mirror of
https://github.com/zhw2590582/ArtPlayer.git
synced 2026-10-08 19:06:15 -08:00
build(site): [SITE-07] bind console licenses to verified component sources
This commit is contained in:
1 parent
4bef084328
commit
fb1faffbe9
20 files changed
+343
-28
No files matched your search
@@ -80,7 +80,7 @@ Source: https://registry.npmjs.org/@vscode/codicons/-/codicons-0.0.26.tgz
|
||||
|
||||
Source: https://github.com/zhw2590582/ArtPlayer/blob/5d6b2f22bc75213ac97cff0bcffa4a1ce2bc786c/docs/assets/js/console.js
|
||||
|
||||
The 100 third-party Parcel modules and loader have exact source reproduction. The two owned adapter modules are built from TypeScript. Preserved notices also cover two embedded license headers, all 17 react-inspector external source-map members, and all seven HTML tokenizer sources from its fixed Git dependency. Embedded attribution review is still incomplete; this inventory is not publication clearance. Modified replicator and Emotion/Stylis copies retain upstream author licenses; the original Emotion online Closure stage is not claimed to be reproducible. MurmurHash credits include Gary Court and Austin Appleby. The customStringify snippet matches Stack Overflow answer revision 5 under CC BY-SA 4.0; its separate attribution, source and full license are supplied. This is a mixed-license bundle, not MIT-only.
|
||||
The 100 third-party Parcel modules and loader have exact source reproduction. The two owned adapter modules are built from TypeScript. Preserved notices also cover two embedded license headers, all 17 react-inspector external source-map members, and all seven HTML tokenizer sources from its fixed Git dependency. The identified embedded-source and attribution review is complete for this frozen vendor boundary. Source records bind each component to its original notices; this inventory is not publication clearance. The original full lockfile and historical online Closure service are not recovered. Modified replicator and Emotion/Stylis copies retain upstream author licenses; the original Emotion online Closure stage is not claimed to be reproducible. MurmurHash credits include Gary Court and Austin Appleby. The customStringify snippet matches Stack Overflow answer revision 5 under CC BY-SA 4.0; its separate attribution, source and full license are supplied. This is a mixed-license bundle, not MIT-only.
|
||||
|
||||
Included component: console-feed 3.2.2
|
||||
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
| [已落实的测试可靠性规则](test-reliability.md) | 历史失败、候选回归、设备缺口、精确异常及等待/重试的执行规则 |
|
||||
| [docs 页面与编辑器测试](docs-browser-testing.md) | 复用已有 HTML、加载版本、隔离状态和补强文档 smoke |
|
||||
| [控制台迁移边界](console-modernization.md) | console.js 旧全局/实例/DOM 契约、冻结模块和待修复生命周期问题 |
|
||||
| [控制台来源与署名审查](console-notice-review.md) | 保留模块、内嵌来源、组件许可关联及历史构建恢复限制 |
|
||||
| [多轮复盘与 npm 准入](release-reviews.md) | Chrome 验证分工、三轮全局复盘、问题闭环和候选发布门槛 |
|
||||
| [逐包发布准入台账](release-ledger.md) | 22包候选/证据绑定、源码和产物指纹、任务风险/许可阻断及严格预检 |
|
||||
| [回退演练与维护](rollback-rehearsal.md) | 独立核心/插件回退、冻结安装文件检查、真实播放及剩余发布门槛 |
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
}
|
||||
],
|
||||
"review": {
|
||||
"status": "partial",
|
||||
"status": "reviewed-with-scope",
|
||||
"confirmed": [
|
||||
"Chromium copyright and full BSD conditions in console-feed source",
|
||||
"Sultan Tarimo MIT header in styled-components embedded rule-sheet source",
|
||||
@@ -36,8 +36,7 @@
|
||||
"customStringify exactly matches Stack Overflow revision 5 under CC BY-SA 4.0, with Alexander Mills and Rob W attribution, original snippet, full license and an emitted bundle comment.",
|
||||
"The shallowequal README source credit is verified; fixed react-pure-render source and Dan Abramov MIT license are retained, with explicit modified-source attribution."
|
||||
],
|
||||
"pending": [
|
||||
"Final embedded-source and mixed-license distribution review"
|
||||
]
|
||||
"pending": [],
|
||||
"conclusion": "refactor/console-notice-review.md"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,98 @@
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"task": "SITE-07",
|
||||
"recordedAt": "2026-09-15T00:26:56.446Z",
|
||||
"baseCommit": "4bef084328877d30a2abf6f71745831edb1e1c1e",
|
||||
"node": "v24.21.0",
|
||||
"fingerprints": {
|
||||
"console": "a5f1388175fd885c03dd21b35fff97dca0b548745588dfca3172579a96537163",
|
||||
"manifest": "f638ed7f3f6b13fcdaccf3c6e12642bea8e754455e1d8fee675d5d12ff19543d",
|
||||
"runtimeDelta": "No byte changes",
|
||||
"browserTest": "d94132e4d254e60281794849466ca09776315693034161ab685e6141852936a9"
|
||||
},
|
||||
"coverage": {
|
||||
"components": 44,
|
||||
"upstreamNotices": 46
|
||||
},
|
||||
"unit": {
|
||||
"passed": 26,
|
||||
"log": "refactor/.cache/console-notice-review-tests.log"
|
||||
},
|
||||
"reproduction": {
|
||||
"result": {
|
||||
"exactModules": 100,
|
||||
"consoleFeed": 32,
|
||||
"commonjs": 41,
|
||||
"esm": 27,
|
||||
"parcelPrelude": true,
|
||||
"packageEdges": true,
|
||||
"embeddedNotices": 2,
|
||||
"embeddedMappedSources": 17,
|
||||
"embeddedTransformedSources": 7,
|
||||
"derivedGitSources": 7,
|
||||
"replicatorFork": true,
|
||||
"emotionStylisSource": true,
|
||||
"stackOverflowRevision": 5,
|
||||
"unresolved": 0,
|
||||
"licenseClosure": false
|
||||
},
|
||||
"log": "refactor/.cache/console-notice-review-reproduce.log",
|
||||
"unchangedNetworkSourceEvidence": "refactor/baselines/console-shallowequal-validation.json"
|
||||
},
|
||||
"browser": {
|
||||
"report": "refactor/.cache/browser/report.json",
|
||||
"sha256": "b69b84fa2fa88b8c8065e660bb698c5852eb10d264e2b294c3a95e221277060f",
|
||||
"tests": [
|
||||
{
|
||||
"project": "chromium",
|
||||
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
|
||||
"status": "passed",
|
||||
"retry": 0,
|
||||
"browser": "153.0.8010.12",
|
||||
"platform": "win32",
|
||||
"notices": 65,
|
||||
"errors": [],
|
||||
"consoleErrors": [],
|
||||
"failedRequests": [
|
||||
{
|
||||
"url": "http://127.0.0.1:8084/test/pattern.mp4",
|
||||
"resourceType": "media",
|
||||
"failure": {
|
||||
"errorText": "net::ERR_ABORTED"
|
||||
}
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"project": "firefox",
|
||||
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
|
||||
"status": "passed",
|
||||
"retry": 0,
|
||||
"browser": "155.0",
|
||||
"platform": "win32",
|
||||
"notices": 65,
|
||||
"errors": [],
|
||||
"consoleErrors": [],
|
||||
"failedRequests": []
|
||||
},
|
||||
{
|
||||
"project": "webkit",
|
||||
"title": "mobile vConsole shows logs and upstream site notice texts are served unchanged",
|
||||
"status": "passed",
|
||||
"retry": 0,
|
||||
"browser": "26.6",
|
||||
"platform": "win32",
|
||||
"notices": 65,
|
||||
"errors": [],
|
||||
"consoleErrors": [],
|
||||
"failedRequests": []
|
||||
}
|
||||
]
|
||||
},
|
||||
"retainedCompatibility": "refactor/baselines/console-stackoverflow-validation.json",
|
||||
"limits": [
|
||||
"Original full lockfile and original online Closure service are not recovered.",
|
||||
"Review is specific to the unchanged runtime and identified component sources, not global release clearance.",
|
||||
"Local Windows browser verification does not replace device, external SDK or remote CI evidence."
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,33 @@
|
||||
# SITE-07 控制台来源审查与关联校验
|
||||
|
||||
修改前 HEAD:4bef084328877d30a2abf6f71745831edb1e1c1e。
|
||||
|
||||
汇总前几批已固定的模块、来源、作者和实际交付证据,形成
|
||||
[限定范围审查](../console-notice-review.md)。VENDOR-08 改为 accepted-with-scope;
|
||||
不再把原始完整锁无法恢复与已核实的组件署名混成一个无限期来源缺口。
|
||||
当前许可分发采用逐组件说明,CC BY-SA 片段仍独立保留其原始许可和署名;
|
||||
具体依据、工程判断及需要重审的变化边界均在审查文档中说明。
|
||||
|
||||
复核发现旧通用 notice 生成器不能拦截错误的组件/许可对应关系:全部文件
|
||||
和数量保持不变,BSD 包仍可以指向另一个包的 MIT 许可。新增 console/notices.ts
|
||||
从独立来源记录检查 44 个组件与 46 份上游材料;47 份输出中的剩余一份是本地
|
||||
编写的来源改动说明。生成和只读检查都会在写入之前执行关联校验。
|
||||
|
||||
测试复现旧生成器接受错误对应,新校验拒绝;改变组件 tarball 也拒绝。
|
||||
实现时遇到多个组件共享 console-feed 归档的情况,改为包名加归档双重匹配,
|
||||
保留内嵌组件的单独身份。严格 TS 检查要求局部数组显式类型,已补齐,未关闭
|
||||
严格选项或加入 any。本批未修改播放器、控制台运行代码、依赖或锁文件。
|
||||
|
||||
## 验证
|
||||
|
||||
- 单元 26/26,严格 docs-tools TS 和相关 lint 通过。
|
||||
- 新旧控制台字节一致,现有 51 项控制台证据继续适用,其中 18 项为历史验证。
|
||||
- 针对修改后的 notice 索引执行三引擎实际页面 3/3,逐字节校验全部 65 份
|
||||
notice 和新说明的相对链接,同时覆盖原生播放、移动控制台和销毁。
|
||||
- 完整来源重现使用上轮联网证据;本批未改变归档/源代码/转换配方。重新执行
|
||||
离线来源校验,确认现存缓存与固定证据一致。
|
||||
- [本批验证](../baselines/console-notice-review-validation.json)绑定当前指纹、
|
||||
测试范围和诊断;计划与风险校验通过。没有真机、远端 CI 或发布完成声明。
|
||||
|
||||
SITE-07 仍 doing,继续 Monaco、字体、媒体。回退时撤销关联检查、审查状态和
|
||||
索引说明,保留上轮已有许可材料;运行行为无需回退。本批独立本地提交。
|
||||
@@ -23,7 +23,8 @@ SITE-07 冻结原始 bundle 和浏览器契约,SITE-CONSOLE-01 已实现自有
|
||||
[冻结来源](baselines/site-console-inventory.json)。
|
||||
- 当前产物另附Stack Overflow代码片段的CC BY-SA 4.0署名注释;只增加注释,
|
||||
不改变100个第三方模块或Parcel运行代码。见[修订来源](baselines/console-stackoverflow-provenance.json)。
|
||||
站点分发47份控制台notice,包含shallowequal原始作者署名;最终混合许可/内嵌来源清查仍未关闭。
|
||||
站点分发47份控制台notice,包含shallowequal原始作者署名;已识别组件的来源与许可按
|
||||
[限定审查范围](console-notice-review.md)闭环,原始完整锁和构建环境仍未恢复。
|
||||
|
||||
## 必须保留或明确验证的契约
|
||||
|
||||
|
||||
@@ -0,0 +1,69 @@
|
||||
# 控制台来源与许可分发审查
|
||||
|
||||
审查基点:4bef084328877d30a2abf6f71745831edb1e1c1e。责任任务 SITE-07,风险
|
||||
VENDOR-08。以下结论仅覆盖本地候选 console.js 及其站点 notice,不代表 npm
|
||||
发布、整个站点或其余第三方资产已经验收。
|
||||
|
||||
## 来源范围
|
||||
|
||||
冻结旧产物包含 102 个 Parcel 模块。两个人工维护的入口/视图模块已迁入 TS;
|
||||
100 个保留模块分别对应 console-feed 的 32 个、CommonJS 组的 41 个、ESM 组的
|
||||
27 个。固定归档与转换配方能重现全部函数体、依赖边及 Parcel 加载器。来源
|
||||
记录中的早期 pending/数量是各批历史快照,当前汇总结论以本文件为准。
|
||||
|
||||
| 材料 | 当前证据与分发处置 |
|
||||
| --- | --- |
|
||||
| 32 个运行包与 Parcel | console-feed/commonjs/esm 三组固定记录;根许可及完整作者文字均交付。styled-components 的 npm 缺失 LICENSE 使用匹配固定 Git commit 补齐 |
|
||||
| Chromium string-utils | console-feed 内完整 BSD 头,保留 Chromium 作者、条件和免责声明 |
|
||||
| styled-components rule-sheet | source map 中完整 Sultan Tarimo MIT 头,独立交付 |
|
||||
| react-inspector 内嵌模块 | source map 中 17 个外部成员分别精确对应 Babel runtime 7.13.10 和 regenerator-runtime 0.13.7,完整许可交付 |
|
||||
| linkifyjs tokenizer | 发布 manifest 固定 Git 依赖;7 文件经固定 Babel 转换精确匹配,Yehuda Katz 原许可交付 |
|
||||
| 修改版 replicator | 固定 console-feed TS 源码经 TS 4.1.2 重现运行代码;保留 Ivan Nikulin 原始许可,不冒充未修改 npm replicator |
|
||||
| Emotion Stylis/rule-sheet | 固定 tag 的源码与 npm 匹配,记录原来对 Stylis 3.5.4 的修改配方,保留 Sultan Tarimo 署名 |
|
||||
| Emotion MurmurHash | 显式引用的 Gary Court README/MIT 及 Austin Appleby public-domain 说明原文均交付 |
|
||||
| customStringify | 精确对应 Stack Overflow 第 5 次修订;CC BY-SA 4.0 全文、来源、作者、原片段及编译改动说明交付,脚本末尾有署名链接 |
|
||||
| shallowequal | 发布 README 引用 react-pure-render;固定原始源码与 Dan Abramov MIT 许可,继续保留 Alberto Leal 当前许可,明确是修改实现 |
|
||||
|
||||
复核保留源码中的来源/版权注释。MDN console、ECMAScript 标准、V8 bug 链接、
|
||||
benchmark 链接及 URI 格式说明属于行为文档引用;没有仅凭 URL 出现就将网页
|
||||
添加为运行依赖或宣称复制了其实现。已发现的复制来源及 source map 外部成员
|
||||
逐项在上表处理,没有剩余已识别但未处置的组件署名缺口。
|
||||
|
||||
## 混合许可边界
|
||||
|
||||
MIT 和 BSD 的完整许可、作者、条件与免责声明随站点交付。哈希算法中的原文
|
||||
public-domain 声明保持原样;不替作者扩大授权范围。
|
||||
|
||||
customStringify 继续按 CC BY-SA 4.0 交付,独立列出原作者、来源和修改,保留
|
||||
原始片段;不以 console-feed 的 MIT 覆盖它。编译和压缩未改变该函数算法。
|
||||
[CC BY-SA 4.0 第 2(a)(4) 节](https://creativecommons.org/licenses/by-sa/4.0/legalcode.en#s2a4)
|
||||
允许必要的技术格式修改;第 3 节规定署名及改编分享条件。
|
||||
[CC 官方 FAQ](https://creativecommons.org/faq/#if-i-create-a-collection-that-includes-a-work-offered-under-a-cc-license-which-licenses-may-i-choose-for-the-collection)
|
||||
说明合集不改变所含原材料的许可。结合当前可独立辨识且算法未修改的函数,
|
||||
本项目采用逐组件许可的分发方式;这是针对当前产物结构的工程判断,不是将
|
||||
整个程序重新许可为 MIT,也不保证未来任意融合或修改仍适用同一结论。以后
|
||||
改变该函数、来源、算法或打包边界时必须重新审查,不能沿用本次结论。
|
||||
|
||||
## 防止后续漂移
|
||||
|
||||
`scripts/site-vendor/console/notices.ts` 从固定来源记录读取许可身份,核对所有
|
||||
44 个组件与 46 份上游材料的关联;另有一份本项目编写的 react-pure-render
|
||||
改动说明,共 47 份控制台输出。此校验接入 build/check:site-notices,在写入
|
||||
之前执行。原有校验继续核对源文件/候选哈希、组件清单和实际文件集合。
|
||||
|
||||
新增反例证明:仅保留文件数量、内容和组件名仍可能把 BSD 包错误标到 MIT;
|
||||
旧通用生成器能接受这种错误关联,新关联校验必须拒绝。错误的归档来源链接
|
||||
同样被拒绝。独立的 reproduction 命令负责重新核实实际归档与上游内容,
|
||||
普通构建不联网、不运行历史第三方运行库,也不重跑旧在线 Closure 服务。
|
||||
|
||||
## 结论与限制
|
||||
|
||||
VENDOR-08 按 `accepted-with-scope` 关闭当前资产的来源与署名缺口:固定源码、
|
||||
完整已识别组件许可、分发和兼容证据具备。保留的限制是原作者完整安装锁、
|
||||
唯一使用版本和完整原始构建环境没有恢复;当前记录证明可复现的来源内容和
|
||||
转换配方。不得将“100 个模块精确匹配”写成“原始构建环境已完整恢复”。
|
||||
|
||||
当前脚本运行字节未变,复用既有 51 项控制台组合验证(其中 18 项历史基线),
|
||||
并针对本次生成物重跑 notice 实际交付检查。后续发布复盘仍需按候选内容绑定
|
||||
证据并重验;本结论不替代三轮全局复盘、真机和远端 CI/CD。SITE-07 继续处理
|
||||
Monaco、字体及媒体;VENDOR-04/05/06 没有因此关闭。
|
||||
+1
-1
@@ -653,7 +653,7 @@
|
||||
- SITE-AI-DOCS-01: [记录](changes/2026-09-14-SITE-AI-DOCS-01-documentation-pipeline.md) [记录](baselines/documentation-pipeline-validation.json)
|
||||
- SITE-BUILD-01: [记录](changes/2026-09-14-SITE-BUILD-01-staged-builds.md) [记录](baselines/site-build-validation.json)
|
||||
- SITE-03: [记录](changes/2026-09-14-SITE-03-desktop-editor.md) [记录](baselines/site-editor-validation.json)
|
||||
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md) [记录](baselines/console-embedded-notices.json) [记录](baselines/console-notices-validation.json) [记录](changes/2026-09-15-SITE-07-console-notices.md) [记录](baselines/console-embedded-sources.json) [记录](baselines/console-embedded-validation.json) [记录](changes/2026-09-15-SITE-07-console-embedded-sources.md) [记录](baselines/console-derived-attribution.json) [记录](baselines/console-derived-validation.json) [记录](changes/2026-09-15-SITE-07-console-derived-attribution.md) [记录](baselines/console-stackoverflow-provenance.json) [记录](baselines/console-stackoverflow-validation.json) [记录](changes/2026-09-15-SITE-07-console-stackoverflow.md) [记录](baselines/console-shallowequal-validation.json) [记录](changes/2026-09-15-SITE-07-console-shallowequal.md)
|
||||
- SITE-07: [记录](site-inventory.md) [记录](baselines/site-provenance.json) [记录](changes/2026-09-14-SITE-07-vendor-notices.md) [记录](baselines/site-notices-checkpoint.json) [记录](baselines/site-codicons-provenance.json) [记录](baselines/site-codicons-validation.json) [记录](changes/2026-09-15-SITE-07-codicons.md) [记录](baselines/vconsole-notices-provenance.json) [记录](baselines/vconsole-notices-validation.json) [记录](changes/2026-09-15-SITE-07-vconsole-notices.md) [记录](console-modernization.md) [记录](baselines/site-console-inventory.json) [记录](baselines/site-console-validation.json) [记录](changes/2026-09-15-SITE-07-console-baseline.md) [记录](baselines/console-feed-provenance.json) [记录](changes/2026-09-15-SITE-07-console-feed-source.md) [记录](baselines/console-commonjs-provenance.json) [记录](changes/2026-09-15-SITE-07-console-commonjs.md) [记录](baselines/console-esm-provenance.json) [记录](changes/2026-09-15-SITE-07-console-esm.md) [记录](baselines/console-embedded-notices.json) [记录](baselines/console-notices-validation.json) [记录](changes/2026-09-15-SITE-07-console-notices.md) [记录](baselines/console-embedded-sources.json) [记录](baselines/console-embedded-validation.json) [记录](changes/2026-09-15-SITE-07-console-embedded-sources.md) [记录](baselines/console-derived-attribution.json) [记录](baselines/console-derived-validation.json) [记录](changes/2026-09-15-SITE-07-console-derived-attribution.md) [记录](baselines/console-stackoverflow-provenance.json) [记录](baselines/console-stackoverflow-validation.json) [记录](changes/2026-09-15-SITE-07-console-stackoverflow.md) [记录](baselines/console-shallowequal-validation.json) [记录](changes/2026-09-15-SITE-07-console-shallowequal.md) [记录](console-notice-review.md) [记录](baselines/console-notice-review-validation.json) [记录](changes/2026-09-15-SITE-07-console-notice-review.md)
|
||||
- EX-01: [记录](changes/2026-09-14-EX-01-react-consumer.md) [记录](baselines/react-consumer-validation.json) [记录](scripts/react-consumer.mjs)
|
||||
- EX-02: [记录](changes/2026-09-14-EX-02-vue-consumer.md) [记录](baselines/vue-consumer-validation.json) [记录](scripts/vue-consumer.mjs)
|
||||
- MOD-01: [记录](changes/2026-09-15-MOD-01-bun-evaluation.md) [记录](baselines/bun-install-validation.json) [记录](bun-evaluation.md)
|
||||
|
||||
@@ -1,5 +1,14 @@
|
||||
# 进度与证据
|
||||
|
||||
## SITE-07 控制台来源审查收敛
|
||||
|
||||
完成[汇总审查](console-notice-review.md),VENDOR-08改为accepted-with-scope:
|
||||
当前100个保留模块及已识别内嵌来源、44组件/47份notice具备对应证据;保留原始
|
||||
完整锁和旧在线Closure服务未恢复的限制。新增组件/许可关联校验,防止文件
|
||||
俱全但BSD组件错误指向MIT许可。单元26/26、离线复现及三引擎交付3/3通过。
|
||||
见[变更](changes/2026-09-15-SITE-07-console-notice-review.md)。运行字节未变;
|
||||
SITE-07继续Monaco、字体及媒体,整体199/265,发布复盘门槛不变。
|
||||
|
||||
## SITE-07 shallowequal 原始署名
|
||||
|
||||
已核对react-pure-render固定源码和Dan Abramov完整MIT许可,保留当前包作者署名,
|
||||
|
||||
@@ -32,7 +32,7 @@
|
||||
| VENDOR-05 | open / 源码/产物事实 | jassub-font-assets 来源、版本与许可闭环 | PKG-JASSUB-01, SITE-01, PKG-JASSUB-06, SITE-07 |
|
||||
| VENDOR-06 | open / 源码/产物事实 | monaco-static-assets 来源、版本与许可闭环 | SITE-01, SITE-05, SITE-07 |
|
||||
| VENDOR-07 | resolved / 源码/产物事实 | vconsole 来源、版本与许可闭环 | SITE-01, SITE-07 |
|
||||
| VENDOR-08 | open / 源码/产物事实 | console-bundle 来源、版本与许可闭环 | SITE-01, SITE-07 |
|
||||
| VENDOR-08 | accepted-with-scope / 源码/产物事实 | console-bundle 来源、版本与许可闭环 | SITE-01, SITE-07 |
|
||||
| SDK-01 | open / 源码/产物事实 | hls.js 实际集成验证范围 | PKG-HLS-05, EX-03 |
|
||||
| SDK-02 | open / 待取证 | dash.js 实际集成验证范围 | PKG-DASH-01, EX-03, PKG-DASH-05 |
|
||||
| SDK-03 | open / 待取证 | flv.js 实际集成验证范围 | EX-03 |
|
||||
|
||||
+13
-3
@@ -667,7 +667,7 @@
|
||||
"id": "VENDOR-08",
|
||||
"title": "console-bundle 来源、版本与许可闭环",
|
||||
"confirmation": "source-observed",
|
||||
"status": "open",
|
||||
"status": "accepted-with-scope",
|
||||
"owners": [
|
||||
"SITE-01",
|
||||
"SITE-07"
|
||||
@@ -709,11 +709,21 @@
|
||||
"refactor/changes/2026-09-15-SITE-07-console-stackoverflow.md",
|
||||
"scripts/site-vendor/console/stackoverflow.ts",
|
||||
"refactor/baselines/console-shallowequal-validation.json",
|
||||
"refactor/changes/2026-09-15-SITE-07-console-shallowequal.md"
|
||||
"refactor/changes/2026-09-15-SITE-07-console-shallowequal.md",
|
||||
"refactor/console-notice-review.md",
|
||||
"refactor/baselines/console-notice-review-validation.json",
|
||||
"refactor/changes/2026-09-15-SITE-07-console-notice-review.md",
|
||||
"scripts/site-vendor/console/notices.ts"
|
||||
],
|
||||
"compatibleResolution": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.",
|
||||
"closureCriteria": "固定上游版本/内容差异、完整组件许可与分发 notices,兼容测试通过;仅当前上游许可证名称不足以关闭。",
|
||||
"workspaceState": "All 100 vendor modules and Parcel remain reproducible. Embedded author notices include fixed Stack Overflow revision 5 (CC BY-SA 4.0) and the react-pure-render origin credited by shallowequal. Both Dan Abramov and Alberto Leal MIT notices are retained, without claiming identical source or a unique installed upstream version. 47 console and 65 total site notices pass three-engine HTTP checks. Functional runtime unchanged. Final embedded-source and mixed-license review remains open."
|
||||
"workspaceState": "Current identified console source and notice scope is reviewed; 47 console notices, 65 total site notices pass actual three-engine delivery. Component-to-upstream-license binding now rejects misassigned licenses. See console-notice-review.md for the source matrix, CC material handling and retained historical reconstruction limits. This does not close other site asset or release review gates.",
|
||||
"resolutionEvidence": [
|
||||
"refactor/console-notice-review.md",
|
||||
"refactor/baselines/console-notice-review-validation.json",
|
||||
"refactor/changes/2026-09-15-SITE-07-console-notice-review.md"
|
||||
],
|
||||
"resolutionRationale": "All 100 retained modules and Parcel have exact reproducing sources, all identified embedded origins have original notices, and 44 components are bound to verified upstream materials before actual distribution. The unchanged runtime retains tested API behavior. Accept only the documented historical-reconstruction limits: the original full lockfile, uniquely installed versions and former online Closure service are not recovered. Component licenses remain separate, including CC BY-SA 4.0. Re-review changed code or integration boundaries and revalidate release candidates."
|
||||
},
|
||||
{
|
||||
"id": "SDK-01",
|
||||
|
||||
+4
-1
@@ -4508,7 +4508,10 @@
|
||||
"baselines/console-stackoverflow-validation.json",
|
||||
"changes/2026-09-15-SITE-07-console-stackoverflow.md",
|
||||
"baselines/console-shallowequal-validation.json",
|
||||
"changes/2026-09-15-SITE-07-console-shallowequal.md"
|
||||
"changes/2026-09-15-SITE-07-console-shallowequal.md",
|
||||
"console-notice-review.md",
|
||||
"baselines/console-notice-review-validation.json",
|
||||
"changes/2026-09-15-SITE-07-console-notice-review.md"
|
||||
]
|
||||
},
|
||||
{
|
||||
|
||||
@@ -1061,7 +1061,7 @@
|
||||
"SITE-01"
|
||||
],
|
||||
"sourceStatus": "Frozen original 340306-byte Parcel bundle e00bbf82bf08c452825690372ded39a9b60f4baf438f0e7ce8300e9bc4629c03 has 102 modules. SITE-CONSOLE-01 replaces only owned Focm/W5CS bodies and removes the missing map trailer. All 100 retained vendor bodies and Parcel loader exactly reproduce from 32 official runtime archives, Babel standalone 7.16.4, Terser 3.17.0 and Parcel 1.12.5 recipes; all package edges verified. This establishes exact source identities, not the original full lockfile or uniquely installed versions.",
|
||||
"licenseStatus": "Generated console notices cover 44 components in 47 files, including react-pure-render origin attribution for shallowequal and Stack Overflow revision 5 under CC BY-SA 4.0. Source and author evidence is in refactor/baselines/console-derived-attribution.json and console-stackoverflow-provenance.json. Three-engine actual delivery is recorded in console-shallowequal-validation.json. Final embedded-source and mixed-license review remains open; never describe the entire bundle as MIT-only.",
|
||||
"licenseStatus": "All currently identified component notices are preserved and delivered: 44 components, 47 files. Component associations are checked against fixed upstream provenance. VENDOR-08 accepted-with-scope; see refactor/console-notice-review.md for retained original-build limitations and CC BY-SA material boundaries. Never describe the entire bundle as MIT-only or treat this as publication clearance.",
|
||||
"upstreamSources": [
|
||||
"https://registry.npmjs.org/console-feed/-/console-feed-3.2.2.tgz",
|
||||
"https://registry.npmjs.org/terser/-/terser-3.17.0.tgz",
|
||||
@@ -1100,7 +1100,7 @@
|
||||
"https://registry.npmjs.org/@babel/standalone/-/standalone-7.16.4.tgz",
|
||||
"https://raw.githubusercontent.com/styled-components/styled-components/9b3457036cfedf1d5336f654f3171657630a9fd8/LICENSE"
|
||||
],
|
||||
"upstreamReviewedAt": null,
|
||||
"upstreamReviewedAt": "2026-09-15T00:26:56.484Z",
|
||||
"updatePolicy": "Keep separate from owned TS migration. Verify source/version/diff and license notices before replacement; preserve API/CSS/worker URLs and run owning package tests.",
|
||||
"fingerprints": [
|
||||
{
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import assert from 'node:assert/strict'
|
||||
import fs from 'node:fs'
|
||||
import process from 'node:process'
|
||||
import { verifyConsoleNoticeSources } from './site-vendor/console/notices.ts'
|
||||
import { writeOrCheckNotices } from './site-vendor/notices.ts'
|
||||
|
||||
assert(process.argv.slice(2).every(arg => arg === '--check'), 'Use yarn build:site-notices [--check]')
|
||||
@@ -70,5 +71,6 @@ assert.equal(consoleGroup?.notices.length, 47, 'Missing reviewed console notice'
|
||||
const vconsoleNotices = manifest.groups.find(group => group.name === 'vconsole')?.notices.map(notice => notice.target)
|
||||
for (const name of ['LICENSE', 'MIT-LICENSE', 'ATTRIBUTION.md'])
|
||||
assert(vconsoleNotices?.includes(`docs/licenses/vconsole/${name}`), `Missing vConsole notice: ${name}`)
|
||||
verifyConsoleNoticeSources(process.cwd(), manifest)
|
||||
const count = writeOrCheckNotices(process.cwd(), manifest, process.argv.includes('--check'))
|
||||
console.log(`Verified site notices: ${count} outputs; Monaco/vConsole/console inventories, embedded and other provenance gates remain open.`)
|
||||
@@ -61,9 +61,10 @@ The desktop console's owned TS entry/view and lifecycle now build through
|
||||
Its other 100 Parcel modules remain frozen and now reproduce exactly from fixed
|
||||
archives, including the Parcel loader. Its package/loader licenses, two embedded
|
||||
headers, embedded dependency licenses and upstream author notices now ship as 47 files
|
||||
under `docs/licenses/console/`. Full embedded
|
||||
attribution remains open; the generated index explicitly preserves that boundary.
|
||||
under `docs/licenses/console/`. Each component is bound to its verified upstream
|
||||
notice by `console/notices.ts`. The consolidated review and historical reconstruction
|
||||
limits are recorded in `refactor/console-notice-review.md`.
|
||||
|
||||
Follow-up: finish Monaco's broader bundled-component notice audit, the console
|
||||
embedded attribution/notices and remaining fonts/media. Do not upgrade these assets
|
||||
Follow-up: finish Monaco's broader bundled-component notice audit and remaining
|
||||
fonts/media. Do not upgrade these assets
|
||||
without verifying globals, AMD/worker paths, CSS, consoleLog and user interaction.
|
||||
@@ -120,12 +120,12 @@ site builds continue using the frozen verified vendor boundary.
|
||||
|
||||
The archived LICENSE is preserved verbatim with its Facebook attribution under
|
||||
`refactor/baselines/site-vendor/console-feed-3.2.2-LICENSE.txt`. Do not rewrite it
|
||||
or infer it covers every embedded/external component. Complete notices remain
|
||||
open, including the bundled replicator and remaining dependencies.
|
||||
or infer it covers every embedded/external component. Embedded and external
|
||||
components have their own source records and notices described below.
|
||||
The other 13 archives' LICENSE texts are also frozen under
|
||||
`refactor/baselines/site-vendor/console-commonjs/`, with exact bytes preserved by
|
||||
Git attributes. They are source evidence; complete site notice delivery still
|
||||
requires the remaining component review. The final ESM and Parcel texts live in
|
||||
Git attributes. They are source evidence tied to the generated notice inventory.
|
||||
The final ESM and Parcel texts live in
|
||||
`refactor/baselines/site-vendor/console-esm/`. React-inspector 5.1.1's ESM member
|
||||
is an exact match after historical conversion; its CJS member was a failed
|
||||
candidate. Styled-components 5.3.3 omits LICENSE in npm; the supplemental original
|
||||
@@ -133,7 +133,7 @@ comes from fixed upstream commit 9b3457036cfedf1d5336f654f3171657630a9fd8.
|
||||
The fetch command verifies that immutable upstream text through GitHub's Contents
|
||||
API too (the raw URL had connection resets); both URLs and the blob ID are
|
||||
recorded, and decoded content must match the same hash. Offline mode checks
|
||||
the frozen bytes. Full embedded-component attribution remains open.
|
||||
the frozen bytes. The consolidated review is in `refactor/console-notice-review.md`.
|
||||
|
||||
## Public notice delivery and embedded sources
|
||||
|
||||
@@ -205,6 +205,16 @@ member. Callback/context support and other changes prevent an exact-source claim
|
||||
the public attribution explains that boundary and retains both authors' notices.
|
||||
|
||||
There are now 47 console notice outputs for 44 components. This includes a
|
||||
CC BY-SA snippet; never describe the bundle as MIT-only. Final embedded-source
|
||||
and mixed-license distribution review remains open. Exact Parcel module
|
||||
reproduction alone is insufficient to close VENDOR-08.
|
||||
CC BY-SA snippet; never describe the bundle as MIT-only. The identified source
|
||||
and notice inventory is reviewed with the scope in `refactor/console-notice-review.md`.
|
||||
The original complete lockfile and online Closure service have not been recovered.
|
||||
The reproduction command's `licenseClosure: false` means that technical byte
|
||||
comparison alone makes no license-clearance claim; the documented review also
|
||||
considers component identity, embedded attribution and actual delivery.
|
||||
|
||||
`notices.ts` binds the 44 delivered components to 46 upstream notice/source files
|
||||
from the independent provenance records. The 47th output is the local modification
|
||||
explanation for react-pure-render. Both normal notice commands verify this relation
|
||||
before writing: retaining all files while redirecting a BSD component to another
|
||||
component's MIT notice is rejected. Re-review changed source or integration boundaries,
|
||||
then revalidate the release candidate; this scope does not replace release reviews.
|
||||
@@ -0,0 +1,63 @@
|
||||
import type { VendorManifest } from '../notices.ts'
|
||||
import assert from 'node:assert/strict'
|
||||
import fs from 'node:fs'
|
||||
import path from 'node:path'
|
||||
|
||||
interface Notice { source: string, sha256: string }
|
||||
interface Archive { name: string, version: string, tarball: string, notices: Notice[] }
|
||||
interface Remote extends Notice { id: string, url: string }
|
||||
|
||||
// Bind delivered component notices to independently verified source records.
|
||||
// The normal site build does not download or execute the historical compilers.
|
||||
export function verifyConsoleNoticeSources(root: string, manifest: VendorManifest): { components: number, upstreamNotices: number } {
|
||||
const read = <T>(name: string): T => JSON.parse(fs.readFileSync(path.join(root, `refactor/baselines/${name}.json`), 'utf8')) as T
|
||||
const feed = read<{ archive: Archive, notice: Notice }>('console-feed-provenance')
|
||||
const common = read<{ archives: Archive[] }>('console-commonjs-provenance')
|
||||
const esm = read<{ archives: Archive[], parcel: { archive: Archive, notices: Notice[] }, supplementalNotices: Notice[] }>('console-esm-provenance')
|
||||
const embedded = read<{ archives: Archive[] }>('console-embedded-sources')
|
||||
const headers = read<{ notices: Notice[] }>('console-embedded-notices')
|
||||
const derived = read<{ archives: Archive[], remotes: Remote[], hash: { notice: Notice }, shallow: { license: string } }>('console-derived-attribution')
|
||||
const stack = read<{ apiUrl: string, notices: Notice[] }>('console-stackoverflow-provenance')
|
||||
const group = manifest.groups.find(group => group.name === 'console')
|
||||
assert(group?.components, 'Missing console component inventory')
|
||||
const visited = new Set<string>()
|
||||
const matchedNotices = new Set<string>()
|
||||
const verify = (identity: { name: string, tarball?: string }, expected: Notice[]): void => {
|
||||
const matches = group.components!.filter(component => component.name === identity.name && (!identity.tarball || component.tarball === identity.tarball))
|
||||
assert.equal(matches.length, 1, 'Expected one component for verified console source')
|
||||
const component = matches[0]!
|
||||
assert(!visited.has(component.name), 'Duplicate console source coverage')
|
||||
assert(expected.length, `Missing source license: ${component.name}`)
|
||||
for (const notice of expected) {
|
||||
const delivered: (Notice & { target: string })[] = group.notices.filter(item => item.source === notice.source && item.sha256 === notice.sha256)
|
||||
assert.equal(delivered.length, 1, `Console source notice not delivered: ${component.name}`)
|
||||
assert(component.notices.includes(delivered[0]!.target), `Console component points to the wrong notice: ${component.name}`)
|
||||
matchedNotices.add(delivered[0]!.target)
|
||||
}
|
||||
visited.add(component.name)
|
||||
}
|
||||
verify(feed.archive, [feed.notice])
|
||||
for (const archive of [...common.archives, ...esm.archives, ...embedded.archives, ...derived.archives]) {
|
||||
const name = archive.name === '@babel/runtime' && archive.version === '7.13.10'
|
||||
? '@babel/runtime (react-inspector embedded)'
|
||||
: archive.name === 'replicator'
|
||||
? 'replicator (console-feed fork)'
|
||||
: archive.name === 'stylis' ? 'stylis (Emotion fork)' : archive.name
|
||||
verify({ name, tarball: archive.tarball }, archive.name === 'styled-components' ? esm.supplementalNotices : archive.notices)
|
||||
}
|
||||
verify(esm.parcel.archive, esm.parcel.notices)
|
||||
assert.equal(headers.notices.length, 2, 'Unexpected embedded header scope')
|
||||
verify({ name: 'chromium-string-utils' }, [headers.notices[0]!])
|
||||
verify({ name: 'stylis-rule-sheet' }, [headers.notices[1]!])
