Repository navigation
Prepare Framework v5: security, correctness and release validation - #243
Conversation
| Cleverbrush Framework is dual-licensed under both the "Unlicense" and the | ||
| "Zero-Clause BSD" (0BSD) licenses. The intent of this dual-licensing | ||
| structure is to make Cleverbrush Framework as consumable as possible in as many | ||
| environments / countries / companies as possible without encumbering | ||
| users. |
There was a problem hiding this comment.
All libraries are under the BSD license, fix it everywhere.
There was a problem hiding this comment.
Fixed in 8022074.
The root LICENSE contained outdated dual Unlicense/0BSD text, which I had copied into the package LICENSE files despite the manifests and documentation declaring BSD-3-Clause. The root and all 22 published packages now contain the same BSD-3-Clause text, with the existing copyright attribution retained. I also normalized the demo backend manifest and regenerated its lockfile metadata through npm.
Package verification now checks license metadata and actual LICENSE contents in source and installed tarballs. Added 10 regression tests covering root/workspace/installed packages, missing or mismatched license files, incorrect or absent metadata, and an incorrect canonical license. The README and existing changeset are updated. Historical release snapshots and third-party notices are unchanged.
Validation: lint, build, all 5,104 unit/type tests and packed-consumer checks pass. All four CI jobs are green, including coverage, PostgreSQL, S3, documentation builds and E2E.
Summary
Prepare the Framework v5 release from the latest
developmentbaseline with correctness/security fixes, reproducible release checks, and current consumer documentation. No release, merge or deployment is performed by this PR.Correctness and security
@cleverbrush/client/idempotencyexport.--todocumentation.Release and documentation
cb-orm). Smoke-test the packed CLI as well as module exports. Give in-process compiler fixture tests explicit CI/coverage time budgets without relaxing assertions.Some test-only/source formatting changes are required by the refreshed Biome version; they are mechanical and contain no semantic changes.
Verification
npm cinpm run lint— zero warnings/errorsnpm run build— all 24 workspace tasksnpm run test— 5,104 tests, 261 files, no type errorsAll four CI jobs passed for commit
8022074c: final validation run. Initial CI failures exposed missing clean-checkout CLI links, compiler fixture timeouts under coverage, and a root-versus-workspace Playwright browser mismatch; all were corrected and the complete workflow rerun successfully.Remaining findings / review notes
npm auditreports 5 affected packages: 3 low, 2 moderate. DOMPurify/Monaco concerns an IN_PLACE plus afterSanitize hook combination; esbuild concerns its Windows development server through tsup; uuid/gaxios concerns older UUID buffer APIs through the demo's Google authentication dependency. These are retained and visible, not suppressed with forced transitive major overrides. The high/critical gate passes, not a claim of zero vulnerabilities.