Skip to content

feat(settings): show generated Pylon open-source notices - #511

Merged
rynfar merged 2 commits into
pylonfrom
upstream/2026-09-12-licenses
Sep 12, 2026
Merged

feat(settings): show generated Pylon open-source notices#511
rynfar merged 2 commits into
pylonfrom
upstream/2026-09-12-licenses

Conversation

@rynfar

@rynfar rynfar commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator

Web, desktop, and mobile Settings now expose searchable open-source notices generated from Pylon’s installed production dependency graph and configured asset notices. Web ships a static manifest; mobile lazily loads an offline generated module. Strict builds fail on missing notices, while development avoids mandatory template downloads. File icons use the upstream package’s supplied icons where custom renditions lacked attribution.

Cycle #497, frozen range 6c583620ff7ad3235b135af7107c0543467eecfa..4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab. Adopted 4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab.

Pylon adaptations retain the existing build/icon scripts, settings entries, product naming, toolchain, and dependency graph. A version-specific @npmcli/agent 4.0.2 override uses the ISC identifier and GitHub Inc. author attribution declared in https://github.com/npm/agent/blob/v4.0.2/package.json; the archive/tag omit a license file. Its provenance and revisit trigger are documented.

Regenerated after devices #509 merged, on 6c5687f95d. The optional tool notices match agent-device 0.20.10 and expo-device-hub 0.9.0 pinned in Pylon. The dependency graph adds MIT notices for proper-lockfile 4.1.2, retry 0.12.0, and ISC signal-exit 3.0.7; the notice code/configuration rebased unchanged.

Validation: final rebase passes 84 focused generator, decoder, mobile link/native markdown, and web icon tests plus web/mobile typechecks. Earlier shared/scripts typechecks remain valid for unchanged code. Frozen install; strict generation and decoding of 459 web/server/desktop and 769 mobile notices; strict Metro config generation; successful web production build, whose emitted-module scan produces 460 decoded notices. The first mobile test attempt read an outdated file-dependency copy; frozen install refreshed it and both failures passed. Changed-file lint reports upstream/new license loading effect warnings and existing settings warnings. Formatting and diff checks pass.

No rendered Pylon screenshots or native mobile verification captured; no browser/computer use, release, or install performed. These visual verification limits remain explicit.

Implemented with GPT-6 in Codex.

@vercel

vercel Bot commented Sep 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
pylon-marketing Ready Ready Preview Sep 12, 2026 6:55am UTC

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL labels Sep 12, 2026
@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.9 KiB 14.1 KiB +157 B (+1.1%) 15.1 KiB
Codex Thread snapshot wire 7.2 KiB 7.2 KiB −3 B (−0.0%) 7.3 KiB
Codex Live turn WebSocket wire 6.7 KiB 6.9 KiB +160 B (+2.3%) 7.8 KiB
Codex Live turn WebSocket decoded 58.0 KiB 58.8 KiB +910 B (+1.5%) 66.4 KiB
Codex Live turn messages 8 10 +2 (+25.0%) 21
Claude Total thread wire 13.9 KiB 14.1 KiB +154 B (+1.1%) 15.1 KiB
Claude Thread snapshot wire 7.2 KiB 7.2 KiB −17 B (−0.2%) 7.3 KiB
Claude Live turn WebSocket wire 6.7 KiB 6.9 KiB +171 B (+2.5%) 7.8 KiB
Claude Live turn WebSocket decoded 58.8 KiB 59.7 KiB +928 B (+1.5%) 66.4 KiB
Claude Live turn messages 8 10 +2 (+25.0%) 21

Baseline: 6c5687f · PR result: 38efa3c · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 115.6 KiB
  • Claude decoded thread snapshot: 116.3 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

juliusmarminge and others added 2 commits September 12, 2026 00:52
Co-authored-by: maria <maria@kuuro.net>
(cherry picked from commit 4a4c6dd2adc350a68ba18bb28b24b5a7e4660dab)
@rynfar

rynfar commented Sep 12, 2026

Copy link
Copy Markdown
Collaborator Author

Independent adversarial review approved the generator, license provenance, npm dependency coverage and runtime bundling. Final delta at38efa3c35430f1a7df8c742c9eb9b65be48a1021 was also re-reviewed after #509: strict web/server/desktop manifest includes proper-lockfile4.1.2, retry0.12.0 and signal-exit3.0.7, with graceful-fs acquiring its server bundle label; mobile769rows unchanged. Both source commits were range-diff equivalent after rebase, and device tool notices match final pinned versions.84 focused tests, scoped types, strict Metro generation and strict web build passed. Final-head CI is green. Scope and native/rendered verification limitations remain explicit in the PR. Landing under the standing upstream-cycle approval.

@rynfar
rynfar merged commit a1f748b into pylon Sep 12, 2026
20 checks passed
@rynfar
rynfar deleted the upstream/2026-09-12-licenses branch September 12, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants