Skip to content

docs(legal): add pinned provider asset notices - #11737

Merged
diegosouzapw merged 9 commits into
release/v3.8.51from
docs/v3850-provider-asset-notices
Aug 28, 2026
Merged

diegosouzapw merged 9 commits into
release/v3.8.51from
docs/v3850-provider-asset-notices

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Aug 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Area Fixed evidence Disposition
LobeHub derivatives @lobehub/icons 5.10.0 fixed tarball, npm shasum and integrity Full MIT notice plus exact six-file mapping
theSVG source GLINCKER/thesvg at 7870bc1c5f657d9accbb7f96cc457b8dd3363ee8 Full MIT codebase/catalog notice plus exact 65/65 byte-match scope
Registry metadata Fixed src/data/icons.json Source claims only: MIT 46, CC0-1.0 14, Apache-2.0 1, brand-use 2, Custom 1, missing 1
Brand rights Fixed LEGAL.md, TRADEMARK.md and LICENSING.md No automatic relicense or trademark clearance; nominative use and no-affiliation disclaimer

This PR is independent from every other release branch. It starts from release/v3.8.50 at 0915890 and changes no asset, manifest, provider, dependency, or runtime code.

HOLD boundaries retained

  • The registry claims are not presented as independent clearance from brand owners.
  • The 46 MIT claims still need authoritative per-asset copyright notices before being called independently cleared.
  • Continue remains HOLD for authoritative Apache NOTICE verification.
  • Azure and Ovhcloud brand-use entries are not open-source license claims.
  • MiniMax remains HOLD under custom terms.
  • HuggingFace has no matching registry claim and remains HOLD.
  • Copyright provenance does not grant trademark rights.

TDD evidence

  • RED: 3/3 focused cases failed because the pinned notice sections were absent.
  • GREEN: 3/3 focused cases pass after adding the notices.
  • Focused command: node --import tsx/esm --test tests/unit/provider-assets-third-party-notices.test.ts

Gates

Gate Result Evidence
Focused notice test PASS 3/3
Focused license-policy tests PASS 37/37
Changelog fragment tests PASS 9/9
Changelog integrity PASS no base bullets lost against origin/release/v3.8.50 at 0915890
check:docs-all PASS exit 0; soft historical drift warnings remain advisory
Focused ESLint PASS exit 0 with the repository suppressions file
Prettier and git diff --check PASS clean
check:licenses BASE-RED / PR-unrelated 1120 scanned: 1110 allowed, 4 registered exceptions, 6 policy violations

The six full-scanner violations are @giscus/react UNKNOWN, @pierre/diffs Apache-2.0*, @pierre/theming UNKNOWN, @splinetool/runtime UNKNOWN, chroma-js BSD-3-Clause AND Apache-2.0, and elkjs EPL-2.0. The exact-base comparison is deterministic: package.json, package-lock.json, and config/quality/.license-allowlist.json have byte-identical Git blobs at this PR head and base 0915890. This notice-only diff therefore neither introduces nor repairs those six baseline findings.

No merge, automerge, tag, release, publish, or deploy is performed by this PR.

@diegosouzapw
diegosouzapw force-pushed the docs/v3850-provider-asset-notices branch from 4dfd0b2 to f6c4a93 Compare August 28, 2026 03:58
@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.50 to release/v3.8.51 August 28, 2026 03:58
diegosouzapw and others added 7 commits August 28, 2026 01:57
…#11712)

Obrigado! Correção honesta e bem documentada — só comentário, nenhuma mudança de lógica.

- Corrige a alegação de que omitir `tenantId` do digest evita o falso-positivo do CodeQL `js/insufficient-password-hash`; documenta que o alerta #874 já foi levantado no `createHash` de qualquer forma e foi dispensado por HR#14 (documentação de segurança, não código).
- Deixa explícito por que não "consertar" com um KDF: quebraria o determinismo de que o dedup depende.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree (typecheck:core, lint red-discriminator vs the pure release tip, complexity/cognitive-complexity ratchets, file-size, changelog-integrity, and the full focused test suite for every touched area all green). Static-asset-only cleanup, no runtime code changes. Thank you for the careful provenance audit.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green (typecheck:core, lint red-discriminator, complexity/cognitive-complexity ratchets, file-size, changelog-integrity, focused tests). THIRD_PARTY_NOTICES.md additive merge, no runtime code changes. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree — full gate suite green. Static-asset-only cleanup, no runtime code changes. Thank you for the provenance audit.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree — full gate suite green. Static-asset-only cleanup, no runtime code changes. Thank you.
Merged via /merge-batch (v3.8.51). Boarded and validated in a combined worktree alongside the batch's other in-flight PRs — full gate suite green (typecheck:core, lint, complexity/cognitive-complexity, file-size, changelog-integrity, focused tests including the video-bridge fusion/transcript suites). Thank you.
@diegosouzapw
diegosouzapw marked this pull request as ready for review August 28, 2026 07:37
@diegosouzapw
diegosouzapw merged commit 451917f into release/v3.8.51 Aug 28, 2026
8 of 12 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green. This PR's THIRD_PARTY_NOTICES.md addition (LobeHub + theSVG provenance sections) conflicted with diegosouzapw#11726's own addition (blackwell-systems/gcf-typescript + lipis/flag-icons) landing first; reconciled additively (both sections kept), re-validated with this PR's own 3 focused tests, and pushed before merge. Thank you.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants