feat(licensing): generate deterministic dependency license inventory - #495
Draft
seonghobae wants to merge 155 commits into
Draft
feat(licensing): generate deterministic dependency license inventory#495seonghobae wants to merge 155 commits into
seonghobae wants to merge 155 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add deterministic, fail-closed npm lockfile dependency-license inventory for acquisition/release evidence without choosing or implying an outbound Noema license.
Buyer boundary
This closes technical package inventory/evidence-generation gaps only. Owner/legal approval, license compatibility, NOTICE obligations, contributor/IP ownership and outbound-rights decisions remain separate authority and are not inferred from package metadata.
Implemented contract
package-lock.jsonlockfileVersion 3.devOptional,inBundle,hasInstallScript, and canonicalcpu/os; malformed present authority fails closed.Current repair — realistic intended-valid SRI fixtures
Production SRI validation correctly rejects digest strings whose decoded byte length does not match SHA-256/SHA-384/SHA-512. Earlier current-head CI showed several intended-valid behavior fixtures still used convenience placeholders such as
sha512-alpha; weakening production validation would have been incorrect.Repair commit
20f7174247d547632ad4137005c45211b94a414econverted the first intended-valid fixture baselines to a real 64-byte SHA-512 SRI while preserving malformed-SRI negative cases. Fresh follow-up found the remaining positivecpu/osfixture still usedsha512-platform. Current exact head9e38a848448cb21b2fab7f323af0d3ebfdf1deb7changes only that intended-valid platform fixture to a real SHA-512 SRI; production validation is unchanged.Earlier test-first SHA-1 rejection, output special-file protection, retained-source-path canonicality, resolved-credential rejection, stable input reads and exact package-authority repairs remain preserved in branch history.
Exact current identity and evidence
On unchanged exact head
9e38a848448cb21b2fab7f323af0d3ebfdf1deb7against independently resolved protectedmain@2c83355529447248c246805d1954f268e027d2ab:33207363420, verify job98971705626: terminal-success;33207363415, reviewer job98971705684: terminal-success, including exact 100% line+branch coverage, 100% docstring coverage, authenticated/scanned distroless sandbox and real no-network CodeGraph smoke;patch-validator-image33207363477: terminal-success;33207363408: workflow-level terminal-success, but not merge-authoritative while protected-central scanner authority remains defective;All currently observed Noema-local technical gates on this exact head are terminal-clean. Keep Draft because #500 remains the earlier dependency root and the read-only central scanner/consumer paths are not protected truth.
Read-only dependency boundary
Earlier Noema dependency root #500 is current exact head
91e72951c739a40d17f8474fd43318837b30c5b2, Draft/mergeable and an exact descendant of protected main. Application33231140202, reviewer33231140178, and workflow-level Security33231140205are terminal-success; dedicatedpatch-validator-image33231140223remains pending/non-passing. This licensing lane must not overtake it.Protected central
.github/mainremains GitHub-verifiede1b03eebc6dc5c85aed393e5928927c96376cf46. Protectedsecurity-scan.ymlexplicitly materializes immutable OSV base/head while Dependency Review and Trivy still use generic checkout and the Dependency Review support probe can map exact-comparison HTTP 403/404 tosupported=falseplus successful completion. Current downstream Security green therefore remains non-authoritative for exact submitted-head proof.Canonical central owner #897 remains open / Ready / mergeable at exact head
74eb5d1753cba1a48e47e9bc05940373181d7b23on the current protected central base, but required Strix provider-unavailable evidence, exact-current OpenCodeCHANGES_REQUESTED, and absence of a qualifying independent approval remain non-passing. Existing.github#1222rolling checkpoint is the owner-boundary canary path. Central #834 separately owns the consumer correction from nonexistent top-level.tokento stabledata.tokenand remains exact head1a202f9745e90280e3b1bbdead4f78320ba413fcon a historical non-mergeable base; Noema does not reshape its producer envelope as a workaround.Merge boundary
Keep Draft. Do not mark Ready or merge until #500 resolves in dependency order, protected-central scanner/consumer repairs are authoritative with fresh eligible downstream evidence, live base/governance is freshly unchanged, every applicable current-head gate remains terminal-clean, and zero valid unresolved findings remain. Generated package metadata remains technical due-diligence evidence, not legal clearance.