From d2f4261aa719a21a8d0dbe042d4d22e307786093 Mon Sep 17 00:00:00 2001 From: Harvey Zhao Date: Tue, 15 Sep 2026 05:25:33 +0800 Subject: [PATCH] build(site): [SITE-07] verify vConsole sources and complete notices --- .gitattributes | 1 + docs/THIRD_PARTY_NOTICES.md | 49 +- docs/licenses/vconsole/ATTRIBUTION.md | 36 + docs/licenses/vconsole/MIT-LICENSE | 21 + docs/licenses/vconsole/babel-runtime/LICENSE | 22 + .../vconsole/copy-text-to-clipboard/LICENSE | 9 + docs/licenses/vconsole/core-js/LICENSE | 19 + docs/licenses/vconsole/css-loader/LICENSE | 20 + .../vconsole/mutation-observer/LICENSE | 55 ++ .../vconsole/regenerator-runtime/LICENSE | 21 + docs/licenses/vconsole/style-loader/LICENSE | 20 + docs/licenses/vconsole/svelte/LICENSE | 7 + docs/licenses/vconsole/webpack/LICENSE | 20 + package.json | 1 + .../vconsole-3.15.0/ATTRIBUTION.txt | 36 + .../site-vendor/vconsole-3.15.0/MIT-LICENSE | 21 + .../vconsole-3.15.0/babel-runtime-LICENSE.txt | 22 + .../copy-text-to-clipboard-LICENSE.txt | 9 + .../vconsole-3.15.0/core-js-LICENSE.txt | 19 + .../vconsole-3.15.0/css-loader-LICENSE.txt | 20 + .../mutation-observer-LICENSE.txt | 55 ++ .../regenerator-runtime-LICENSE.txt | 21 + .../vconsole-3.15.0/style-loader-LICENSE.txt | 20 + .../vconsole-3.15.0/svelte-LICENSE.txt | 7 + .../vconsole-3.15.0/webpack-LICENSE.txt | 20 + .../vconsole-notices-provenance.json | 795 ++++++++++++++++++ .../vconsole-notices-validation.json | 441 ++++++++++ .../2026-09-15-SITE-07-vconsole-notices.md | 57 ++ refactor/plan.md | 2 +- refactor/progress.md | 7 + refactor/risk-table.md | 2 +- refactor/risks.json | 17 +- refactor/site-inventory.md | 5 + refactor/tasks.json | 5 +- refactor/third-party.json | 9 +- scripts/build-site-notices.mjs | 16 +- scripts/site-vendor/README.md | 11 +- scripts/site-vendor/manifest.json | 158 +++- scripts/site-vendor/vconsole/README.md | 51 +- scripts/site-vendor/vconsole/reproduce.ts | 79 ++ test/site-notices.test.js | 22 + 41 files changed, 2206 insertions(+), 22 deletions(-) create mode 100644 docs/licenses/vconsole/ATTRIBUTION.md create mode 100644 docs/licenses/vconsole/MIT-LICENSE create mode 100644 docs/licenses/vconsole/babel-runtime/LICENSE create mode 100644 docs/licenses/vconsole/copy-text-to-clipboard/LICENSE create mode 100644 docs/licenses/vconsole/core-js/LICENSE create mode 100644 docs/licenses/vconsole/css-loader/LICENSE create mode 100644 docs/licenses/vconsole/mutation-observer/LICENSE create mode 100644 docs/licenses/vconsole/regenerator-runtime/LICENSE create mode 100644 docs/licenses/vconsole/style-loader/LICENSE create mode 100644 docs/licenses/vconsole/svelte/LICENSE create mode 100644 docs/licenses/vconsole/webpack/LICENSE create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt create mode 100644 refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt create mode 100644 refactor/baselines/vconsole-notices-provenance.json create mode 100644 refactor/baselines/vconsole-notices-validation.json create mode 100644 refactor/changes/2026-09-15-SITE-07-vconsole-notices.md create mode 100644 scripts/site-vendor/vconsole/reproduce.ts diff --git a/.gitattributes b/.gitattributes index c7d23ccb5..23c258f91 100644 --- a/.gitattributes +++ b/.gitattributes @@ -22,3 +22,4 @@ refactor/baselines/site-vendor/codicons-0.0.26/README.txt -text whitespace=-trai docs/licenses/monaco-editor/codicons/LICENSE* -text whitespace=-trailing-space,cr-at-eol docs/licenses/monaco-editor/codicons/README.md -text whitespace=-trailing-space,cr-at-eol refactor/baselines/site-vendor/codicons-0.0.26/ATTRIBUTION.txt text eol=lf +refactor/baselines/site-vendor/vconsole-3.15.0/** text eol=lf whitespace=-blank-at-eof diff --git a/docs/THIRD_PARTY_NOTICES.md b/docs/THIRD_PARTY_NOTICES.md index c18a3e331..543a06044 100644 --- a/docs/THIRD_PARTY_NOTICES.md +++ b/docs/THIRD_PARTY_NOTICES.md @@ -8,9 +8,56 @@ Generated by yarn build:site-notices. Runtime asset URLs are retained; reviewed Source: https://registry.npmjs.org/vconsole/-/vconsole-3.15.0.tgz -The 3.15.0 upstream LICENSE declares MIT but omits the promised full license text. The copied file preserves this upstream evidence; completeness and bundled dependency notices remain under review. ArtPlayer applies a reproducible local lifecycle patch to log frame cancellation and delayed panel ownership; the upstream bundle is frozen in scripts/site-vendor/vconsole/upstream.js and generated by yarn build:vconsole. Public asset URL and UMD/CSS contracts are retained. +The original 3.15.0 LICENSE is preserved unchanged; its missing MIT body is supplemented separately using the MIT text explicitly referenced by upstream. Exact reconstruction from the pinned source and lockfile establishes eight bundled package dependencies and webpack bootstrap; their complete notices and attribution are distributed below. ArtPlayer retains its reproducible lifecycle patch and the original script URL/UMD/CSS contracts. + +Included component: @babel/runtime 7.17.9 + +Source: https://registry.npmjs.org/@babel/runtime/-/runtime-7.17.9.tgz + +Included component: core-js 3.21.1 + +Source: https://registry.npmjs.org/core-js/-/core-js-3.21.1.tgz + +Included component: copy-text-to-clipboard 3.0.1 + +Source: https://registry.npmjs.org/copy-text-to-clipboard/-/copy-text-to-clipboard-3.0.1.tgz + +Included component: mutation-observer 1.0.3 + +Source: https://registry.npmjs.org/mutation-observer/-/mutation-observer-1.0.3.tgz + +Included component: svelte 3.47.0 + +Source: https://registry.npmjs.org/svelte/-/svelte-3.47.0.tgz + +Included component: regenerator-runtime 0.13.9 + +Source: https://registry.npmjs.org/regenerator-runtime/-/regenerator-runtime-0.13.9.tgz + +Included component: style-loader 3.3.1 + +Source: https://registry.npmjs.org/style-loader/-/style-loader-3.3.1.tgz + +Included component: css-loader 6.7.1 + +Source: https://registry.npmjs.org/css-loader/-/css-loader-6.7.1.tgz + +Included component: webpack 5.72.0 + +Source: https://registry.npmjs.org/webpack/-/webpack-5.72.0.tgz - licenses/vconsole/LICENSE +- licenses/vconsole/babel-runtime/LICENSE +- licenses/vconsole/core-js/LICENSE +- licenses/vconsole/copy-text-to-clipboard/LICENSE +- licenses/vconsole/mutation-observer/LICENSE +- licenses/vconsole/svelte/LICENSE +- licenses/vconsole/regenerator-runtime/LICENSE +- licenses/vconsole/style-loader/LICENSE +- licenses/vconsole/css-loader/LICENSE +- licenses/vconsole/webpack/LICENSE +- licenses/vconsole/MIT-LICENSE +- licenses/vconsole/ATTRIBUTION.md ## monaco-editor 0.30.1 diff --git a/docs/licenses/vconsole/ATTRIBUTION.md b/docs/licenses/vconsole/ATTRIBUTION.md new file mode 100644 index 000000000..fd8b304f3 --- /dev/null +++ b/docs/licenses/vconsole/ATTRIBUTION.md @@ -0,0 +1,36 @@ +# vConsole 3.15.0 distribution notices + +Copyright (C) 2017 THL A29 Limited, a Tencent company. All rights reserved. + +The [original LICENSE](LICENSE) is preserved unchanged. Its promised MIT body +is absent from the upstream file. [MIT-LICENSE](MIT-LICENSE) supplies the MIT +text explicitly referenced by the original published bundle, with its copyright +notice. ArtPlayer assembled this supplemental file; it is not presented as a +verbatim file from Tencent's archive. + +- [Original npm archive](https://registry.npmjs.org/vconsole/-/vconsole-3.15.0.tgz) +- [Source revision](https://github.com/Tencent/vConsole/tree/05d80398bae35e793774f74e3c052b4e530e293a) +- [MIT text referenced by upstream](https://opensource.org/license/mit) + +The fixed source and original lockfile reproduce the upstream bundle byte for +byte (SHA-256 671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4). The build includes the following runtime +components, whose original notices are preserved alongside this document: + +- @babel/runtime 7.17.9: [license](babel-runtime/LICENSE) +- core-js 3.21.1: [license](core-js/LICENSE) +- copy-text-to-clipboard 3.0.1: [license](copy-text-to-clipboard/LICENSE) +- mutation-observer 1.0.3: [license](mutation-observer/LICENSE) +- svelte 3.47.0: [license](svelte/LICENSE) +- regenerator-runtime 0.13.9: [license](regenerator-runtime/LICENSE) +- style-loader 3.3.1: [license](style-loader/LICENSE) +- css-loader 6.7.1: [license](css-loader/LICENSE) +- webpack 5.72.0: [license](webpack/LICENSE) + +Mutation-observer contains separate Automattic and Polymer Authors BSD notices; +both are retained in full. Webpack's generated bootstrap is included in the +notice set, as are the runtime helpers from style-loader and css-loader. + +ArtPlayer applies a local lifecycle patch to queued logs, panel insertion and +late scroller callbacks. The original bundle is preserved and the patch is +reproducible; the public script URL, UMD export and CSS remain compatible. +This notice set covers this vConsole distribution, not other site assets. diff --git a/docs/licenses/vconsole/MIT-LICENSE b/docs/licenses/vconsole/MIT-LICENSE new file mode 100644 index 000000000..c47a7e11f --- /dev/null +++ b/docs/licenses/vconsole/MIT-LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (C) 2017 THL A29 Limited, a Tencent company. All rights reserved. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. diff --git a/docs/licenses/vconsole/babel-runtime/LICENSE b/docs/licenses/vconsole/babel-runtime/LICENSE new file mode 100644 index 000000000..f31575ec7 --- /dev/null +++ b/docs/licenses/vconsole/babel-runtime/LICENSE @@ -0,0 +1,22 @@ +MIT License + +Copyright (c) 2014-present Sebastian McKenzie and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE +LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION +WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/docs/licenses/vconsole/copy-text-to-clipboard/LICENSE b/docs/licenses/vconsole/copy-text-to-clipboard/LICENSE new file mode 100644 index 000000000..fa7ceba3e --- /dev/null +++ b/docs/licenses/vconsole/copy-text-to-clipboard/LICENSE @@ -0,0 +1,9 @@ +MIT License + +Copyright (c) Sindre Sorhus (https://sindresorhus.com) + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/docs/licenses/vconsole/core-js/LICENSE b/docs/licenses/vconsole/core-js/LICENSE new file mode 100644 index 000000000..1256c1dd9 --- /dev/null +++ b/docs/licenses/vconsole/core-js/LICENSE @@ -0,0 +1,19 @@ +Copyright (c) 2014-2022 Denis Pushkarev + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. diff --git a/docs/licenses/vconsole/css-loader/LICENSE b/docs/licenses/vconsole/css-loader/LICENSE new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/docs/licenses/vconsole/css-loader/LICENSE @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/docs/licenses/vconsole/mutation-observer/LICENSE b/docs/licenses/vconsole/mutation-observer/LICENSE new file mode 100644 index 000000000..f8315db5f --- /dev/null +++ b/docs/licenses/vconsole/mutation-observer/LICENSE @@ -0,0 +1,55 @@ +// Copyright (c) 2014 Automattic Inc. All rights reserved. +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Automattic Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +// Copyright (c) 2012 The Polymer Authors. All rights reserved. +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Google Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. \ No newline at end of file diff --git a/docs/licenses/vconsole/regenerator-runtime/LICENSE b/docs/licenses/vconsole/regenerator-runtime/LICENSE new file mode 100644 index 000000000..cde61b6c5 --- /dev/null +++ b/docs/licenses/vconsole/regenerator-runtime/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2014-present, Facebook, Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/docs/licenses/vconsole/style-loader/LICENSE b/docs/licenses/vconsole/style-loader/LICENSE new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/docs/licenses/vconsole/style-loader/LICENSE @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/docs/licenses/vconsole/svelte/LICENSE b/docs/licenses/vconsole/svelte/LICENSE new file mode 100644 index 000000000..cd8f94f4c --- /dev/null +++ b/docs/licenses/vconsole/svelte/LICENSE @@ -0,0 +1,7 @@ +Copyright (c) 2016-22 [these people](https://github.com/sveltejs/svelte/graphs/contributors) + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/docs/licenses/vconsole/webpack/LICENSE b/docs/licenses/vconsole/webpack/LICENSE new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/docs/licenses/vconsole/webpack/LICENSE @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/package.json b/package.json index c7a5fc50c..a1fc6c76a 100644 --- a/package.json +++ b/package.json @@ -148,6 +148,7 @@ "test:site-notices": "node --test test/site-notices.test.js", "build:vconsole": "node scripts/build-vconsole.mjs", "check:vconsole": "node scripts/build-vconsole.mjs --check", + "verify:vconsole-source": "node scripts/site-vendor/vconsole/reproduce.ts", "test:vconsole": "node --test test/vconsole-lifecycle.test.js", "test:browser:source": "node scripts/browser-check.mjs source", "test:browser:installed": "node scripts/browser-check.mjs installed", diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt new file mode 100644 index 000000000..fd8b304f3 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt @@ -0,0 +1,36 @@ +# vConsole 3.15.0 distribution notices + +Copyright (C) 2017 THL A29 Limited, a Tencent company. All rights reserved. + +The [original LICENSE](LICENSE) is preserved unchanged. Its promised MIT body +is absent from the upstream file. [MIT-LICENSE](MIT-LICENSE) supplies the MIT +text explicitly referenced by the original published bundle, with its copyright +notice. ArtPlayer assembled this supplemental file; it is not presented as a +verbatim file from Tencent's archive. + +- [Original npm archive](https://registry.npmjs.org/vconsole/-/vconsole-3.15.0.tgz) +- [Source revision](https://github.com/Tencent/vConsole/tree/05d80398bae35e793774f74e3c052b4e530e293a) +- [MIT text referenced by upstream](https://opensource.org/license/mit) + +The fixed source and original lockfile reproduce the upstream bundle byte for +byte (SHA-256 671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4). The build includes the following runtime +components, whose original notices are preserved alongside this document: + +- @babel/runtime 7.17.9: [license](babel-runtime/LICENSE) +- core-js 3.21.1: [license](core-js/LICENSE) +- copy-text-to-clipboard 3.0.1: [license](copy-text-to-clipboard/LICENSE) +- mutation-observer 1.0.3: [license](mutation-observer/LICENSE) +- svelte 3.47.0: [license](svelte/LICENSE) +- regenerator-runtime 0.13.9: [license](regenerator-runtime/LICENSE) +- style-loader 3.3.1: [license](style-loader/LICENSE) +- css-loader 6.7.1: [license](css-loader/LICENSE) +- webpack 5.72.0: [license](webpack/LICENSE) + +Mutation-observer contains separate Automattic and Polymer Authors BSD notices; +both are retained in full. Webpack's generated bootstrap is included in the +notice set, as are the runtime helpers from style-loader and css-loader. + +ArtPlayer applies a local lifecycle patch to queued logs, panel insertion and +late scroller callbacks. The original bundle is preserved and the patch is +reproducible; the public script URL, UMD export and CSS remain compatible. +This notice set covers this vConsole distribution, not other site assets. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE b/refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE new file mode 100644 index 000000000..c47a7e11f --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (C) 2017 THL A29 Limited, a Tencent company. All rights reserved. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt new file mode 100644 index 000000000..f31575ec7 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt @@ -0,0 +1,22 @@ +MIT License + +Copyright (c) 2014-present Sebastian McKenzie and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +"Software"), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND +NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE +LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION +WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt new file mode 100644 index 000000000..fa7ceba3e --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt @@ -0,0 +1,9 @@ +MIT License + +Copyright (c) Sindre Sorhus (https://sindresorhus.com) + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt new file mode 100644 index 000000000..1256c1dd9 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt @@ -0,0 +1,19 @@ +Copyright (c) 2014-2022 Denis Pushkarev + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt new file mode 100644 index 000000000..f8315db5f --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt @@ -0,0 +1,55 @@ +// Copyright (c) 2014 Automattic Inc. All rights reserved. +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Automattic Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +// Copyright (c) 2012 The Polymer Authors. All rights reserved. +// +// Redistribution and use in source and binary forms, with or without +// modification, are permitted provided that the following conditions are +// met: +// +// * Redistributions of source code must retain the above copyright +// notice, this list of conditions and the following disclaimer. +// * Redistributions in binary form must reproduce the above +// copyright notice, this list of conditions and the following disclaimer +// in the documentation and/or other materials provided with the +// distribution. +// * Neither the name of Google Inc. nor the names of its +// contributors may be used to endorse or promote products derived from +// this software without specific prior written permission. +// +// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS +// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT +// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR +// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT +// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, +// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT +// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. \ No newline at end of file diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt new file mode 100644 index 000000000..cde61b6c5 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2014-present, Facebook, Inc. + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt new file mode 100644 index 000000000..cd8f94f4c --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt @@ -0,0 +1,7 @@ +Copyright (c) 2016-22 [these people](https://github.com/sveltejs/svelte/graphs/contributors) + +Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt b/refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt new file mode 100644 index 000000000..8c11fc728 --- /dev/null +++ b/refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt @@ -0,0 +1,20 @@ +Copyright JS Foundation and other contributors + +Permission is hereby granted, free of charge, to any person obtaining +a copy of this software and associated documentation files (the +'Software'), to deal in the Software without restriction, including +without limitation the rights to use, copy, modify, merge, publish, +distribute, sublicense, and/or sell copies of the Software, and to +permit persons to whom the Software is furnished to do so, subject to +the following conditions: + +The above copyright notice and this permission notice shall be +included in all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, +EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. +IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, +TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE +SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/refactor/baselines/vconsole-notices-provenance.json b/refactor/baselines/vconsole-notices-provenance.json new file mode 100644 index 000000000..f597801f3 --- /dev/null +++ b/refactor/baselines/vconsole-notices-provenance.json @@ -0,0 +1,795 @@ +{ + "schemaVersion": 1, + "task": "SITE-07", + "recordedAt": "2026-09-14T21:15:14.896Z", + "upstream": { + "name": "vconsole", + "version": "3.15.0", + "commit": "05d80398bae35e793774f74e3c052b4e530e293a", + "tarball": "https://registry.npmjs.org/vconsole/-/vconsole-3.15.0.tgz", + "integrity": "sha512-8hq7wabPcRucSWQyN7/1tthMawP9JPvM95zgtMHpPknMMMCKj+abpoK7P7oKK4B0qw58C24Mdvo9+raUdpHyVQ==", + "archiveSha256": "7ebe6c7a51309a4c1627285c1e26326402874192aea54e7933bbc8b321c97538", + "bundleSha256": "671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4" + }, + "reconstruction": { + "node": "24.21.0", + "npm": "11.19.0", + "install": "npm ci --ignore-scripts --no-audit --no-fund", + "scope": "Isolated historical upstream reconstruction in ignored cache; ArtPlayer still uses Yarn 1.22.22 and only root yarn.lock.", + "installedPackages": 520, + "installExitCode": 0, + "buildExitCode": 0, + "exactByteMatch": true, + "bytes": 282381, + "sha256": "671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4", + "statsSha256": "5e29d316a6d2158ef24b775270f67b10150fda510649eae27e3017163fca705c", + "moduleRecords": 326, + "filteredModules": 0, + "warnings": [ + "Unchanged upstream webpack asset/entry size and performance recommendations" + ], + "sources": [ + { + "path": "babel.config.json", + "gitBlob": "af8c106a3b8ad620b930e848abce303624b78ba6", + "sha256": "776ffbdb27a4f457141d0a6cdae22796a4db0d1d7a6312648f1e59b95f5c55bd" + }, + { + "path": "build/build.typings.js", + "gitBlob": "69861e2939bcd266f456b8592f6a0c8bc6be6a06", + "sha256": "bb165df362c3fa7bb36a3e9e393aa93ca8c80edf7cf6b94c7a25a77e1aaeedf4" + }, + { + "path": "build/dummy.js", + "gitBlob": "b1c6ea436a540020ff61f01dea449d5b39367b27", + "sha256": "fc00d19bc94e10c24f07bd9be1c2bb24d4978856963c5a68745338ecbf131dfc" + }, + { + "path": "build/vendor.d.ts", + "gitBlob": "9b948616dcf071569c32893d41b968aa7e36d796", + "sha256": "5fccc966a1d5a9116877eb87b130c402157b9be07849fa5da223fda71a836d3f" + }, + { + "path": "build/vendor.json", + "gitBlob": "96afe665617a58b08dae261ee3684e52039f5d1c", + "sha256": "7e8c28ec4d8c3338fe1899d5cb23d08c8d335f7aec4b405a975b560035dd9257" + }, + { + "path": "package-lock.json", + "gitBlob": "aa240b8251ee8a3bc3517c00fd4dc208788c480a", + "sha256": "ef863ffe898bc7e66b40c4bc9be4d6643e95b355df5adb750144631cf874f8e9" + }, + { + "path": "package.json", + "gitBlob": "ecf0395bbd1b1316d594408a07934c5bbf286508", + "sha256": "14db331c45b0c79b5f94611a5f140e6ebd64a1cbe5d1f63b38559d625563ee8e" + }, + { + "path": "src/component/icon/icon.less", + "gitBlob": "015d8576a12d9795b19858d80549c6c603135c9d", + "sha256": "b40f5a687fe4a02e01ee524a925e6444d8394833f8d5e237b06d67904adac3cb" + }, + { + "path": "src/component/icon/icon.svelte", + "gitBlob": "5caaa3775561b97c1497c48f620fb14862d68f98", + "sha256": "98240e230822f9b4d714b384a22172f60d98f70255b489e9c2a018263ba1b814" + }, + { + "path": "src/component/icon/iconCopy.svelte", + "gitBlob": "9afc17019da92a301becc214aa9b5c7f2dd8d53f", + "sha256": "709f0e0e110e114b0f8107810018025ff4a85be6610dc7c2687b7067dc17883f" + }, + { + "path": "src/component/recycleScroller/recycleItem.svelte", + "gitBlob": "5dd718bb38e0defd4d54fb00f4e4db096e5e3c3d", + "sha256": "6763b0685edc06adc972c5f58ffb19c4cf5be88bcc810cd699aab94c3f5fcf8b" + }, + { + "path": "src/component/recycleScroller/recycleManager.ts", + "gitBlob": "368c0faf0c94bcf678a8171601342672695c566b", + "sha256": "b49e06d99a70cacf199a10ff0532bb2fcdf9e366b511a8ab1dc6bf97b6fd21d0" + }, + { + "path": "src/component/recycleScroller/recycleScroller.less", + "gitBlob": "2c9a73c469f0e6dad82c1df72ee6cc2180fd447e", + "sha256": "37cebc600e6a731bb79d7c99fc851518f5552c38101f5e87ff53e6fb054b6d25" + }, + { + "path": "src/component/recycleScroller/recycleScroller.svelte", + "gitBlob": "fe30208e77c19129f66eaf43b29f2a5e82912ad4", + "sha256": "6ba45a377111d6a4cefe5dba6c29b9acf7c2170d7b6b241eb6ac61ddb19e2247" + }, + { + "path": "src/component/recycleScroller/scroll/friction.ts", + "gitBlob": "6f3c15cf4803334fbf204d39f36d8c63411a6660", + "sha256": "b8bde1271cdcfc60d91bf7b99aa99d2f81a17c05d78d2abd6d5b18f0a6f1f912" + }, + { + "path": "src/component/recycleScroller/scroll/linear.ts", + "gitBlob": "4462a6c6f0adc88720f1a7a17fe6532a8e129ec4", + "sha256": "cc8b4fbe9f7a99fe89090e365d44b5b554a01d69136dabe6e4db522b2b8ea77b" + }, + { + "path": "src/component/recycleScroller/scroll/scroll.ts", + "gitBlob": "98b2dd76ce480d85621360f3b2e27591cc4a7210", + "sha256": "80e21fd70b5bb3d5f9e8eaacb6ab6dee317187c0b578d1aa4359743d5da778b0" + }, + { + "path": "src/component/recycleScroller/scroll/scrollHandler.ts", + "gitBlob": "5fb5b7ff0a79204a29594adceb9c847977aebdea", + "sha256": "cd34ef533ba76f1b836d81e0e8282614ee300868f7b2de7e331fe03e21e5be91" + }, + { + "path": "src/component/recycleScroller/scroll/spring.ts", + "gitBlob": "603a0f137ebf5c333361e65a8053c25a71acf4a8", + "sha256": "5b52c98456939cfd2f99cede6132454615bfe4f278e9dca04b86afb01cb4c8e1" + }, + { + "path": "src/component/recycleScroller/scroll/touchTracker.ts", + "gitBlob": "3e2cef37f5bce69e9755eb60125c950d96d63faf", + "sha256": "4021f048fbd14273b98620251f3c10ac73f9be6ac7680bf0e641a3b80043d19c" + }, + { + "path": "src/core/core.less", + "gitBlob": "1169d85ff3489dbd56fd38dda7dfac4e182af206", + "sha256": "9c5839c0b5a3c01011c2783156ddb0c9e02d3cdd4c67610c196f12800718d525" + }, + { + "path": "src/core/core.model.ts", + "gitBlob": "3297d71a01267ff346a76631143545c534496f15", + "sha256": "85a7ebc2536c76ce1fea458fe216b3ca9400f43d1d587731a314a1fe7ea774ba" + }, + { + "path": "src/core/core.svelte", + "gitBlob": "3729b16065f7bf95ee607a0174d04b6dba7ea074", + "sha256": "113eb830e5ce13d5272e65e1e65f4b9360fb38f8959781b05533bbd499754559" + }, + { + "path": "src/core/core.ts", + "gitBlob": "843db2bf9f93219aa105398e4e6a05933127556b", + "sha256": "0da9969d4b76b97d72081780fcaeee9201507eeea63c6680074db132ac1ba239" + }, + { + "path": "src/core/options.interface.ts", + "gitBlob": "7c63c84255b879aaecaec0ef4edeb6923a68f04f", + "sha256": "3bbdf7a69e2d394a324a026f0c211db2d0cf3c6c3b4ce12fda72898042163b96" + }, + { + "path": "src/core/style/tabbar.less", + "gitBlob": "b0f6838edcc6ca66b3f5548843a8e45bcd160de1", + "sha256": "1f244c27b1c3da5c4eb02cacd3a0905a879933eec22af80ff5de1e102f623f1f" + }, + { + "path": "src/core/style/theme.less", + "gitBlob": "5b1b734a7d044bd0a57385ae4a33f0d092609c4e", + "sha256": "183b7fc613778e9f9ac0c6da6ab788104a05d0a4400a006963d5f0bd91d8cd8d" + }, + { + "path": "src/core/style/toolbar.less", + "gitBlob": "bac064ed610cb88b59342243401384308dcaf578", + "sha256": "e0d9f2f4c9b0a639420c8b6aad7da88a7136bc148aa01d977df66116b28e50b7" + }, + { + "path": "src/core/style/topbar.less", + "gitBlob": "36739a522a7caa9dbc6a8894c99d305f5211e0a4", + "sha256": "df62abcf8d38eaddb1f2b659069a77324208a188e0b01def05fe7115d0bbbac9" + }, + { + "path": "src/core/style/view.less", + "gitBlob": "539cba61d049b700406cfb217ac2f9064debabd1", + "sha256": "a076a199cfc51e19ca3de0e0e29c7351c1fc6cf6b48d1e76583e763f8ddaac6f" + }, + { + "path": "src/core/switchButton.less", + "gitBlob": "d15ab35ac7b1ed0640e9d8b64cf125c13102526a", + "sha256": "4151c6d959645e5205ff36495cbe0ee4d066239544ba6716dd259984466719cd" + }, + { + "path": "src/core/switchButton.svelte", + "gitBlob": "409bc3e846a01e9355e1f1e1ebaf9589b8e85b11", + "sha256": "1c1d488296d6514f17319b540a16792fc5629d6c8a6b5d373e766099b7f2276e" + }, + { + "path": "src/element/element.model.ts", + "gitBlob": "be98163cdb1633fa459913a22a9737831d58d300", + "sha256": "6e70a7f01a37d562d89491f52b36cdedddc72bf6cb3e848dd1bb3694ccd567c4" + }, + { + "path": "src/element/element.svelte", + "gitBlob": "eb4cb42e4203c24a623078ba40349972b0f84af1", + "sha256": "6518a7b84e15586cbe981507eafc8590df4685fa75f67cc978abd41c74e17b3e" + }, + { + "path": "src/element/element.ts", + "gitBlob": "9ed4da578df00a6811990097fbd972fb0e4c0cc3", + "sha256": "f868c5139181bff6501a01f9f2a81c465a66c6ac56b0c15b1a08ba20501947b9" + }, + { + "path": "src/element/elementNode.less", + "gitBlob": "364982b3e998384f7df7717fbb34ad9a4221cc2c", + "sha256": "b7aef0bf6ce870eb3316633ede3ef56c17b90f03d85b84bf689f26f34b8a28be" + }, + { + "path": "src/element/elementNode.svelte", + "gitBlob": "f57c78ae97b0de48b7c008ca3330b0e083297699", + "sha256": "208fc090d2bd90e0f39c8a25d1c62c99c6d29a65e3d97133e8c43c62e5e35a0d" + }, + { + "path": "src/lib/model.ts", + "gitBlob": "1cdd3d3fa78732b1723c8e3d8cd427c88d56c602", + "sha256": "5642cd1a2db401847de267e2f612773d7838f80f520a1e717a0c497e1baf4ff1" + }, + { + "path": "src/lib/plugin.ts", + "gitBlob": "ebe0ca9351b1f2b41282489cbbac386bdfe85777", + "sha256": "377678f357f535befb431b229b773fe8199fa22fbdfa83b47d60d34f664200d0" + }, + { + "path": "src/lib/pluginExporter.ts", + "gitBlob": "fb45df3ae4ba41793b9f97b0b635d84854be9a49", + "sha256": "a1b444be8b503cb590fa37575e0cee2bd0eae140ce47f651e04d03658ba3f350" + }, + { + "path": "src/lib/query.ts", + "gitBlob": "2a7545d31fa94ba8517757752ea2f9b7e3083b81", + "sha256": "f6897549721535541fdf560589a6c0000a87ac6281fd489b7648ba11a96a7fc6" + }, + { + "path": "src/lib/sveltePlugin.ts", + "gitBlob": "5d09da35fb9975ce3d23daadef8e317523eeda81", + "sha256": "4fd19b67b114ed084380ab844ec0bb232501a0c84cd7ae659fce96f91a633d26" + }, + { + "path": "src/lib/tool.ts", + "gitBlob": "e595bef5a26f92b7516a984fb25c8c79c5270dd3", + "sha256": "1def9b4067bf83b5cae8db908d33f519903df060d8cff63b818146861313bd1a" + }, + { + "path": "src/log/default.ts", + "gitBlob": "e025fe3b17ec7d136c3ca7db78afed11f877359e", + "sha256": "0889cfb44362fd22a3aa2476a3531d259119f9d8fba23a025a0b586a0ad3bcc3" + }, + { + "path": "src/log/log.exporter.ts", + "gitBlob": "2eae4d6ffd70d193a0e67121ffc893957a6b0dc8", + "sha256": "edf4bd50716d6a77789b34b65aaec10588bb514df53e6512396c0dec652429fc" + }, + { + "path": "src/log/log.less", + "gitBlob": "3890599267760e6b86625f09a38192b817fd1bae", + "sha256": "f395e6ace1074497e9d6b5b2ff211d472471b6d1b82e9d19c5321417772ebcc9" + }, + { + "path": "src/log/log.model.ts", + "gitBlob": "ea8b2cd3ec2b4f358fcaf37ecce30a6d0539b167", + "sha256": "358f60402b8a6148812f1566cb4deb9046559ff3ec2775d8e7954db05bb13c72" + }, + { + "path": "src/log/log.store.ts", + "gitBlob": "1f93f45585de92e545dabf89b3c669b66e6efab9", + "sha256": "5a9cda061defc960ca906e4002921135c4f009c3cc679f898a40dae54309335b" + }, + { + "path": "src/log/log.svelte", + "gitBlob": "d7d5734f6ecb44e1ce4970d048e62c134b4475e2", + "sha256": "218847b496068fdc6bc188ba64d53c629c5db2fc6481ffba7395032ab96eb2b3" + }, + { + "path": "src/log/log.ts", + "gitBlob": "73c49e46db8eba036226bb200eb3c027aca1dc36", + "sha256": "fe1fab061c487efc8523cf7fbc4352ff44f031968b0e842364a139284c3908d6" + }, + { + "path": "src/log/logCommand.less", + "gitBlob": "7e5eff79aa0719d3e5f215924dedc910d61aa2f6", + "sha256": "b5ea59421e114cb2b05a99990b90f625ea3285f471187fa462aca57e2468354f" + }, + { + "path": "src/log/logCommand.svelte", + "gitBlob": "c703b650e0bb36ad1fd9ce608a45d4f5a57368b6", + "sha256": "4459eca94c80aa466ce23e6ced74c29fd19b0fa8eed844101e42621063d7573b" + }, + { + "path": "src/log/logRow.less", + "gitBlob": "a048c9be3384a33660c781cf1c50a5cd21f3974a", + "sha256": "088324d4162587d8a2bf3fe4cf888609f7017a34ffa3c89499a37aec7378fc3d" + }, + { + "path": "src/log/logRow.svelte", + "gitBlob": "3f4273f88ab6f7f38d0a86df233c14c19717ff58", + "sha256": "2eed4afe359aeb49a6bd1d51eb29e3394085be6f4dd170602fce8e247b7e2c5d" + }, + { + "path": "src/log/logTool.ts", + "gitBlob": "bc57725336045ba095563cc24edde18254616ead", + "sha256": "e4706f3fe5be34356fbcaa0c04764f090fa6f0294f3af2adefa88d0a61c804d0" + }, + { + "path": "src/log/logTree.less", + "gitBlob": "ab8121f8d564f4e101e636fa058de02a90ce13a2", + "sha256": "55da1e60bc8a310bf4a5e7490e8dc3009d055b59614573813622b1b86916b219" + }, + { + "path": "src/log/logTree.svelte", + "gitBlob": "0d8229ae5bd270bbecaaa06679c26e7c5db67111", + "sha256": "f237b1d82d98d5eb8e1b4048d749b7121ee9b7a4824f1afea3afb6d195792ab0" + }, + { + "path": "src/log/logValue.less", + "gitBlob": "da3be4ca585b0ee9de1e557ecb1c739ed0ef1369", + "sha256": "09990dd75b3c21aa50716a8672d98d1d8f63be5d4146432148819a78e6442678" + }, + { + "path": "src/log/logValue.svelte", + "gitBlob": "d747a813895f2b4ebb5aa438a81ce79e3f19bfb2", + "sha256": "74d54ad6594921d54cd1bf6df3dd71ac7e4afe05f470b200fcdffd06253cea97" + }, + { + "path": "src/log/system.ts", + "gitBlob": "3ca46a99758bc0d22001a5b1c6e32419d7478498", + "sha256": "3c7dc0a57dc519c26b82754a8848522d1c6ff85381731c88bcda895e28e797b6" + }, + { + "path": "src/network/beacon.proxy.ts", + "gitBlob": "815e356477b5a31c5892415430aecd89d21bd123", + "sha256": "f7552835c4d6fec1f86b175c6c7a7fbb411cdafbec5e8514ffa07cfa2108f8c0" + }, + { + "path": "src/network/fetch.proxy.ts", + "gitBlob": "4c1089f19d2632529ca97cb4f515cfb2f822e181", + "sha256": "61a1dab8ba65d0d758f624032533788e7c9153f983710b023258b315fbccd793" + }, + { + "path": "src/network/helper.ts", + "gitBlob": "9a5b338494e2d20bf8c6023714737919c5c8d065", + "sha256": "93dd4e66976b3214886be82bb39a7049e1d1b534dba33a1e3b992fb12207f892" + }, + { + "path": "src/network/network.exporter.ts", + "gitBlob": "bfcf28a62917e8caa9e4827eef0ead02d18b703e", + "sha256": "a498b8455d45c75f136c6005d1fda437ad1a8e68f44e254579149348ee253a5e" + }, + { + "path": "src/network/network.less", + "gitBlob": "143d1bc2a92409328f5f5d11437c8976e2ca4a6c", + "sha256": "2c8ad4a8ce363d47d3d4a7290d1328cd0db19a6f6469316ae33ad4f78c952764" + }, + { + "path": "src/network/network.model.ts", + "gitBlob": "5a039354c2790ca17f2597993ff84470d7921b58", + "sha256": "4f5ae8206ed0fc146a742586384d8914fca674c29850366521cdc7599f872271" + }, + { + "path": "src/network/network.svelte", + "gitBlob": "79c25cab35d9562c3d56bed09580a08b0a0d0bda", + "sha256": "97984c2f11e62cda217ec098c6c2241a774d0b92aa025ad109635b89786bce1e" + }, + { + "path": "src/network/network.ts", + "gitBlob": "67451d858e6758007d735c47a391610a78656468", + "sha256": "c7e6be6313b994058e3d183e80295bb9e97630ff4d8fd63cbc78a30857633ec4" + }, + { + "path": "src/network/requestItem.ts", + "gitBlob": "7bb9f2f5256a154ffcbf64797b957103097567db", + "sha256": "63d41182c91390a5f9b1572c5abfcec6d77671dcf36a906a8cf769dfb09bf900" + }, + { + "path": "src/network/xhr.proxy.ts", + "gitBlob": "25ba70b05766e4a657b53f384ad5679a88be9f02", + "sha256": "e04d766cff794a87442ee82f4724df8fd8e2b9775e742f445c574cf56695888f" + }, + { + "path": "src/storage/storage.cookie.ts", + "gitBlob": "24cf3ab229555d31894487289d17b152e0cd95f1", + "sha256": "22742a8bc1b8e9cdf107cf0d68abdae30e84a5e98d966bbb0d33dcd934c42057" + }, + { + "path": "src/storage/storage.model.ts", + "gitBlob": "a40415b0d9cf4ab9402233daa1c64b248fb671b0", + "sha256": "3cc10946d7d293e8e7ea3aa78e562357ff5ed8859b0753b73ca77e2349668245" + }, + { + "path": "src/storage/storage.svelte", + "gitBlob": "b9dd214f7366225a53fd970269cb42ac13aa3588", + "sha256": "2853c8687ba4711bd47f02b6f02b465aa9a6f1615ea18ef80781f27b15a13a9b" + }, + { + "path": "src/storage/storage.ts", + "gitBlob": "95275da37d7ac160c7c75265ca1a90a0377d50e2", + "sha256": "855e9633ddc4c6c6156fd0bb3d4301005834b81a339f10618c37a02a2b3ca37f" + }, + { + "path": "src/storage/storage.wx.ts", + "gitBlob": "bed7badb7048e171213008c1efc386eccbdf365c", + "sha256": "21a74f7bc78311e6ab77b67b0e3c75b4eae194699026a82cffd0e9f45104892a" + }, + { + "path": "src/styles/var.less", + "gitBlob": "038cf16f692ec140feceddf7bb6d9615565e9f38", + "sha256": "fe59f23b66be5d7b67bc8143642ed669d171558ed8d2709378404fde1db31c6e" + }, + { + "path": "src/types.d.ts", + "gitBlob": "f17357717f2edb7dae98321cd627e3c44bf40ce3", + "sha256": "73573ca0b3fec1e92406cef58f3de7231940380094f814e7e973692bf0d2b1c2" + }, + { + "path": "src/vconsole.ts", + "gitBlob": "95fa40572ee48cda89daeb1456d1b44eb28a9449", + "sha256": "e589b46f4fdc75c238bfd78e54d125f1606c3c52a07313de55f0c4fec9e14811" + }, + { + "path": "tsconfig.json", + "gitBlob": "f831bdfd6ddccb3522b740a61a03023b5961f540", + "sha256": "45627b4f62b138d120854813364816f04ca4486cdb0a670dce2b988ec0ed16c3" + }, + { + "path": "tsconfig.type.json", + "gitBlob": "ddb392516fca2254ca0bfaa1686ee49fb2135989", + "sha256": "876935b8495d1e47fb114fdc9546bd1e8cde3343d97b1d94f92b02801a00c598" + }, + { + "path": "webpack.config.js", + "gitBlob": "0ef08d81678678aef4aebce2b2899009b188bad4", + "sha256": "7514c55c4c46d1ef5050e804c54bf6c76b89e9bf5a1ee88b3b564ce6b063b176" + } + ] + }, + "dependencies": [ + { + "name": "@babel/runtime", + "version": "7.17.9", + "tarball": "https://registry.npmjs.org/@babel/runtime/-/runtime-7.17.9.tgz", + "integrity": "sha512-lSiBBvodq29uShpWGNbgFdKYNiFDo5/HIYsaCEY9ff4sb10x9jizo2+pRrSyF4jKZCXqgzuqBOQKbUm90gQwJg==", + "archiveSha256": "ff7cfac68698985f91b704387077db5dd8e4514d619bcdd83bac8ec5e07a9fbd", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt", + "target": "docs/licenses/vconsole/babel-runtime/LICENSE", + "sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/@babel/runtime/helpers/esm/assertThisInitialized.js", + "node_modules/@babel/runtime/helpers/esm/asyncToGenerator.js", + "node_modules/@babel/runtime/helpers/esm/construct.js", + "node_modules/@babel/runtime/helpers/esm/createClass.js", + "node_modules/@babel/runtime/helpers/esm/defineProperty.js", + "node_modules/@babel/runtime/helpers/esm/getPrototypeOf.js", + "node_modules/@babel/runtime/helpers/esm/inheritsLoose.js", + "node_modules/@babel/runtime/helpers/esm/isNativeFunction.js", + "node_modules/@babel/runtime/helpers/esm/isNativeReflectConstruct.js", + "node_modules/@babel/runtime/helpers/esm/setPrototypeOf.js", + "node_modules/@babel/runtime/helpers/esm/wrapNativeSuper.js", + "node_modules/@babel/runtime/regenerator/index.js" + ] + }, + { + "name": "core-js", + "version": "3.21.1", + "tarball": "https://registry.npmjs.org/core-js/-/core-js-3.21.1.tgz", + "integrity": "sha512-FRq5b/VMrWlrmCzwRrpDYNxyHP9BcAZC+xHJaqTgIE5091ZV1NTmyh0sGOg5XqpnHvR0svdy0sv1gWA1zmhxig==", + "archiveSha256": "048cef00c1fbae8ed98ae1e03d6b3f3a23385f401704459577358278e76a78f0", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt", + "target": "docs/licenses/vconsole/core-js/LICENSE", + "sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/core-js/es/promise/index.js", + "node_modules/core-js/es/symbol/index.js", + "node_modules/core-js/internals/a-callable.js", + "node_modules/core-js/internals/a-constructor.js", + "node_modules/core-js/internals/a-possible-prototype.js", + "node_modules/core-js/internals/add-to-unscopables.js", + "node_modules/core-js/internals/an-instance.js", + "node_modules/core-js/internals/an-object.js", + "node_modules/core-js/internals/array-includes.js", + "node_modules/core-js/internals/array-iteration.js", + "node_modules/core-js/internals/array-method-has-species-support.js", + "node_modules/core-js/internals/array-slice-simple.js", + "node_modules/core-js/internals/array-slice.js", + "node_modules/core-js/internals/array-species-constructor.js", + "node_modules/core-js/internals/array-species-create.js", + "node_modules/core-js/internals/check-correctness-of-iteration.js", + "node_modules/core-js/internals/classof-raw.js", + "node_modules/core-js/internals/classof.js", + "node_modules/core-js/internals/clear-error-stack.js", + "node_modules/core-js/internals/copy-constructor-properties.js", + "node_modules/core-js/internals/correct-prototype-getter.js", + "node_modules/core-js/internals/create-iterator-constructor.js", + "node_modules/core-js/internals/create-non-enumerable-property.js", + "node_modules/core-js/internals/create-property-descriptor.js", + "node_modules/core-js/internals/create-property.js", + "node_modules/core-js/internals/define-iterator.js", + "node_modules/core-js/internals/define-well-known-symbol.js", + "node_modules/core-js/internals/descriptors.js", + "node_modules/core-js/internals/document-create-element.js", + "node_modules/core-js/internals/dom-iterables.js", + "node_modules/core-js/internals/dom-token-list-prototype.js", + "node_modules/core-js/internals/engine-is-browser.js", + "node_modules/core-js/internals/engine-is-ios-pebble.js", + "node_modules/core-js/internals/engine-is-ios.js", + "node_modules/core-js/internals/engine-is-node.js", + "node_modules/core-js/internals/engine-is-webos-webkit.js", + "node_modules/core-js/internals/engine-user-agent.js", + "node_modules/core-js/internals/engine-v8-version.js", + "node_modules/core-js/internals/enum-bug-keys.js", + "node_modules/core-js/internals/error-stack-installable.js", + "node_modules/core-js/internals/export.js", + "node_modules/core-js/internals/fails.js", + "node_modules/core-js/internals/function-apply.js", + "node_modules/core-js/internals/function-bind-context.js", + "node_modules/core-js/internals/function-bind-native.js", + "node_modules/core-js/internals/function-call.js", + "node_modules/core-js/internals/function-name.js", + "node_modules/core-js/internals/function-uncurry-this.js", + "node_modules/core-js/internals/get-built-in.js", + "node_modules/core-js/internals/get-iterator-method.js", + "node_modules/core-js/internals/get-iterator.js", + "node_modules/core-js/internals/get-method.js", + "node_modules/core-js/internals/global.js", + "node_modules/core-js/internals/has-own-property.js", + "node_modules/core-js/internals/hidden-keys.js", + "node_modules/core-js/internals/host-report-errors.js", + "node_modules/core-js/internals/html.js", + "node_modules/core-js/internals/ie8-dom-define.js", + "node_modules/core-js/internals/indexed-object.js", + "node_modules/core-js/internals/inspect-source.js", + "node_modules/core-js/internals/install-error-cause.js", + "node_modules/core-js/internals/internal-state.js", + "node_modules/core-js/internals/is-array-iterator-method.js", + "node_modules/core-js/internals/is-array.js", + "node_modules/core-js/internals/is-callable.js", + "node_modules/core-js/internals/is-constructor.js", + "node_modules/core-js/internals/is-forced.js", + "node_modules/core-js/internals/is-object.js", + "node_modules/core-js/internals/is-pure.js", + "node_modules/core-js/internals/is-symbol.js", + "node_modules/core-js/internals/iterate.js", + "node_modules/core-js/internals/iterator-close.js", + "node_modules/core-js/internals/iterators-core.js", + "node_modules/core-js/internals/iterators.js", + "node_modules/core-js/internals/length-of-array-like.js", + "node_modules/core-js/internals/microtask.js", + "node_modules/core-js/internals/native-promise-constructor.js", + "node_modules/core-js/internals/native-symbol.js", + "node_modules/core-js/internals/native-weak-map.js", + "node_modules/core-js/internals/new-promise-capability.js", + "node_modules/core-js/internals/normalize-string-argument.js", + "node_modules/core-js/internals/object-create.js", + "node_modules/core-js/internals/object-define-properties.js", + "node_modules/core-js/internals/object-define-property.js", + "node_modules/core-js/internals/object-get-own-property-descriptor.js", + "node_modules/core-js/internals/object-get-own-property-names-external.js", + "node_modules/core-js/internals/object-get-own-property-names.js", + "node_modules/core-js/internals/object-get-own-property-symbols.js", + "node_modules/core-js/internals/object-get-prototype-of.js", + "node_modules/core-js/internals/object-is-prototype-of.js", + "node_modules/core-js/internals/object-keys-internal.js", + "node_modules/core-js/internals/object-keys.js", + "node_modules/core-js/internals/object-property-is-enumerable.js", + "node_modules/core-js/internals/object-set-prototype-of.js", + "node_modules/core-js/internals/object-to-string.js", + "node_modules/core-js/internals/ordinary-to-primitive.js", + "node_modules/core-js/internals/own-keys.js", + "node_modules/core-js/internals/path.js", + "node_modules/core-js/internals/perform.js", + "node_modules/core-js/internals/promise-resolve.js", + "node_modules/core-js/internals/queue.js", + "node_modules/core-js/internals/redefine-all.js", + "node_modules/core-js/internals/redefine.js", + "node_modules/core-js/internals/require-object-coercible.js", + "node_modules/core-js/internals/set-global.js", + "node_modules/core-js/internals/set-species.js", + "node_modules/core-js/internals/set-to-string-tag.js", + "node_modules/core-js/internals/shared-key.js", + "node_modules/core-js/internals/shared-store.js", + "node_modules/core-js/internals/shared.js", + "node_modules/core-js/internals/species-constructor.js", + "node_modules/core-js/internals/string-multibyte.js", + "node_modules/core-js/internals/task.js", + "node_modules/core-js/internals/to-absolute-index.js", + "node_modules/core-js/internals/to-indexed-object.js", + "node_modules/core-js/internals/to-integer-or-infinity.js", + "node_modules/core-js/internals/to-length.js", + "node_modules/core-js/internals/to-object.js", + "node_modules/core-js/internals/to-primitive.js", + "node_modules/core-js/internals/to-property-key.js", + "node_modules/core-js/internals/to-string-tag-support.js", + "node_modules/core-js/internals/to-string.js", + "node_modules/core-js/internals/try-to-string.js", + "node_modules/core-js/internals/uid.js", + "node_modules/core-js/internals/use-symbol-as-uid.js", + "node_modules/core-js/internals/v8-prototype-define-bug.js", + "node_modules/core-js/internals/validate-arguments-length.js", + "node_modules/core-js/internals/well-known-symbol-wrapped.js", + "node_modules/core-js/internals/well-known-symbol.js", + "node_modules/core-js/modules/es.aggregate-error.js", + "node_modules/core-js/modules/es.array.concat.js", + "node_modules/core-js/modules/es.array.iterator.js", + "node_modules/core-js/modules/es.json.to-string-tag.js", + "node_modules/core-js/modules/es.math.to-string-tag.js", + "node_modules/core-js/modules/es.object.to-string.js", + "node_modules/core-js/modules/es.promise.all-settled.js", + "node_modules/core-js/modules/es.promise.any.js", + "node_modules/core-js/modules/es.promise.finally.js", + "node_modules/core-js/modules/es.promise.js", + "node_modules/core-js/modules/es.reflect.to-string-tag.js", + "node_modules/core-js/modules/es.string.iterator.js", + "node_modules/core-js/modules/es.symbol.async-iterator.js", + "node_modules/core-js/modules/es.symbol.description.js", + "node_modules/core-js/modules/es.symbol.has-instance.js", + "node_modules/core-js/modules/es.symbol.is-concat-spreadable.js", + "node_modules/core-js/modules/es.symbol.iterator.js", + "node_modules/core-js/modules/es.symbol.js", + "node_modules/core-js/modules/es.symbol.match-all.js", + "node_modules/core-js/modules/es.symbol.match.js", + "node_modules/core-js/modules/es.symbol.replace.js", + "node_modules/core-js/modules/es.symbol.search.js", + "node_modules/core-js/modules/es.symbol.species.js", + "node_modules/core-js/modules/es.symbol.split.js", + "node_modules/core-js/modules/es.symbol.to-primitive.js", + "node_modules/core-js/modules/es.symbol.to-string-tag.js", + "node_modules/core-js/modules/es.symbol.unscopables.js", + "node_modules/core-js/modules/web.dom-collections.iterator.js", + "node_modules/core-js/stable/promise/index.js", + "node_modules/core-js/stable/symbol/index.js" + ] + }, + { + "name": "copy-text-to-clipboard", + "version": "3.0.1", + "tarball": "https://registry.npmjs.org/copy-text-to-clipboard/-/copy-text-to-clipboard-3.0.1.tgz", + "integrity": "sha512-rvVsHrpFcL4F2P8ihsoLdFHmd404+CMg71S756oRSeQgqk51U3kicGdnvfkrxva0xXH92SjGS62B0XIJsbh+9Q==", + "archiveSha256": "f503f0000bfd090c6ab13ff0133f45c454b0601f4693070ab5f9370f6b257f43", + "noticeMember": "package/license", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt", + "target": "docs/licenses/vconsole/copy-text-to-clipboard/LICENSE", + "sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/copy-text-to-clipboard/index.js" + ] + }, + { + "name": "mutation-observer", + "version": "1.0.3", + "tarball": "https://registry.npmjs.org/mutation-observer/-/mutation-observer-1.0.3.tgz", + "integrity": "sha512-M/O/4rF2h776hV7qGMZUH3utZLO/jK7p8rnNgGkjKUw8zCGjRQPxB8z6+5l8+VjRUQ3dNYu4vjqXYLr+U8ZVNA==", + "archiveSha256": "6fba66a0fc7af58492d5b7b1ced4e8bb639e9cc0b5dbfb6d7981cb102948b882", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt", + "target": "docs/licenses/vconsole/mutation-observer/LICENSE", + "sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179" + }, + "license": "Two BSD 3-clause notices (Automattic and Polymer Authors)", + "runtimeResources": [ + "node_modules/mutation-observer/index.js" + ] + }, + { + "name": "svelte", + "version": "3.47.0", + "tarball": "https://registry.npmjs.org/svelte/-/svelte-3.47.0.tgz", + "integrity": "sha512-4JaJp3HEoTCGARRWZQIZDUanhYv0iyoHikklVHVLH9xFE9db22g4TDv7CPeNA8HD1JgjXI1vlhR1JZvvhaTu2Q==", + "archiveSha256": "d446bc9f1260da0e64b4ff7a002126b432d70f466ae9e5390a4a66ab88fb9bd9", + "noticeMember": "package/LICENSE.md", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt", + "target": "docs/licenses/vconsole/svelte/LICENSE", + "sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/svelte/index.mjs", + "node_modules/svelte/internal/index.mjs", + "node_modules/svelte/store/index.mjs" + ] + }, + { + "name": "regenerator-runtime", + "version": "0.13.9", + "tarball": "https://registry.npmjs.org/regenerator-runtime/-/regenerator-runtime-0.13.9.tgz", + "integrity": "sha512-p3VT+cOEgxFsRRA9X4lkI1E+k2/CtnKtU4gcxyaCUreilL/vqI6CdZ3wxVUx3UOUg+gnUOQQcRI7BmSI656MYA==", + "archiveSha256": "1a6b5437215dc6558817acfd9f8300f5519475ddc8f9f55bec243c622fd099b8", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt", + "target": "docs/licenses/vconsole/regenerator-runtime/LICENSE", + "sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/regenerator-runtime/runtime.js" + ] + }, + { + "name": "style-loader", + "version": "3.3.1", + "tarball": "https://registry.npmjs.org/style-loader/-/style-loader-3.3.1.tgz", + "integrity": "sha512-GPcQ+LDJbrcxHORTRes6Jy2sfvK2kS6hpSfI/fXhPt+spVzxF6LJ1dHLN9zIGmVaaP044YKaIatFaufENRiDoQ==", + "archiveSha256": "26bccc234f5fe61e39e5e9d6f253bd78208ade1037bed388fc9e5effb06f3627", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt", + "target": "docs/licenses/vconsole/style-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/style-loader/dist/runtime/injectStylesIntoStyleTag.js", + "node_modules/style-loader/dist/runtime/insertBySelector.js", + "node_modules/style-loader/dist/runtime/insertStyleElement.js", + "node_modules/style-loader/dist/runtime/setAttributesWithoutAttributes.js", + "node_modules/style-loader/dist/runtime/styleDomAPI.js", + "node_modules/style-loader/dist/runtime/styleTagTransform.js" + ] + }, + { + "name": "css-loader", + "version": "6.7.1", + "tarball": "https://registry.npmjs.org/css-loader/-/css-loader-6.7.1.tgz", + "integrity": "sha512-yB5CNFa14MbPJcomwNh3wLThtkZgcNyI2bNMRt8iE5Z8Vwl7f8vQXFAzn2HDOJvtDq2NTZBUGMSUNNyrv3/+cw==", + "archiveSha256": "dbca9bdbcb72f7f8e84c715104fb55b66b34dcae75bb09da2770f5743273cfd8", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt", + "target": "docs/licenses/vconsole/css-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + "license": "MIT", + "runtimeResources": [ + "node_modules/css-loader/dist/runtime/api.js", + "node_modules/css-loader/dist/runtime/noSourceMaps.js" + ] + }, + { + "name": "webpack", + "version": "5.72.0", + "tarball": "https://registry.npmjs.org/webpack/-/webpack-5.72.0.tgz", + "integrity": "sha512-qmSmbspI0Qo5ld49htys8GY9XhS9CGqFoHTsOVAnjBdg0Zn79y135R+k4IR4rKK6+eKaabMhJwiVB7xw0SJu5w==", + "archiveSha256": "2aeb4cf8d9fffced8a1fa24183dbe8d6a821c88662db6d2e019365db2fe5731b", + "noticeMember": "package/LICENSE", + "notice": { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt", + "target": "docs/licenses/vconsole/webpack/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + "license": "MIT", + "runtimeResources": [ + "webpack/runtime/compat get default export", + "webpack/runtime/define property getters", + "webpack/runtime/global", + "webpack/runtime/hasOwnProperty shorthand" + ] + } + ], + "supplement": { + "source": "https://opensource.org/license/mit", + "basis": "Original vConsole 3.15.0 bundle explicitly links this MIT license; original Tencent notice is retained. Supplemental MIT body and attribution are authored assemblies, not verbatim upstream files.", + "notices": [ + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE", + "target": "docs/licenses/vconsole/MIT-LICENSE", + "sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt", + "target": "docs/licenses/vconsole/ATTRIBUTION.md", + "sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3" + } + ] + }, + "limits": [ + "Build-only dependencies are not claimed to be runtime components; css/style runtime helpers and webpack bootstrap are included.", + "Remote source archive host failed DNS; all 81 required source/config files were instead fetched from fixed raw GitHub paths and verified against Git tree blob IDs.", + "Real devices and other site components remain separate gates." + ] +} diff --git a/refactor/baselines/vconsole-notices-validation.json b/refactor/baselines/vconsole-notices-validation.json new file mode 100644 index 000000000..aa2761265 --- /dev/null +++ b/refactor/baselines/vconsole-notices-validation.json @@ -0,0 +1,441 @@ +{ + "schemaVersion": 1, + "task": "SITE-07", + "baseCommit": "bf432ed62a8206fd388ab0cbd4052eccc5e7e192", + "node": "24.21.0", + "yarn": "1.22.22", + "reconstruction": { + "command": "node scripts/site-vendor/vconsole/reproduce.ts refactor/.cache/site07-vconsole-notices/upstream-build", + "exitCode": 0, + "exactBundle": true, + "sha256": "671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4", + "resources": 189, + "notices": 9, + "warnings": [ + { + "message": "asset size limit: The following asset(s) exceed the recommended size limit (244 KiB).\nThis can impact web performance.\nAssets: \n vconsole.min.js (276 KiB)", + "stack": "AssetsOverSizeLimitWarning: asset size limit: The following asset(s) exceed the recommended size limit (244 KiB).\nThis can impact web performance.\nAssets: \n vconsole.min.js (276 KiB)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\performance\\SizeLimitsPlugin.js:134:7\n at Hook.eval [as callAsync] (eval at create (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\HookCodeFactory.js:33:10), :9:1)\n at Hook.CALL_ASYNC_DELEGATE [as _callAsync] (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\Hook.js:18:14)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:882:27\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:2818:7\n at done (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:3522:9)\n at alreadyWritten (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:714:8)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:802:19\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\graceful-fs\\graceful-fs.js:123:16\n at FSReqCallback.readFileAfterClose [as oncomplete] (node:internal/fs/read/context:96:3)" + }, + { + "message": "entrypoint size limit: The following entrypoint(s) combined asset size exceeds the recommended limit (244 KiB). This can impact web performance.\nEntrypoints:\n vconsole (276 KiB)\n vconsole.min.js\n", + "stack": "EntrypointsOverSizeLimitWarning: entrypoint size limit: The following entrypoint(s) combined asset size exceeds the recommended limit (244 KiB). This can impact web performance.\nEntrypoints:\n vconsole (276 KiB)\n vconsole.min.js\n\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\performance\\SizeLimitsPlugin.js:139:7\n at Hook.eval [as callAsync] (eval at create (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\HookCodeFactory.js:33:10), :9:1)\n at Hook.CALL_ASYNC_DELEGATE [as _callAsync] (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\Hook.js:18:14)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:882:27\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:2818:7\n at done (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:3522:9)\n at alreadyWritten (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:714:8)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:802:19\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\graceful-fs\\graceful-fs.js:123:16\n at FSReqCallback.readFileAfterClose [as oncomplete] (node:internal/fs/read/context:96:3)" + }, + { + "message": "webpack performance recommendations: \nYou can limit the size of your bundles by using import() or require.ensure to lazy load some parts of your application.\nFor more info visit https://webpack.js.org/guides/code-splitting/", + "stack": "NoAsyncChunksWarning: webpack performance recommendations: \nYou can limit the size of your bundles by using import() or require.ensure to lazy load some parts of your application.\nFor more info visit https://webpack.js.org/guides/code-splitting/\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\performance\\SizeLimitsPlugin.js:153:21\n at Hook.eval [as callAsync] (eval at create (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\HookCodeFactory.js:33:10), :9:1)\n at Hook.CALL_ASYNC_DELEGATE [as _callAsync] (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\tapable\\lib\\Hook.js:18:14)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:882:27\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:2818:7\n at done (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\neo-async\\async.js:3522:9)\n at alreadyWritten (D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:714:8)\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\webpack\\lib\\Compiler.js:802:19\n at D:\\github\\ArtPlayer\\refactor\\.cache\\site07-vconsole-notices\\upstream-build\\node_modules\\graceful-fs\\graceful-fs.js:123:16\n at FSReqCallback.readFileAfterClose [as oncomplete] (node:internal/fs/read/context:96:3)" + } + ], + "negative": [ + { + "case": "changed frozen source", + "exitCode": 1, + "rejectedBeforeBuild": true + }, + { + "case": "repository input outside ignored cache", + "exitCode": 1, + "rejectedBeforeBuild": true + } + ] + }, + "browser": { + "command": "node node_modules/@playwright/test/cli.js test test/browser/site-vendor.spec.js --workers=1", + "exitCode": 0, + "reportPath": "refactor/.cache/site07-vconsole-notices-browser-report/report.json", + "reportSha256": "505aae95946de005cc802cdcb428492f7ac0b6c47b2d5466522d8525b0fec28e", + "stats": { + "startTime": "2026-09-14T21:18:02.545Z", + "duration": 10239.792, + "expected": 3, + "skipped": 0, + "unexpected": 0, + "flaky": 0 + }, + "cases": [ + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "chromium", + "status": "passed", + "retry": 0, + "browser": "153.0.8010.12", + "platform": "win32", + "errors": [], + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/babel-runtime/LICENSE", + "sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/core-js/LICENSE", + "sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/copy-text-to-clipboard/LICENSE", + "sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/mutation-observer/LICENSE", + "sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/svelte/LICENSE", + "sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/regenerator-runtime/LICENSE", + "sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/style-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/css-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/webpack/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/MIT-LICENSE", + "sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/ATTRIBUTION.md", + "sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + }, + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "firefox", + "status": "passed", + "retry": 0, + "browser": "155.0", + "platform": "win32", + "errors": [], + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/babel-runtime/LICENSE", + "sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/core-js/LICENSE", + "sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/copy-text-to-clipboard/LICENSE", + "sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/mutation-observer/LICENSE", + "sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/svelte/LICENSE", + "sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/regenerator-runtime/LICENSE", + "sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/style-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/css-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/webpack/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/MIT-LICENSE", + "sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/ATTRIBUTION.md", + "sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + }, + { + "title": "mobile vConsole shows logs and upstream site notice texts are served unchanged", + "project": "webkit", + "status": "passed", + "retry": 0, + "browser": "26.6", + "platform": "win32", + "errors": [], + "notices": [ + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/LICENSE", + "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/babel-runtime/LICENSE", + "sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/core-js/LICENSE", + "sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/copy-text-to-clipboard/LICENSE", + "sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/mutation-observer/LICENSE", + "sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/svelte/LICENSE", + "sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/regenerator-runtime/LICENSE", + "sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/style-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/css-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/webpack/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/MIT-LICENSE", + "sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217" + }, + { + "component": "vconsole", + "version": "3.15.0", + "url": "http://127.0.0.1:8084/licenses/vconsole/ATTRIBUTION.md", + "sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/LICENSE", + "sha256": "33e4ff1a06ef62ba21788ea162564ee8165269a24a9ce6ef301837447eab0ac6" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/ThirdPartyNotices.txt", + "sha256": "b23ab6e9a1a31ce6948a98b16a83474c999a384ece75643dd0affc83ea1724ef" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE", + "sha256": "d6239afa918961b465b07bf7411cbe34ff6685854f58553db7966f4881a0211f" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/LICENSE-CODE", + "sha256": "9906940f61b1f0b533fa7d99baf55178b2808fbe113ea51dfbfad8572ccd5f2b" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/README.md", + "sha256": "3d53172e204bcbf282c360fe58bf0697de97ddd27c964a6e48823fb4f7cd6689" + }, + { + "component": "monaco-editor", + "version": "0.30.1", + "url": "http://127.0.0.1:8084/licenses/monaco-editor/codicons/ATTRIBUTION.md", + "sha256": "ac4a57ce60aebaec1796b715d075273c4fd849853cd943fb92790c61ad038a5f" + } + ] + } + ] + }, + "unit": { + "command": "node --test test/site-notices.test.js test/vconsole-lifecycle.test.js test/pages-artifact.test.js", + "exitCode": 0, + "passed": 17, + "durationMs": 559.5656, + "log": "refactor/.cache/site07-vconsole-notices-tests-final.log" + }, + "checks": [ + "strict docs-tools TypeScript", + "scoped ESLint", + "build:site-notices", + "check:site-notices", + "check:vconsole" + ], + "runtimeAssetChanged": false, + "limitations": [ + "Windows automated engines with local playback, not physical device or remote CI evidence", + "Other SITE-07 components/fonts/media remain independent", + "No full-site or full-installed-ecosystem regression run for this notice-only change" + ], + "rootLint": { + "exitCode": 1, + "log": "refactor/.cache/site07-vconsole-notices-lint.log", + "error": "Pre-existing VAST package.json dependencies/typesVersions key ordering", + "warning": "Pre-existing docs/assets/ts/artplayer.d.ts unused namespace disable", + "followUp": "Separate engineering fix after this SITE-07 checkpoint" + } +} diff --git a/refactor/changes/2026-09-15-SITE-07-vconsole-notices.md b/refactor/changes/2026-09-15-SITE-07-vconsole-notices.md new file mode 100644 index 000000000..7cae17ae9 --- /dev/null +++ b/refactor/changes/2026-09-15-SITE-07-vconsole-notices.md @@ -0,0 +1,57 @@ +# SITE-07 vConsole 可复现来源与完整通知 + +## 结果与依据 + +vConsole 3.15.0 的历史 LICENSE 声称附带 MIT 全文,实际没有正文。发布 bundle +及固定构建配置明确引用 MIT 原文。保留旧 LICENSE,另补 MIT-LICENSE 和署名说明, +明确它们是 ArtPlayer 补充整理的文件,不伪称从 Tencent 归档逐字复制。 +依据为[发布脚本](../../scripts/site-vendor/vconsole/upstream.js)头部以及其引用的 +[MIT 原文](https://opensource.org/license/mit)。 + +从固定提交 05d80398bae35e793774f74e3c052b4e530e293a 取得 81 份源文件/配置, +逐个验证 Git blob ID 和 SHA-256。在 ignored cache 用原始 package-lock.json +执行 npm ci --ignore-scripts --no-audit --no-fund,安装 520 包、退出 0。 +这是上游历史重建,不改变 ArtPlayer 的 Yarn 1.22.22、根 yarn.lock 或依赖。 +源码 archive 主机 DNS 失败后改用固定 raw 路径,没有用其他版本代替。 + +构建结果 282,381 字节,与原始 npm bundle **逐字节一致**,SHA-256 为 +671f47427e1e3048919147c765e9fb71e4ea40d79a8c2829089f499d3e9b9bf4。 +首次 stats 隐藏 orphan/runtime 分组,不能据此声称完整。改为不分组且不截断, +取得 326 条模块记录:八个依赖及 webpack 的四个 bootstrap 模块;从实际 resource +识别,排除了只出现在 loader 链的 less-loader。原始锁文件版本、重建字节和 +模块路径共同建立来源依据,不仅凭 dependency 字段猜测。 + +九个组件的 npm 归档均按固定 SRI 校验,保存完整原文。mutation-observer 的 +Automattic/Polymer Authors 两份 BSD 通知均保留;其余组件 MIT 各自署名保留。 +固定证据和重跑输入见[来源记录](../baselines/vconsole-notices-provenance.json)。 + +## 实现与验证 + +- 原 notice 生成流程增加 vConsole 九个组件及补充文件;CLI 拒绝漏掉已核实组件、 + 原始 LICENSE、补充 MIT 或署名。全部站点通知现在是 19 个输出(18 份文本加索引)。 +- 新增 TS 重建校验入口:固定输入及依赖版本检查、精确 bundle 比较、不截断模块 + 清单核对,脚本名 verify:vconsole-source。只在 cache 重建,不触碰站点 patched bundle。维护方法见 + [vConsole 模块说明](../../scripts/site-vendor/vconsole/README.md)。 +- 正向重建验证通过;改动冻结源码和使用 cache 外目录的两个实际负例均在构建前 + 拒绝,产物未被重写,注入的源码改动已恢复。没有运行上游安装脚本。 +- notice、vConsole 生命周期和 Pages 资产测试最终 17/17,559.57ms;新增 CLI 负例 + 要求删除任一核心通知或 webpack 组件在写出前失败。strict docs-tools、 + scoped lint、check:vconsole、build/check:site-notices 通过。 + 首次 lint 的数组换行和 require 后空行问题已修正并重新检查。 +- 扩大到全仓 lint 后发现未改动的 VAST package.json 键顺序错误,以及已有生成 + 声明的 unused-disable 警告;本批 scoped lint 通过,全仓 lint 本轮退出 1。 + 键顺序错误单独作为后续工程修复提交,不把全仓检查写成通过。 +- 三种真实浏览器移动页面 3/3,包含日志、真实本地媒体播放、销毁、全部 18 份通知 + HTTP 原文、原字体指纹和索引。具体版本、报告及退出状态见 + [验证记录](../baselines/vconsole-notices-validation.json)。未重跑全站、全包安装矩阵。 +- 原构建保留 size/entry/performance 和旧 Browserslist 警告,不为消除历史警告更新 + 锁文件或改变发布内容。站点 vConsole 的本地生命周期补丁及 JS 字节保持原样。 + +## 状态与后续 + +VENDOR-07 的本版本来源/完整通知缺口据上述证据关闭;SITE-07 仍 doing。 +Monaco 全组件通知、console.js 来源、其他字体与样本仍需处理,不扩大为全站许可 +放行。物理设备、远端 CI/Pages/npm 和多轮发布审查保持独立门槛。 + +本批为 SITE-07 本地检查点提交,未推送或发布。回退仅还原补充通知、manifest、 +生成输出、校验和文档,生产 JS 无需回退。后续继续 console.js 可复现来源/替代。 diff --git a/refactor/plan.md b/refactor/plan.md index fa5cae875..0585d543e 100644 --- a/refactor/plan.md +++ b/refactor/plan.md @@ -651,7 +651,7 @@ - SITE-AI-DOCS-01: [记录](changes/2026-09-14-SITE-AI-DOCS-01-documentation-pipeline.md) [记录](baselines/documentation-pipeline-validation.json) - SITE-BUILD-01: [记录](changes/2026-09-14-SITE-BUILD-01-staged-builds.md) [记录](baselines/site-build-validation.json) - SITE-03: [记录](changes/2026-09-14-SITE-03-desktop-editor.md) [记录](baselines/site-editor-validation.json) -- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) +- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) - EX-01: [记录](changes/2026-09-14-EX-01-react-consumer.md) [记录](baselines/react-consumer-validation.json) [记录](scripts/react-consumer.mjs) - EX-02: [记录](changes/2026-09-14-EX-02-vue-consumer.md) [记录](baselines/vue-consumer-validation.json) [记录](scripts/vue-consumer.mjs) - MOD-01: [记录](changes/2026-09-15-MOD-01-bun-evaluation.md) [记录](baselines/bun-install-validation.json) [记录](bun-evaluation.md) diff --git a/refactor/progress.md b/refactor/progress.md index c99b9aef2..a7af8b0a6 100644 --- a/refactor/progress.md +++ b/refactor/progress.md @@ -1,5 +1,12 @@ # 进度与证据 +## SITE-07 vConsole 精确重建与完整通知 + +固定源码/锁文件重建与 npm 3.15.0 逐字节一致;补齐 MIT 正文、署名及九个运行时 +组件的许可。VENDOR-07 本版本来源/通知风险关闭,原生命周期补丁不变。三浏览器 +3/3、工程测试17/17通过,见[记录](changes/2026-09-15-SITE-07-vconsole-notices.md)。 +197/263 完成,SITE-07 仍 doing;继续 console.js、Monaco 复核和其他字体媒体。 + ## SITE-07 Codicons 历史字体来源与通知 字体精确匹配官方 npm 0.0.26,补原始许可/README和署名,运行时内容及旧 URL 不变。 diff --git a/refactor/risk-table.md b/refactor/risk-table.md index 0752deb27..7ddaf80ba 100644 --- a/refactor/risk-table.md +++ b/refactor/risk-table.md @@ -31,7 +31,7 @@ | VENDOR-04 | open / 源码/产物事实 | jassub-code-and-workers 来源、版本与许可闭环 | PKG-JASSUB-01, PKG-JASSUB-06 | | VENDOR-05 | open / 源码/产物事实 | jassub-font-assets 来源、版本与许可闭环 | PKG-JASSUB-01, SITE-01, PKG-JASSUB-06, SITE-07 | | VENDOR-06 | open / 源码/产物事实 | monaco-static-assets 来源、版本与许可闭环 | SITE-01, SITE-05, SITE-07 | -| VENDOR-07 | open / 源码/产物事实 | vconsole 来源、版本与许可闭环 | SITE-01, SITE-07 | +| VENDOR-07 | resolved / 源码/产物事实 | vconsole 来源、版本与许可闭环 | SITE-01, SITE-07 | | VENDOR-08 | open / 待取证 | console-bundle 来源、版本与许可闭环 | SITE-01, SITE-07 | | SDK-01 | open / 源码/产物事实 | hls.js 实际集成验证范围 | PKG-HLS-05, EX-03 | | SDK-02 | open / 待取证 | dash.js 实际集成验证范围 | PKG-DASH-01, EX-03, PKG-DASH-05 | diff --git a/refactor/risks.json b/refactor/risks.json index 5bbdad06c..b539445ab 100644 --- a/refactor/risks.json +++ b/refactor/risks.json @@ -634,7 +634,7 @@ "id": "VENDOR-07", "title": "vconsole 来源、版本与许可闭环", "confirmation": "source-observed", - "status": "open", + "status": "resolved", "owners": [ "SITE-01", "SITE-07" @@ -646,11 +646,22 @@ "refactor/baselines/site-provenance.json", "refactor/changes/2026-09-14-SITE-07-vendor-notices.md", "refactor/baselines/site-notices-checkpoint.json", - "scripts/site-vendor/manifest.json" + "scripts/site-vendor/manifest.json", + "refactor/baselines/vconsole-notices-provenance.json", + "refactor/baselines/vconsole-notices-validation.json", + "refactor/changes/2026-09-15-SITE-07-vconsole-notices.md" ], "compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.", "closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。", - "workspaceState": "Upstream 3.15.0 LICENSE copied verbatim but promises an absent MIT body; body and bundled dependency notices remain open. The historical mobile WebKit destruction defect was separately fixed by SITE-VCONSOLE-01; current three-engine site checks retain and pass destruction assertions." + "workspaceState": "Fixed-commit sources and original lockfile reproduce npm vConsole 3.15.0 exactly. Untruncated module resources identify eight bundled package runtimes plus webpack bootstrap, whose complete original license texts now ship. The original incomplete LICENSE is preserved and the explicitly referenced MIT body is separately supplied and attributed. Three native browser mobile/log/play/destroy cases serve all notice bytes exactly; the previously fixed local lifecycle patch is unchanged. This closes this vConsole source/notice risk, not whole-site, device or release gates.", + "resolutionEvidence": [ + "refactor/baselines/vconsole-notices-provenance.json", + "refactor/baselines/vconsole-notices-validation.json", + "refactor/changes/2026-09-15-SITE-07-vconsole-notices.md", + "scripts/site-vendor/manifest.json", + "scripts/site-vendor/vconsole/reproduce.ts" + ], + "resolutionRationale": "Fixed-commit sources and original lockfile reproduce npm vConsole 3.15.0 exactly. Untruncated module resources identify eight bundled package runtimes plus webpack bootstrap, whose complete original license texts now ship. The original incomplete LICENSE is preserved and the explicitly referenced MIT body is separately supplied and attributed. Three native browser mobile/log/play/destroy cases serve all notice bytes exactly; the previously fixed local lifecycle patch is unchanged. This closes this vConsole source/notice risk, not whole-site, device or release gates." }, { "id": "VENDOR-08", diff --git a/refactor/site-inventory.md b/refactor/site-inventory.md index 73606de10..958ce961e 100644 --- a/refactor/site-inventory.md +++ b/refactor/site-inventory.md @@ -1,5 +1,10 @@ # 文档站、示例与生成链清单 +2026-09-15后续:vConsole 3.15.0 已由固定源码/锁文件精确重建,补原始声明所引用的 +MIT 正文和九个运行时组件的完整通知;VENDOR-07 关闭。三引擎真实播放/日志/销毁及 +全部 HTTP 通知 3/3 通过。见[当前记录](changes/2026-09-15-SITE-07-vconsole-notices.md)。 +下面的许可缺口描述属于先前检查点;其他站点来源/字体/媒体门槛继续保留。 + SITE-07检查点已将Monaco LICENSE/ThirdPartyNotices和vConsole上游LICENSE原文加入 站点分发,并建立固定文件清单/指纹及只读检查。进一步检查发现vConsole上游文件 只有许可声明,缺其声称附带的MIT全文;不能把“已取得LICENSE”当成完整许可闭环。 diff --git a/refactor/tasks.json b/refactor/tasks.json index c77b1ddd7..35ba65e6f 100644 --- a/refactor/tasks.json +++ b/refactor/tasks.json @@ -4480,7 +4480,10 @@ "baselines/site-notices-checkpoint.json", "baselines/site-codicons-provenance.json", "baselines/site-codicons-validation.json", - "changes/2026-09-15-SITE-07-codicons.md" + "changes/2026-09-15-SITE-07-codicons.md", + "baselines/vconsole-notices-provenance.json", + "baselines/vconsole-notices-validation.json", + "changes/2026-09-15-SITE-07-vconsole-notices.md" ] }, { diff --git a/refactor/third-party.json b/refactor/third-party.json index 7fd061667..5c6920040 100644 --- a/refactor/third-party.json +++ b/refactor/third-party.json @@ -1029,13 +1029,14 @@ "SITE-07", "SITE-VCONSOLE-01" ], - "sourceStatus": "Frozen npm 3.15.0 bundle, with reproducible six-hook lifecycle patch; see scripts/site-vendor/vconsole/README.md.", - "licenseStatus": "Original npm LICENSE is distributed verbatim but lacks its promised MIT body; bundled dependency notices remain open in VENDOR-07.", + "sourceStatus": "Exact 282381-byte reconstruction of npm 3.15.0 from commit 05d80398bae35e793774f74e3c052b4e530e293a and its frozen npm lockfile; 326 untruncated module records establish eight runtime package dependencies and webpack bootstrap. ArtPlayer retains the separate reviewed lifecycle patch.", + "licenseStatus": "Original vConsole LICENSE retained; missing referenced MIT text supplied separately with explicit attribution. All nine runtime-component notices are preserved in full, including both mutation-observer BSD notices. Actual HTTP delivery and fingerprints verified; see vconsole-notices-provenance/validation.json.", "upstreamSources": [ "https://registry.npmjs.org/vconsole/-/vconsole-3.15.0.tgz", - "https://github.com/Tencent/vConsole/tree/05d80398bae35e793774f74e3c052b4e530e293a" + "https://github.com/Tencent/vConsole/tree/05d80398bae35e793774f74e3c052b4e530e293a", + "https://opensource.org/license/mit" ], - "upstreamReviewedAt": "2026-09-14", + "upstreamReviewedAt": "2026-09-15", "updatePolicy": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.", "fingerprints": [ { diff --git a/scripts/build-site-notices.mjs b/scripts/build-site-notices.mjs index 3451eebc6..2cb2c3b15 100644 --- a/scripts/build-site-notices.mjs +++ b/scripts/build-site-notices.mjs @@ -7,6 +7,20 @@ assert(process.argv.slice(2).every(arg => arg === '--check'), 'Use yarn build:si /** @type {import('./site-vendor/notices.ts').VendorManifest} */ const manifest = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8')) assert.deepEqual(manifest.groups.map(group => group.name).sort(), ['monaco-editor', 'vconsole'], 'Do not silently drop a verified site component') -assert.deepEqual(manifest.groups.flatMap(group => (group.components || []).map(component => component.name)), ['@vscode/codicons'], 'Do not silently drop the verified Codicons attribution') +assert.deepEqual(manifest.groups.flatMap(group => (group.components || []).map(component => component.name)).sort(), [ + '@babel/runtime', + '@vscode/codicons', + 'copy-text-to-clipboard', + 'core-js', + 'css-loader', + 'mutation-observer', + 'regenerator-runtime', + 'style-loader', + 'svelte', + 'webpack', +], 'Do not silently drop verified bundled component attribution') +const vconsoleNotices = manifest.groups.find(group => group.name === 'vconsole')?.notices.map(notice => notice.target) +for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md']) + assert(vconsoleNotices?.includes(`docs/licenses/vconsole/${name}`), `Missing vConsole notice: ${name}`) const count = writeOrCheckNotices(process.cwd(), manifest, process.argv.includes('--check')) console.log(`Verified site notices: ${count} outputs; Monaco/vConsole only, other provenance gates remain open.`) diff --git a/scripts/site-vendor/README.md b/scripts/site-vendor/README.md index 9b3bebeb3..c23b7c43b 100644 --- a/scripts/site-vendor/README.md +++ b/scripts/site-vendor/README.md @@ -3,8 +3,10 @@ `manifest.json` pins the already-identified Monaco 0.30.1 and vConsole 3.15.0 archives, corresponding files and upstream notice texts. It does not clear other site dependencies or grant rights to samples/fonts. The vConsole LICENSE is -preserved verbatim but is incomplete: it promises an MIT copy that is absent. -Its completion and bundled dependency notices remain open under SITE-07. +preserved verbatim. A separately identified MIT text supplies the body referenced +by the original bundle, alongside the full notices for eight bundled dependencies +and webpack's generated bootstrap. Fixed-source reconstruction verifies their +identity; see `vconsole/README.md` and `vconsole/reproduce.ts`. Monaco's supplied notices lack a Codicons entry. The bundled font now has an exact byte match to the official `@vscode/codicons@0.0.26` archive. Its historical README, CC BY 4.0 content license and MIT code license are preserved, alongside @@ -20,7 +22,8 @@ files retain their exact upstream bytes, including final blank lines. `../build-site-notices.mjs` provides `yarn build:site-notices` and read-only `yarn check:site-notices`. The write command cannot bless altered vendor assets; review the new archive and license evidence before changing the manifest. The -CLI prevents accidentally dropping either verified group or the Codicons component. +CLI prevents accidentally dropping either verified group, the ten reviewed nested +components, or vConsole's original license, supplemental MIT body and attribution. Component references require their runtime assets and every notice before writing. Source notices live in `refactor/baselines/site-vendor/`; generated delivery files live under @@ -52,6 +55,6 @@ members as Buffers. Compare `package/dist/codicon.ttf` directly with `fontPath`, and each non-null notice member with its frozen `source`. Do not pipe binary font output through PowerShell text redirection. No dependency installation is needed. -Follow-up: finish the broader bundled-component notice audit, then recover the +Follow-up: finish Monaco's broader bundled-component notice audit, then recover the console.js build and resolve remaining fonts/media. Do not upgrade these assets without verifying globals, AMD/worker paths, CSS, consoleLog and user interaction. diff --git a/scripts/site-vendor/manifest.json b/scripts/site-vendor/manifest.json index b5352ea6f..3c916385d 100644 --- a/scripts/site-vendor/manifest.json +++ b/scripts/site-vendor/manifest.json @@ -26,9 +26,165 @@ "source": "refactor/baselines/site-vendor/vconsole-LICENSE.txt", "target": "docs/licenses/vconsole/LICENSE", "sha256": "272588ba6d7c09d6c3bedf3601e37b2ede6d4539d28a9052fcc3038df99cf683" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/babel-runtime-LICENSE.txt", + "target": "docs/licenses/vconsole/babel-runtime/LICENSE", + "sha256": "117da2af0d4ce0fe1c8e19b5cff9dcd806adf973d328d27b11d4448c4ff24f76" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/core-js-LICENSE.txt", + "target": "docs/licenses/vconsole/core-js/LICENSE", + "sha256": "e1dad265f157187a8b0290f57b3c6807d94c322ffbcdf75ab82b638eb52b1789" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/copy-text-to-clipboard-LICENSE.txt", + "target": "docs/licenses/vconsole/copy-text-to-clipboard/LICENSE", + "sha256": "5c932d88256b4ab958f64a856fa48e8bd1f55bc1d96b8149c65689e0c61789d3" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/mutation-observer-LICENSE.txt", + "target": "docs/licenses/vconsole/mutation-observer/LICENSE", + "sha256": "1e6f3f536e6e589b5c807d144c60b583bc10d78f7ae6cfba4c0baba4a72a8179" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/svelte-LICENSE.txt", + "target": "docs/licenses/vconsole/svelte/LICENSE", + "sha256": "1b790e7defe7121ad9a2e065df61d45f3e4080ffc6a0f79b4a46941bcd70be56" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/regenerator-runtime-LICENSE.txt", + "target": "docs/licenses/vconsole/regenerator-runtime/LICENSE", + "sha256": "51887a3d47051ac2fce1210562e5b9fe0830a8a8fabeb272c2d586eeb18a05fd" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/style-loader-LICENSE.txt", + "target": "docs/licenses/vconsole/style-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/css-loader-LICENSE.txt", + "target": "docs/licenses/vconsole/css-loader/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/webpack-LICENSE.txt", + "target": "docs/licenses/vconsole/webpack/LICENSE", + "sha256": "9068a8782d2fb4c6e432cfa25334efa56f722822180570802bf86e71b6003b1e" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/MIT-LICENSE", + "target": "docs/licenses/vconsole/MIT-LICENSE", + "sha256": "dda328fe74b6a80e515d24827d1f15bdefcf2db82c3bcb9e490032b98dd46217" + }, + { + "source": "refactor/baselines/site-vendor/vconsole-3.15.0/ATTRIBUTION.txt", + "target": "docs/licenses/vconsole/ATTRIBUTION.md", + "sha256": "72e1b273fc12248f5d120f33cdaab54f0421f31cfc2b3e99edd130fb32a6cfc3" } ], - "review": "The 3.15.0 upstream LICENSE declares MIT but omits the promised full license text. The copied file preserves this upstream evidence; completeness and bundled dependency notices remain under review. ArtPlayer applies a reproducible local lifecycle patch to log frame cancellation and delayed panel ownership; the upstream bundle is frozen in scripts/site-vendor/vconsole/upstream.js and generated by yarn build:vconsole. Public asset URL and UMD/CSS contracts are retained." + "review": "The original 3.15.0 LICENSE is preserved unchanged; its missing MIT body is supplemented separately using the MIT text explicitly referenced by upstream. Exact reconstruction from the pinned source and lockfile establishes eight bundled package dependencies and webpack bootstrap; their complete notices and attribution are distributed below. ArtPlayer retains its reproducible lifecycle patch and the original script URL/UMD/CSS contracts.", + "components": [ + { + "name": "@babel/runtime", + "version": "7.17.9", + "tarball": "https://registry.npmjs.org/@babel/runtime/-/runtime-7.17.9.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/babel-runtime/LICENSE" + ] + }, + { + "name": "core-js", + "version": "3.21.1", + "tarball": "https://registry.npmjs.org/core-js/-/core-js-3.21.1.