Skip to content

Enforce WP00.02 npm project licence boundary - #8

Merged
deku2026 merged 1 commit into
mainfrom
codex/wp00-02-licence-boundaries
Sep 18, 2026
Merged

deku2026 merged 1 commit into
mainfrom
codex/wp00-02-licence-boundaries

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

The npm build had no explicit licence-boundary declaration or complete project inventory gate. Declare AGPL-3.0-only / AGPL, register the current npm project, and check Git-discovered manifests, effective npm metadata, direct references and transitive first-party lock entries before validation and candidate construction. Unknown owners, npm aliases hiding unknown dependencies, unpublished source references and unregistered build scopes fail.

CI retains declarations, dependency edges and source identity. Ten new temporary-Git negative/positive tests join the existing tooling suite. The development guide's protobuf runtime version is corrected to the already locked 2.15.0; no dependency version, Workflow behavior, model selection or deployment admission behavior changes.

Validation: locked npm install, generated binding check, formatting, lint, type checks, 56 runtime tests and 30 tooling tests passed. The final bundled Worker and Workflow passed local tests with explicitly mocked inference. Exact-head CI and post-merge Cloudflare deployment/model smoke remain required and must retain their real instance evidence.

Authority: merged ArcForges-Design PR18, commit 6ba885ad38dd71de532c74d7b69f439d01d19a0a, WP00.02. Nine-owner closure is a separate family gate; no adjacent implementation is imported or built.

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Completed full final-head self-review against Design WP00.02. The remote patch matches the reviewed local patch (38c1cae3f835d13bac49789ffb8cfb77f71b63e9). The inventory, effective npm metadata, dependency/alias checks and ten new Git-fixture cases cover the accepted owner boundary. Existing model admission, retry limits, private routing and immutable deployment behavior are unchanged. No open findings remain.

Local 56 runtime tests, 30 tooling tests, generated bindings and clean-source final bundle checks passed. All applicable final-head CI jobs are now successful. Inference in local and PR fixtures remains mocked. The existing main-only deployment guard already accounts for skipped PR-only ancestors; actual Cloudflare deployment and the guarded model/tool/model smoke must pass after merge before this owner is closed.

@deku2026
deku2026 merged commit a896c8d into main Sep 18, 2026
11 checks passed
@deku2026

Copy link
Copy Markdown
Contributor Author

WP00.02 post-merge verification completed for merge commit a896c8d. Main CI 35398284537 succeeded, including actual Cloudflare deployment and its verification. Linux and Windows licence reports both identify the clean merge commit and pass the closed project inventory.

Public release ai-0.1.0-ci.22.1 targets that commit. All three release assets were downloaded; the 13 Worker ZIP files match the immutable candidate and its SHA-256 manifest. Candidate SHA-256: 7d8f0bbb541a9370f556e966f2e1ec881a01b6fd8851d4e3721f81756e4fb8a3.

The live evidence records Worker version d1c00a3b-ded4-416e-886b-c8379852149d, run hello-d1c00a3b-ded4-416e-886b-c8379852149d, complete Workflow execution and two real Workers AI model calls using @cf/openai/gpt-oss-20b. The repository's candidate and live-output validators passed against the downloaded publication evidence. Local receipt: artifacts/evidence/wp00-02-postmerge.json in the retained codex/wp00-02-licence-boundaries worktree. The primary checkout was pulled to the merge commit; branch and worktree remain. These results verify this policy change and the existing diagnostic release path, not later commercial-product gates.

@deku2026
deku2026 deleted the codex/wp00-02-licence-boundaries branch September 19, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant