditions. + + c. No term or condition of this Public License will be waived and no + failure to comply consented to unless expressly agreed to by the + Licensor. + + d. Nothing in this Public License constitutes or may be interpreted + as a limitation upon, or waiver of, any privileges and immunities + that apply to the Licensor or You, including from the legal + processes of any jurisdiction or authority. + + +======================================================================= + +Creative Commons is not a party to its public +licenses. Notwithstanding, Creative Commons may elect to apply one of +its public licenses to material it publishes and in those instances +will be considered the “Licensor.” The text of the Creative Commons +public licenses is dedicated to the public domain under the CC0 Public +Domain Dedication. Except for the limited purpose of indicating that +material is shared under a Creative Commons public license or as +otherwise permitted by the Creative Commons policies published at +creativecommons.org/policies, Creative Commons does not authorize the +use of the trademark "Creative Commons" or any other trademark or logo +of Creative Commons without its prior written consent including, +without limitation, in connection with any unauthorized modifications +to any of its public licenses or any other arrangements, +understandings, or agreements concerning use of licensed material. For +the avoidance of doubt, this paragraph does not form part of the +public licenses. + +Creative Commons may be contacted at creativecommons.org. \ No newline at end of file diff --git a/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE-CODE b/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE-CODE new file mode 100644 index 000000000..3d8b93bc7 --- /dev/null +++ b/refactor/baselines/site-vendor/codicons-0.0.26/LICENSE-CODE @@ -0,0 +1,21 @@ + MIT License + + Copyright (c) Microsoft Corporation. + + Permission is hereby granted, free of charge, to any person obtaining a copy + of this software and associated documentation files (the "Software"), to deal + in the Software without restriction, including without limitation the rights + to use, copy, modify, merge, publish, distribute, sublicense, and/or sell + copies of the Software, and to permit persons to whom the Software is + furnished to do so, subject to the following conditions: + + The above copyright notice and this permission notice shall be included in all + copies or substantial portions of the Software. + + THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR + IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, + FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE + AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER + LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, + OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE + SOFTWARE diff --git a/refactor/baselines/site-vendor/codicons-0.0.26/README.txt b/refactor/baselines/site-vendor/codicons-0.0.26/README.txt new file mode 100644 index 000000000..346a5e027 --- /dev/null +++ b/refactor/baselines/site-vendor/codicons-0.0.26/README.txt @@ -0,0 +1,108 @@ +# Codicons + +[](https://www.npmjs.com/package/@vscode/codicons) +[](https://www.npmjs.com/package/@vscode/codicons) +[](https://github.com/microsoft/vscode-codicons/actions/workflows/build.yml) +[](https://github.com/microsoft/vscode-codicons/actions/workflows/build.yml) + + + +This tool takes the Visual Studio Code icons and converts them into an icon font using [fantasticon](https://github.com/tancredi/fantasticon). + +## Install +You can use the [npm package](https://www.npmjs.com/package/@vscode/codicons) and install into your project via: + +``` +npm i @vscode/codicons +``` + +_Note: We've deprecated `vscode-codicons` in favor of `@vscode/codicons`_ + +If you're building a VS Code extension, see this [webview extension sample](https://github.com/microsoft/vscode-extension-samples/tree/master/webview-codicons-sample) on how to integrate. + +# Building Locally + +All icons are stored under `src > icons`. The mappings of the class names and unicode characters are stored in `src/template/mapping.json` as well as the default styles under `src/template/styles.hbs`. + +## Install dependencies +After cloning this repo, install dependencies by running: + +``` +npm install +``` + +## Build + +``` +npm run build +``` + +Output will be exported to a `dist` folder. We track this folder so that we can see the updated changes to the unicode characters. + +## Update packages + +You can run `npm outdated` to see if there are any package updates. To update packages, run: + +``` +npm update +``` + +## Add icons + +Export your icons (svg) to the `src/icons` folder and add an entry into `src/template/mapping.json` with a new codepoint key (this gets converted into a unicode key) and run the the build command. The build command will also remove any subfolders in the `icons` folder to keep the folder structure consistent. + +Next, update the [codicons file](https://github.com/microsoft/vscode/blob/master/src/vs/base/common/codicons.ts) on the vscode repository, ensuring that the unicode characters are the same (you can reference the [css file](https://github.com/microsoft/vscode-codicons/blob/master/dist/codicon.css)). + + +## Using CSS Classes + +If you're building a VS Code extension, see this [webview extension sample](https://github.com/microsoft/vscode-extension-samples/tree/master/webview-codicons-sample) on how to integrate. + +When needing to reference an icon in the [Visual Studio Code source code](https://github.com/microsoft/vscode) via CSS classes, simply create a dom element/container that contains `codicon` and the [icon name](https://microsoft.github.io/vscode-codicons/dist/codicon.html) like: + +```html + +``` + +It's recommended to use a single dom element for each icon and not to add children elements to it. + +## Using SVG Sprites + +When needing to use the `codicon.svg` sprite file, you can reference icons using the following method: + +```html + +``` + +# Contributing + +This project welcomes contributions and suggestions. Most contributions require you to agree to a +Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us +the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com. + +When you submit a pull request, a CLA bot will automatically determine whether you need to provide +a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions +provided by the bot. You will only need to do this once across all repos using our CLA. + +This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/). +For more information see the [Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/) or +contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with any additional questions or comments. + +# Legal Notices + +Microsoft and any contributors grant you a license to the Microsoft documentation and other content +in this repository under the [Creative Commons Attribution 4.0 International Public License](https://creativecommons.org/licenses/by/4.0/legalcode), +see the [LICENSE](LICENSE) file, and grant you a license to any code in the repository under the [MIT License](https://opensource.org/licenses/MIT), see the +[LICENSE-CODE](LICENSE-CODE) file. + +Microsoft, Windows, Microsoft Azure and/or other Microsoft products and services referenced in the documentation +may be either trademarks or registered trademarks of Microsoft in the United States and/or other countries. +The licenses for this project do not grant you rights to use any Microsoft names, logos, or trademarks. +Microsoft's general trademark guidelines can be found at http://go.microsoft.com/fwlink/?LinkID=254653. + +Privacy information can be found at https://privacy.microsoft.com/en-us/ + +Microsoft and any contributors reserve all other rights, whether under their respective copyrights, patents, +or trademarks, whether by implication, estoppel or otherwise. diff --git a/refactor/changes/2026-09-15-SITE-07-codicons.md b/refactor/changes/2026-09-15-SITE-07-codicons.md new file mode 100644 index 000000000..3a2f265c0 --- /dev/null +++ b/refactor/changes/2026-09-15-SITE-07-codicons.md @@ -0,0 +1,50 @@ +# SITE-07 Codicons 历史来源与随站点分发 + +## 本次修改 + +现有 Monaco 0.30.1 包内 codicon.ttf 与官方 npm @vscode/codicons 0.0.26 的 +package/dist/codicon.ttf 逐字节一致;相邻 0.0.25 不匹配。下载归档先核对 npm +SHA-512 SRI 和 SHA-1,再记录 SHA-256、发布时间、gitHead、成员路径及字体直接 +比较结果。完整固定证据见 [来源记录](../baselines/site-codicons-provenance.json)。 +依据为历史 npm 归档原文;固定 GitHub 页面经网页工具未能取回,未计作取证成功。 + +从该归档保留完整 LICENSE、LICENSE-CODE、README,另加 Microsoft/contributors +署名、来源和未修改说明。历史 README 将内容列为 CC BY 4.0、代码列为 MIT; +没有套用当前上游许可,也没有用 Monaco MIT 代替字体许可。三份原文保留 CRLF, +Git 精确路径 -text 规则避免跨系统改写;生成到 docs/licenses/monaco-editor/codicons。 +原文存放 [冻结目录](../baselines/site-vendor/codicons-0.0.26)。 + +TS 生成模块增加嵌套组件关联,要求字体存在于父包清单且每份通知均有输出。 +CLI 拒绝遗漏已确认的 Codicons 组件。旧文件检查继续拒绝运行时代码和字体漂移; +生成过程不能把删改的原文自动认可为新基线。站点索引标明独立组件版本和来源。 +实现与重跑方法见 [模块说明](../../scripts/site-vendor/README.md)。没有新依赖。 + +## 验证 + +- Node 24.21.0 / Yarn 1.22.22;notice、vConsole 生命周期、Pages 资产测试 16/16。 + 新负例验证缺少嵌套许可、丢失字体关联、空证据和 CRLF 被转换,失败发生在写出前。 +- strict docs-tools 类型检查和相关源码 lint 通过。初次 lint 发现 Buffer 显式导入 + 和 import 排序问题,均已修正后重新通过。 +- Git 初次暂存检查将原文 CRLF 与原始尾空格视为空白错误;仅为这六个不可改写的 + 原文源/输出路径设置空白规则例外,继续由字节指纹保护,没有格式化上游文件。 +- build:site-notices / check:site-notices:8 个输出(原 4 个加 4 个 Codicons 文件), + 全部通过;原 100 个 Monaco/vConsole 运行时文件通过固定指纹检查。 +- 三引擎真实浏览器 6/6,22.72 秒,退出 0,无失败、跳过、重试。每引擎各验证 + 桌面 TS worker 编译/Run/Ctrl-S/语法错误保留实例,以及移动 vConsole 日志、 + 真实本地视频播放、销毁和 HTTP 返回全部 7 份 notice 的完整原文。 + 另外实际请求旧字体 URL 比较 SHA-256、读取索引确认组件条目。 +- Windows Playwright Chromium 153.0.8010.12、Firefox 155.0、WebKit 26.6; + 使用源码构建核心、真实本地 Monaco/vConsole;没有重新打包全部 npm 包。 + 移动页面测试不代表物理手机验证。报告摘要见 + [验证记录](../baselines/site-codicons-validation.json),完整报告在 ignored cache 中。 + +## 边界和后续 + +API-08/09:字体、JS/CSS、AMD/worker、旧 URL 均未修改,仅增加通知文件与校验。 +本次解决 Codicons 历史字体归属和通知分发缺口;SITE-07 仍 doing,任务完成数不变。 +Monaco 全组件通知复核、vConsole MIT 正文与捆绑依赖、console.js 来源、其他字体及 +媒体仍分别跟踪。旧 vConsole 销毁问题已有 SITE-VCONSOLE-01 修复,不重复当作本次 +新问题;当前三引擎仍保留销毁断言。没有执行远端 Pages/npm 发布或声称真机通过。 + +本次为 SITE-07 独立本地检查点提交。回退时还原对应源通知、manifest、生成文件、 +校验和文档即可,运行时资产无需回退。后续优先处理 vConsole 许可正文和依赖来源。 diff --git a/refactor/plan.md b/refactor/plan.md index 4db863681..fa5cae875 100644 --- a/refactor/plan.md +++ b/refactor/plan.md @@ -651,7 +651,7 @@ - SITE-AI-DOCS-01: [记录](changes/2026-09-14-SITE-AI-DOCS-01-documentation-pipeline.md) [记录](baselines/documentation-pipeline-validation.json) - SITE-BUILD-01: [记录](changes/2026-09-14-SITE-BUILD-01-staged-builds.md) [记录](baselines/site-build-validation.json) - SITE-03: [记录](changes/2026-09-14-SITE-03-desktop-editor.md) [记录](baselines/site-editor-validation.json) -- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) +- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) - EX-01: [记录](changes/2026-09-14-EX-01-react-consumer.md) [记录](baselines/react-consumer-validation.json) [记录](scripts/react-consumer.mjs) - EX-02: [记录](changes/2026-09-14-EX-02-vue-consumer.md) [记录](baselines/vue-consumer-validation.json) [记录](scripts/vue-consumer.mjs) - MOD-01: [记录](changes/2026-09-15-MOD-01-bun-evaluation.md) [记录](baselines/bun-install-validation.json) [记录](bun-evaluation.md) diff --git a/refactor/progress.md b/refactor/progress.md index e7c035992..c99b9aef2 100644 --- a/refactor/progress.md +++ b/refactor/progress.md @@ -1,5 +1,12 @@ # 进度与证据 +## SITE-07 Codicons 历史字体来源与通知 + +字体精确匹配官方 npm 0.0.26,补原始许可/README和署名,运行时内容及旧 URL 不变。 +新增完整通知关联校验;16/16 单元与工程测试、三引擎真实编辑器/移动播放/HTTP 原文 +6/6 通过。见[记录](changes/2026-09-15-SITE-07-codicons.md)。197/263 完成,SITE-07 +仍 doing;其余组件通知、字体媒体与远端/真机验收继续跟踪。下一步补 vConsole 许可。 + ## CI-01 VAST 完整安装包与真实 IMA 二十包安装准备通过。VAST 完整 glomex 加载边界在源码、安装范围各 36/36; diff --git a/refactor/risks.json b/refactor/risks.json index fac0bc005..5bbdad06c 100644 --- a/refactor/risks.json +++ b/refactor/risks.json @@ -621,11 +621,14 @@ "refactor/baselines/site-provenance.json", "refactor/changes/2026-09-14-SITE-07-vendor-notices.md", "refactor/baselines/site-notices-checkpoint.json", - "scripts/site-vendor/manifest.json" + "scripts/site-vendor/manifest.json", + "refactor/baselines/site-codicons-provenance.json", + "refactor/baselines/site-codicons-validation.json", + "refactor/changes/2026-09-15-SITE-07-codicons.md" ], "compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.", "closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。", - "workspaceState": "Monaco 0.30.1 runtime fingerprints and complete upstream LICENSE/ThirdPartyNotices now ship with the site; all three desktop TypeScript worker cases pass. Closure review found no Codicons entry in those notices, while the separate Microsoft Codicons source distinguishes content CC-BY-4.0 from code MIT. Exact bundled codicon.ttf version and attribution mapping remain to verify; do not infer full font clearance from Monaco MIT." + "workspaceState": "Monaco 0.30.1 inventory and original LICENSE/ThirdPartyNotices remain verified. Bundled codicon.ttf exactly matches official @vscode/codicons 0.0.26; historical CC BY 4.0 content license, MIT code license, README and added attribution now ship verbatim. Three-engine editor/mobile/native playback and HTTP notice/font checks pass 6/6. The Codicons gap is addressed; broader bundled-component notice completeness review remains open before closing VENDOR-06." }, { "id": "VENDOR-07", @@ -647,7 +650,7 @@ ], "compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.", "closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。", - "workspaceState": "Upstream 3.15.0 LICENSE copied verbatim but contains only the MIT declaration and a promise of a license copy; actual MIT body is absent. Completeness and bundled dependency notices remain open; mobile WebKit destruction also produces a log-store update page error." + "workspaceState": "Upstream 3.15.0 LICENSE copied verbatim but promises an absent MIT body; body and bundled dependency notices remain open. The historical mobile WebKit destruction defect was separately fixed by SITE-VCONSOLE-01; current three-engine site checks retain and pass destruction assertions." }, { "id": "VENDOR-08", diff --git a/refactor/site-inventory.md b/refactor/site-inventory.md index 5324bae45..73606de10 100644 --- a/refactor/site-inventory.md +++ b/refactor/site-inventory.md @@ -3,7 +3,10 @@ SITE-07检查点已将Monaco LICENSE/ThirdPartyNotices和vConsole上游LICENSE原文加入 站点分发,并建立固定文件清单/指纹及只读检查。进一步检查发现vConsole上游文件 只有许可声明,缺其声称附带的MIT全文;不能把“已取得LICENSE”当成完整许可闭环。 -Monaco真实TS worker三引擎通过;vConsole销毁在WebKit出现未处理回调错误,继续登记。 +Monaco真实TS worker三引擎通过;旧vConsole销毁错误已由SITE-VCONSOLE-01修复。 +2026-09-15:Codicons字体精确匹配npm0.0.26,其历史许可、README和署名已随站点分发; +真实三引擎6/6包含编辑器、播放、销毁及HTTP原文/字体指纹。详见 +[Codicons记录](changes/2026-09-15-SITE-07-codicons.md)。其余组件和字体媒体仍须复核。 原始SITE-01清单及下面的历史未分发描述保留,当前入口见scripts/site-vendor/README.md。 SITE-SMOKE-01 后续已将 build:test 拆为 TS 解析、生成和浏览器运行模块,新增 diff --git a/refactor/tasks.json b/refactor/tasks.json index 85ccf934b..c77b1ddd7 100644 --- a/refactor/tasks.json +++ b/refactor/tasks.json @@ -4477,7 +4477,10 @@ "site-inventory.md", "baselines/site-provenance.json", "changes/2026-09-14-SITE-07-vendor-notices.md", - "baselines/site-notices-checkpoint.json" + "baselines/site-notices-checkpoint.json", + "baselines/site-codicons-provenance.json", + "baselines/site-codicons-validation.json", + "changes/2026-09-15-SITE-07-codicons.md" ] }, { diff --git a/refactor/third-party.json b/refactor/third-party.json index add4b848e..7fd061667 100644 --- a/refactor/third-party.json +++ b/refactor/third-party.json @@ -511,10 +511,13 @@ "SITE-01", "SITE-05" ], - "sourceStatus": "Local headers name Monaco build 0.30.1 (829382514cb1065f5ebb90f436e1c6103e153953).", - "licenseStatus": "Headers identify MIT; editor.main also includes third-party notices such as DOMPurify. Full component/notice closure is pending.", - "upstreamSources": [], - "upstreamReviewedAt": null, + "sourceStatus": "Monaco 0.30.1 verified against official npm archive: 98 byte-exact files, one CSS newline-only difference. The bundled font additionally matches @vscode/codicons 0.0.26 exactly; see site-codicons-provenance.json.", + "licenseStatus": "Full Monaco LICENSE/ThirdPartyNotices and Codicons 0.0.26 historical LICENSE, LICENSE-CODE, README plus attribution are distributed and HTTP verified. Broader bundled-component notice completeness audit remains under VENDOR-06; do not infer permission for other fonts or media.", + "upstreamSources": [ + "https://registry.npmjs.org/monaco-editor/-/monaco-editor-0.30.1.tgz", + "https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz" + ], + "upstreamReviewedAt": "2026-09-15", "updatePolicy": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.", "fingerprints": [ { diff --git a/scripts/build-site-notices.mjs b/scripts/build-site-notices.mjs index e6c903324..3451eebc6 100644 --- a/scripts/build-site-notices.mjs +++ b/scripts/build-site-notices.mjs @@ -7,5 +7,6 @@ assert(process.argv.slice(2).every(arg => arg === '--check'), 'Use yarn build:si /** @type {import('./site-vendor/notices.ts').VendorManifest} */ const manifest = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8')) assert.deepEqual(manifest.groups.map(group => group.name).sort(), ['monaco-editor', 'vconsole'], 'Do not silently drop a verified site component') +assert.deepEqual(manifest.groups.flatMap(group => (group.components || []).map(component => component.name)), ['@vscode/codicons'], 'Do not silently drop the verified Codicons attribution') const count = writeOrCheckNotices(process.cwd(), manifest, process.argv.includes('--check')) console.log(`Verified site notices: ${count} outputs; Monaco/vConsole only, other provenance gates remain open.`) diff --git a/scripts/site-vendor/README.md b/scripts/site-vendor/README.md index ec3734faa..9b3bebeb3 100644 --- a/scripts/site-vendor/README.md +++ b/scripts/site-vendor/README.md @@ -5,9 +5,11 @@ archives, corresponding files and upstream notice texts. It does not clear other site dependencies or grant rights to samples/fonts. The vConsole LICENSE is preserved verbatim but is incomplete: it promises an MIT copy that is absent. Its completion and bundled dependency notices remain open under SITE-07. -Monaco's supplied notices also lack a Codicons entry. Match the included font to -its historical source and attribution before claiming the font review complete; -the Monaco MIT statement does not establish the separate font's license. +Monaco's supplied notices lack a Codicons entry. The bundled font now has an +exact byte match to the official `@vscode/codicons@0.0.26` archive. Its historical +README, CC BY 4.0 content license and MIT code license are preserved, alongside +ArtPlayer's attribution, in `docs/licenses/monaco-editor/codicons/`. This evidence +does not derive the font license from Monaco's MIT statement or today's Codicons. `notices.ts` validates the exact file inventory and fingerprints before preparing outputs. JavaScript/CSS comparisons normalize CRLF to LF; font bytes are exact. @@ -18,13 +20,20 @@ files retain their exact upstream bytes, including final blank lines. `../build-site-notices.mjs` provides `yarn build:site-notices` and read-only `yarn check:site-notices`. The write command cannot bless altered vendor assets; review the new archive and license evidence before changing the manifest. The -CLI prevents accidentally dropping either verified component. Source notices +CLI prevents accidentally dropping either verified group or the Codicons component. +Component references require their runtime assets and every notice before writing. +Source notices live in `refactor/baselines/site-vendor/`; generated delivery files live under `docs/licenses/` with an explicitly limited `docs/THIRD_PARTY_NOTICES.md` index. CI runs the read-only check before building, and generation during ci:build. Library builds remain independent. Pages preparation copies the notices into its own fingerprinted site. `.gitattributes` preserves text bytes across Windows/Linux. +The historical Codicons files use explicit `-text` overrides to retain archive +CRLF bytes. Their frozen README source uses `.txt` to avoid interpreting upstream +repository links as local refactor links; delivery restores `README.md` unchanged. +Only these immutable upstream paths allow their original trailing whitespace; +the notice hash check, rather than formatting, protects their contents. `yarn test:site-notices` tests missing/extra/modified assets, changed or incomplete inputs, path escape and read-only output drift. The browser fixture @@ -34,6 +43,15 @@ old-build reproduction are maintained in `vconsole/README.md`; generated asset checks run before the notice checks. Do not skip destruction or catch page errors. Existing desktop TypeScript editor tests cover the real Monaco worker and Run. -Follow-up: restore complete licensing from fixed upstream evidence, then recover the +The Codicons archive identity, integrity, notice members and negative comparison +with version 0.0.25 are recorded in `refactor/baselines/site-codicons-provenance.json`. +For an independent reproduction, download the pinned `comparisons[0].tarball` into +an ignored cache directory. In Node, verify its SHA-512 SRI and SHA-256 against +that record before using `execFileSync('tar', ['-xOzf', archive, member])` to read +members as Buffers. Compare `package/dist/codicon.ttf` directly with `fontPath`, +and each non-null notice member with its frozen `source`. Do not pipe binary font +output through PowerShell text redirection. No dependency installation is needed. + +Follow-up: finish the broader bundled-component notice audit, then recover the console.js build and resolve remaining fonts/media. Do not upgrade these assets without verifying globals, AMD/worker paths, CSS, consoleLog and user interaction. diff --git a/scripts/site-vendor/manifest.json b/scripts/site-vendor/manifest.json index 2084619b9..b5352ea6f 100644 --- a/scripts/site-vendor/manifest.json +++ b/scripts/site-vendor/manifest.json @@ -744,9 +744,45 @@ "source": "refactor/baselines/site-vendor/monaco-editor-ThirdPartyNotices.txt.txt", "target": "docs/licenses/monaco-editor/ThirdPartyNotices.txt", "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/LICENSE", + "target": "docs/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/LICENSE-CODE", + "target": "docs/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/README.txt", + "target": "docs/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "source": "refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt", + "target": "docs/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" } ], - "review": "The upstream Monaco LICENSE and ThirdPartyNotices are retained in full. The included codicon.ttf still needs matching Codicons version/attribution evidence; the Monaco package license alone does not close that font review." + "review": "The complete upstream Monaco LICENSE/ThirdPartyNotices are retained. The unmodified bundled Codicons font exactly matches @vscode/codicons 0.0.26; its historical README, CC BY 4.0 content license, MIT code license and added attribution are distributed below. Other site assets remain subject to their separate provenance reviews.", + "components": [ + { + "name": "@vscode/codicons", + "version": "0.0.26", + "tarball": "https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz", + "assets": [ + "docs/assets/js/vs/base/browser/ui/codicons/codicon/codicon.ttf" + ], + "notices": [ + "docs/licenses/monaco-editor/codicons/LICENSE", + "docs/licenses/monaco-editor/codicons/LICENSE-CODE", + "docs/licenses/monaco-editor/codicons/README.md", + "docs/licenses/monaco-editor/codicons/ATTRIBUTION.md" + ] + } + ] } ] } diff --git a/scripts/site-vendor/notices.ts b/scripts/site-vendor/notices.ts index 56c7ee6a9..fae29a7bf 100644 --- a/scripts/site-vendor/notices.ts +++ b/scripts/site-vendor/notices.ts @@ -5,7 +5,14 @@ import path from 'node:path' interface Asset { path: string, sha256: string, mode: string } interface Notice { source: string, target: string, sha256: string } -interface Group { name: string, version: string, tarball: string, review?: string, roots: string[], files: Asset[], notices: Notice[] } +interface Component { + name: string + version: string + tarball: string + assets: string[] + notices: string[] +} +interface Group { name: string, version: string, tarball: string, review?: string, roots: string[], files: Asset[], notices: Notice[], components?: Component[] } export interface VendorManifest { schemaVersion: number, scope: string, groups: Group[] } const hash = (bytes: Uint8Array) => createHash('sha256').update(bytes).digest('hex') @@ -44,6 +51,14 @@ export function generateNotices(root: string, manifest: VendorManifest): Map