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/core-js/LICENSE" + ] + }, + { + "name": "copy-text-to-clipboard", + "version": "3.0.1", + "tarball": "https://registry.npmjs.org/copy-text-to-clipboard/-/copy-text-to-clipboard-3.0.1.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/copy-text-to-clipboard/LICENSE" + ] + }, + { + "name": "mutation-observer", + "version": "1.0.3", + "tarball": "https://registry.npmjs.org/mutation-observer/-/mutation-observer-1.0.3.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/mutation-observer/LICENSE" + ] + }, + { + "name": "svelte", + "version": "3.47.0", + "tarball": "https://registry.npmjs.org/svelte/-/svelte-3.47.0.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/svelte/LICENSE" + ] + }, + { + "name": "regenerator-runtime", + "version": "0.13.9", + "tarball": "https://registry.npmjs.org/regenerator-runtime/-/regenerator-runtime-0.13.9.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/regenerator-runtime/LICENSE" + ] + }, + { + "name": "style-loader", + "version": "3.3.1", + "tarball": "https://registry.npmjs.org/style-loader/-/style-loader-3.3.1.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/style-loader/LICENSE" + ] + }, + { + "name": "css-loader", + "version": "6.7.1", + "tarball": "https://registry.npmjs.org/css-loader/-/css-loader-6.7.1.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/css-loader/LICENSE" + ] + }, + { + "name": "webpack", + "version": "5.72.0", + "tarball": "https://registry.npmjs.org/webpack/-/webpack-5.72.0.tgz", + "assets": [ + "docs/assets/js/vconsole.min.js" + ], + "notices": [ + "docs/licenses/vconsole/webpack/LICENSE" + ] + } + ] }, { "name": "monaco-editor", diff --git a/scripts/site-vendor/vconsole/README.md b/scripts/site-vendor/vconsole/README.md index 63d2e54d4..2c5adbc10 100644 --- a/scripts/site-vendor/vconsole/README.md +++ b/scripts/site-vendor/vconsole/README.md @@ -50,8 +50,49 @@ test to reproduce failures; normal CI serves the candidate and expects no errors The scroller case holds zero-delay timers to force the late continuation while using native rendering, ResizeObserver and RAF; this is explicit fault injection. -This patch does not claim complete upstream lifecycle coverage, device coverage, -or permission clearance. The upstream LICENSE is distributed verbatim, but its -missing MIT body and bundled dependency notices remain open in VENDOR-07/SITE-07. -Do not replace or upgrade the bundle to resolve these issues without separately -checking entrypoints, logging, CSS and the full dependency notices. +This patch does not claim complete upstream lifecycle or device coverage. The +notice set now preserves the original LICENSE, supplies its missing MIT body in a +separate file, and includes the complete licenses of the verified bundled runtime +components. Do not upgrade the bundle without reviewing entrypoints, logging, +CSS and the new dependency notices. + +## Historical bundle reconstruction and notices + +`refactor/baselines/vconsole-notices-provenance.json` pins 81 original source/config +files from the commit above, the upstream lockfile, nine notice-bearing component +archives and the observed runtime resource paths. The original npm bundle was +reproduced byte for byte using Node 24.21.0 and the frozen upstream npm lockfile. +No upstream install scripts ran. This is an isolated historical reconstruction; +ArtPlayer remains on Yarn Classic with its root yarn.lock. + +Prepare a checkout of the exact upstream commit inside `refactor/.cache/`, then +run `npm ci --ignore-scripts --no-audit --no-fund` there. The 81 source/config files +can also be fetched from fixed raw GitHub URLs using the recorded Git blob IDs +and SHA-256 values when the source archive host is unavailable. Return to the +ArtPlayer root and run: + +```powershell +yarn verify:vconsole-source refactor/.cache/ +``` + +The helper checks every pinned input and dependency version before loading the +upstream build configuration. It builds only in the ignored checkout, requires +the exact npm bundle SHA-256, rejects hidden/truncated module statistics, and +compares all dependency resources and webpack bootstrap modules to the reviewed +notice set. It never copies the rebuilt bundle over ArtPlayer's patched asset. +Upstream size warnings and its old Browserslist dataset remain visible; do not +update the lockfile or dataset to silence them during historical reconstruction. + +The eight runtime packages are @babel/runtime, copy-text-to-clipboard, core-js, +css-loader, mutation-observer, regenerator-runtime, style-loader and svelte. +Only actual resource paths count: less-loader's appearance in a loader chain does +not make it a runtime dependency. Webpack's four generated bootstrap modules also +have a license entry. Mutation-observer's two BSD notices are both retained. +Other packages' MIT licenses retain their own copyright holders. + +The published vConsole header explicitly links the MIT license. The upstream +LICENSE omits its promised body, so ArtPlayer supplies `MIT-LICENSE` with that +body and the original Tencent copyright, without pretending it came verbatim +from the archive. `ATTRIBUTION.md` identifies this assembly, original sources and +the local lifecycle modifications. These files and all dependency licenses are +generated into `docs/licenses/vconsole/`; never edit the outputs by hand. diff --git a/scripts/site-vendor/vconsole/reproduce.ts b/scripts/site-vendor/vconsole/reproduce.ts new file mode 100644 index 000000000..1cf115986 --- /dev/null +++ b/scripts/site-vendor/vconsole/reproduce.ts @@ -0,0 +1,79 @@ +import assert from 'node:assert/strict' +import { createHash } from 'node:crypto' +import fs from 'node:fs' +import { createRequire } from 'node:module' +import path from 'node:path' +import process from 'node:process' +import { fileURLToPath } from 'node:url' + +interface Module { + name?: string + nameForCondition?: string + moduleType?: string + filteredChildren?: number + modules?: Module[] +} +interface Stats { + hasErrors: () => boolean + toJson: (options: Record) => { modules: Module[], errors: unknown[], warnings: unknown[] } +} +interface Provenance { + upstream: { bundleSha256: string } + reconstruction: { sources: { path: string, sha256: string }[] } + dependencies: { name: string, version: string, runtimeResources: string[] }[] +} + +const repository = fileURLToPath(new URL('../../../', import.meta.url)) +const cache = fs.realpathSync(path.join(repository, 'refactor/.cache')) +assert.equal(process.argv.length, 3, 'Pass a prepared upstream checkout inside refactor/.cache') +const checkout = fs.realpathSync(process.argv[2]!) +assert(checkout.startsWith(`${cache}${path.sep}`), 'Reconstruction must stay inside the ignored cache') +const provenance: Provenance = JSON.parse(fs.readFileSync(path.join(repository, 'refactor/baselines/vconsole-notices-provenance.json'), 'utf8')) +const hash = (bytes: Uint8Array) => createHash('sha256').update(bytes).digest('hex') +for (const source of provenance.reconstruction.sources) { + const filename = fs.realpathSync(path.join(checkout, source.path)) + assert(filename.startsWith(`${checkout}${path.sep}`), 'Source must stay in the prepared checkout') + assert.equal(hash(fs.readFileSync(filename)), source.sha256, `Frozen source changed: ${source.path}`) +} +for (const dependency of provenance.dependencies) { + const manifest = JSON.parse(fs.readFileSync(path.join(checkout, 'node_modules', dependency.name, 'package.json'), 'utf8')) + assert.equal(manifest.version, dependency.version, `Installed version changed: ${dependency.name}`) +} + +// The verified upstream config resolves aliases and compiler targets from cwd. +process.chdir(checkout) +const require = createRequire(path.join(checkout, 'package.json')) +const config = require('./webpack.config.js')({ target: 'web' }, { mode: 'production' }) + +const stats = await new Promise((resolve, reject) => { + require('webpack')(config, (error: Error | null, result: Stats) => error ? reject(error) : resolve(result)) +}) +const report = stats.toJson({ + all: true, + groupModulesByAttributes: false, + groupModulesByType: false, + groupModulesByPath: false, + groupModulesByCacheStatus: false, + groupModulesByExtension: false, + groupModulesByLayer: false, + modulesSpace: Infinity, + nestedModulesSpace: Infinity, + chunkModulesSpace: Infinity, +}) +assert(!stats.hasErrors(), JSON.stringify(report.errors)) +assert.equal(hash(fs.readFileSync('dist/vconsole.min.js')), provenance.upstream.bundleSha256, 'Rebuilt bundle differs from the frozen npm bundle') +const resources = new Set() +function visit(module: Module) { + assert(!module.filteredChildren, 'Webpack hid modules; this is incomplete provenance') + const resource = module.nameForCondition?.replaceAll('\\', '/') + if (resource?.includes('/node_modules/')) + resources.add(`node_modules/${resource.split('/node_modules/').pop()}`) + if (module.moduleType === 'runtime') { + assert(module.name) + resources.add(module.name) + } + module.modules?.forEach(visit) +} +report.modules.forEach(visit) +assert.deepEqual([...resources].sort(), [...new Set(provenance.dependencies.flatMap(dependency => dependency.runtimeResources))].sort(), 'Bundled component resources differ from the reviewed notice set') +console.log(JSON.stringify({ exactBundle: true, sha256: provenance.upstream.bundleSha256, resources: resources.size, notices: provenance.dependencies.length, warnings: report.warnings })) diff --git a/test/site-notices.test.js b/test/site-notices.test.js index c3ae796ba..d23387a14 100644 --- a/test/site-notices.test.js +++ b/test/site-notices.test.js @@ -1,8 +1,10 @@ import assert from 'node:assert/strict' import { Buffer } from 'node:buffer' +import { spawnSync } from 'node:child_process' import { createHash } from 'node:crypto' import fs from 'node:fs' import path from 'node:path' +import process from 'node:process' // eslint-disable-next-line test/no-import-node-test -- Verify real notice bytes and failure-before-write behavior. import test from 'node:test' import { generateNotices, writeOrCheckNotices } from '../scripts/site-vendor/notices.ts' @@ -83,3 +85,23 @@ test('Bundled component attribution requires its asset and every upstream notice fs.writeFileSync(path.join(root, 'ATTRIBUTION'), upstream.toString().replaceAll('\r\n', '\n')) assert.throws(() => generateNotices(root, manifest), /Upstream notice changed/) }) + +test('Site notice CLI rejects omitted reviewed components and supplemental vConsole notices', (t) => { + const { root } = fixture(t) + const manifestPath = path.join(root, 'scripts/site-vendor/manifest.json') + fs.mkdirSync(path.dirname(manifestPath), { recursive: true }) + const original = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8')) + for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md', 'webpack']) { + const manifest = structuredClone(original) + const group = manifest.groups.find(group => group.name === 'vconsole') + if (name === 'webpack') + group.components = group.components.filter(component => component.name !== name) + else + group.notices = group.notices.filter(notice => notice.target !== `docs/licenses/vconsole/${name}`) + fs.writeFileSync(manifestPath, JSON.stringify(manifest)) + const result = spawnSync(process.execPath, [path.resolve('scripts/build-site-notices.mjs')], { cwd: root, encoding: 'utf8' }) + assert.equal(result.status, 1) + assert.match(result.stderr, name === 'webpack' ? /Do not silently drop verified bundled component/ : /Missing vConsole notice/) + assert(!fs.existsSync(path.join(root, 'docs'))) + } +})