|
||||
const hashLicense = derived.remotes.find(source => source.id === 'gary-readme')
|
||||
assert(hashLicense, 'Missing MurmurHash license source')
|
||||
verify({ name: 'murmurhash-js (Gary Court)' }, [hashLicense])
|
||||
verify({ name: 'murmurhash2 (Austin Appleby)' }, [derived.hash.notice])
|
||||
verify({ name: 'stackoverflow-custom-stringify', tarball: stack.apiUrl }, stack.notices)
|
||||
const pureLicense = derived.remotes.find(source => source.id === derived.shallow.license)
|
||||
assert(pureLicense, 'Missing react-pure-render license source')
|
||||
verify({ name: 'react-pure-render (shallowequal origin)' }, [pureLicense])
|
||||
assert.equal(visited.size, 44, 'Incomplete reviewed console source scope')
|
||||
assert.deepEqual([...visited].sort(), group.components.map(component => component.name).sort(), 'Unreviewed console component')
|
||||
return { components: visited.size, upstreamNotices: matchedNotices.size }
|
||||
}
|
||||
@@ -944,7 +944,7 @@
|
||||
"name": "console",
|
||||
"version": "legacy-vendor-with-TS-adapter",
|
||||
"tarball": "https://github.com/zhw2590582/ArtPlayer/blob/5d6b2f22bc75213ac97cff0bcffa4a1ce2bc786c/docs/assets/js/console.js",
|
||||
"review": "The 100 third-party Parcel modules and loader have exact source reproduction. The two owned adapter modules are built from TypeScript. Preserved notices also cover two embedded license headers, all 17 react-inspector external source-map members, and all seven HTML tokenizer sources from its fixed Git dependency. Embedded attribution review is still incomplete; this inventory is not publication clearance. Modified replicator and Emotion/Stylis copies retain upstream author licenses; the original Emotion online Closure stage is not claimed to be reproducible. MurmurHash credits include Gary Court and Austin Appleby. The customStringify snippet matches Stack Overflow answer revision 5 under CC BY-SA 4.0; its separate attribution, source and full license are supplied. This is a mixed-license bundle, not MIT-only.",
|
||||
"review": "The 100 third-party Parcel modules and loader have exact source reproduction. The two owned adapter modules are built from TypeScript. Preserved notices also cover two embedded license headers, all 17 react-inspector external source-map members, and all seven HTML tokenizer sources from its fixed Git dependency. The identified embedded-source and attribution review is complete for this frozen vendor boundary. Source records bind each component to its original notices; this inventory is not publication clearance. The original full lockfile and historical online Closure service are not recovered. Modified replicator and Emotion/Stylis copies retain upstream author licenses; the original Emotion online Closure stage is not claimed to be reproducible. MurmurHash credits include Gary Court and Austin Appleby. The customStringify snippet matches Stack Overflow answer revision 5 under CC BY-SA 4.0; its separate attribution, source and full license are supplied. This is a mixed-license bundle, not MIT-only.",
|
||||
"roots": [
|
||||
"docs/assets/js/console.js"
|
||||
],
|
||||
|
||||
@@ -47,7 +47,7 @@ test('mobile vConsole shows logs and upstream site notice texts are served uncha
|
||||
expect(await index.text()).toContain('Included component: murmurhash-js (Gary Court)')
|
||||
expect(await index.text()).toContain('Included component: murmurhash2 (Austin Appleby)')
|
||||
expect(await index.text()).toContain('stackoverflow-custom-stringify answer 48254637 revision 5 (CC BY-SA 4.0)')
|
||||
expect(await index.text()).toContain('Embedded attribution review is still incomplete')
|
||||
expect(await index.text()).toContain('The identified embedded-source and attribution review is complete for this frozen vendor boundary.')
|
||||
await page.evaluate(() => {
|
||||
window.vConsole.destroy()
|
||||
window.art.destroy()
|
||||
|
||||
@@ -7,9 +7,25 @@ import path from 'node:path'
|
||||
import process from 'node:process'
|
||||
// eslint-disable-next-line test/no-import-node-test -- Verify real notice bytes and failure-before-write behavior.
|
||||
import test from 'node:test'
|
||||
import { verifyConsoleNoticeSources } from '../scripts/site-vendor/console/notices.ts'
|
||||
import { generateNotices, writeOrCheckNotices } from '../scripts/site-vendor/notices.ts'
|
||||
|
||||
const hash = bytes => createHash('sha256').update(bytes).digest('hex')
|
||||
test('Console notices retain the verified owner and license association', () => {
|
||||
const manifest = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
|
||||
assert.deepEqual(verifyConsoleNoticeSources(process.cwd(), manifest), { components: 44, upstreamNotices: 46 })
|
||||
const group = manifest.groups.find(group => group.name === 'console')
|
||||
const bsd = group.components.find(component => component.name === 'hoist-non-react-statics')
|
||||
const react = group.components.find(component => component.name === 'react')
|
||||
bsd.notices = [...react.notices]
|
||||
// Every component/file remains present, but the BSD component falsely points to MIT.
|
||||
assert.doesNotThrow(() => generateNotices(process.cwd(), manifest))
|
||||
assert.throws(() => verifyConsoleNoticeSources(process.cwd(), manifest), /wrong notice: hoist-non-react-statics/)
|
||||
bsd.notices = group.notices.filter(notice => notice.source.includes('hoist-non-react-statics')).map(notice => notice.target)
|
||||
bsd.tarball = react.tarball
|
||||
assert.throws(() => verifyConsoleNoticeSources(process.cwd(), manifest), /one component for verified/)
|
||||
})
|
||||
|
||||
function fixture(t) {
|
||||
const root = fs.mkdtempSync(path.resolve('refactor/.cache/site-notices-test-'))
|
||||
t.after(() => {
|
||||
|
||||
Reference in new issue
Block a user