feat(settings): show generated Pylon open-source notices - #511
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
Co-authored-by: maria <maria@kuuro.net> (cherry picked from commit 4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab)
0526459 to
38efa3c
Compare
|
Independent adversarial review approved the generator, license provenance, npm dependency coverage and runtime bundling. Final delta at38efa3c35430f1a7df8c742c9eb9b65be48a1021 was also re-reviewed after #509: strict web/server/desktop manifest includes proper-lockfile4.1.2, retry0.12.0 and signal-exit3.0.7, with graceful-fs acquiring its server bundle label; mobile769rows unchanged. Both source commits were range-diff equivalent after rebase, and device tool notices match final pinned versions.84 focused tests, scoped types, strict Metro generation and strict web build passed. Final-head CI is green. Scope and native/rendered verification limitations remain explicit in the PR. Landing under the standing upstream-cycle approval. |
Web, desktop, and mobile Settings now expose searchable open-source notices generated from Pylon’s installed production dependency graph and configured asset notices. Web ships a static manifest; mobile lazily loads an offline generated module. Strict builds fail on missing notices, while development avoids mandatory template downloads. File icons use the upstream package’s supplied icons where custom renditions lacked attribution.
Cycle #497, frozen range
6c583620ff7ad3235b135af7107c0543467eecfa..4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab. Adopted4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab.Pylon adaptations retain the existing build/icon scripts, settings entries, product naming, toolchain, and dependency graph. A version-specific
@npmcli/agent4.0.2 override uses the ISC identifier and GitHub Inc. author attribution declared in https://github.com/npm/agent/blob/v4.0.2/package.json; the archive/tag omit a license file. Its provenance and revisit trigger are documented.Regenerated after devices #509 merged, on
6c5687f95d. The optional tool notices matchagent-device0.20.10 andexpo-device-hub0.9.0 pinned in Pylon. The dependency graph adds MIT notices forproper-lockfile4.1.2,retry0.12.0, and ISCsignal-exit3.0.7; the notice code/configuration rebased unchanged.Validation: final rebase passes 84 focused generator, decoder, mobile link/native markdown, and web icon tests plus web/mobile typechecks. Earlier shared/scripts typechecks remain valid for unchanged code. Frozen install; strict generation and decoding of 459 web/server/desktop and 769 mobile notices; strict Metro config generation; successful web production build, whose emitted-module scan produces 460 decoded notices. The first mobile test attempt read an outdated file-dependency copy; frozen install refreshed it and both failures passed. Changed-file lint reports upstream/new license loading effect warnings and existing settings warnings. Formatting and diff checks pass.
No rendered Pylon screenshots or native mobile verification captured; no browser/computer use, release, or install performed. These visual verification limits remain explicit.
Implemented with GPT-6 in Codex.