fix(supply-chain): separate MIT and bundled-font licenses - #270
seonghobae wants to merge 14 commits into
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 34 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Exact-current-head read-only review request for Direct exact-head gates are complete: CI @coderabbitai review Review only. Do not mutate the branch, dispatch repair writers, reuse predecessor/stale/synthetic evidence, or synthesize author approval. Bind findings and verdicts to this exact unchanged head. |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
head='b2c6b6eb7b9638051688939b722a1094c97da013'
base='a430b1c153702de3b6439def801732d7453b4940'
echo '== Revision identities =='
git rev-parse HEAD
git cat-file -t "$head"
git cat-file -t "$base"
git merge-base --is-ancestor "$base" "$head" && echo 'base-is-ancestor=yes' || echo 'base-is-ancestor=no'
echo '== Changed paths and diff summary =='
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"
git diff -- "$base" "$head" -- LICENSE package.json src/fonts/NOTICE src/fonts/OFL.txt 2>/dev/null || true
echo '== Root LICENSE canonical MIT comparison =='
expected="$(mktemp)"
cat > "$expected" <<'EOF'
MIT License
Copyright (c) 2026 Inkspan Contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
EOF
if diff -u "$expected" LICENSE; then
echo 'root-license-canonical-mit=yes'
else
echo 'root-license-canonical-mit=no'
fi
rm -f "$expected"
echo '== Font-license evidence =='
printf 'NOTICE Noto occurrences: '
rg -n -i 'Noto(\s+Sans)?' src/fonts/NOTICE || true
printf 'OFL reserved-font-name occurrences: '
rg -n 'Reserved Font Name|Noto Sans' src/fonts/OFL.txt || true
printf 'OFL version markers: '
rg -n 'SIL OPEN FONT LICENSE|Version 1\.1|PREAMBLE|TERMS AND CONDITIONS' src/fonts/OFL.txt || true
wc -l src/fonts/NOTICE src/fonts/OFL.txt
echo '== npm manifest evidence =='
jq '{license, files, version, dependencies, devDependencies, exports, main, module, types}' package.json
echo '== Package-related changed manifest fields =='
git diff -U0 "$base" "$head" -- package.json
echo '== Non-scope changes excluding license evidence =='
git diff --name-only "$base" "$head" -- . ':!LICENSE' ':!package.json' ':!src/fonts/NOTICE' ':!src/fonts/OFL.txt'Length of output: 8196 🏁 Script executed: #!/bin/bash
set -euo pipefail
head='b2c6b6eb7b9638051688939b722a1094c97da013'
base='a430b1c153702de3b6439def801732d7453b4940'
echo '== Test structure =='
ast-grep outline src/licenseBoundary.test.ts --items all
echo '== Added test content =='
cat -n src/licenseBoundary.test.ts
echo '== License content at base and head =='
echo '-- base LICENSE --'
git show "${base}:LICENSE" | cat -n
echo '-- head LICENSE --'
git show "${head}:LICENSE" | cat -n
echo '== Corrected canonical MIT comparison =='
expected="$(mktemp)"
cat > "$expected" <<'EOF'
MIT License
Copyright (c) 2026 ContextualWisdomLab
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
EOF
diff -u "$expected" LICENSE && echo 'root-license-canonical-mit=yes'
rm -f "$expected"
echo '== Exact package contract comparison =='
for key in version license dependencies devDependencies peerDependencies optionalDependencies exports main module types files; do
before="$(git show "${base}:package.json" | jq -c --arg key "$key" '.[$key]')"
after="$(git show "${head}:package.json" | jq -c --arg key "$key" '.[$key]')"
if [ "$before" = "$after" ]; then
printf '%s=unchanged\n' "$key"
else
printf '%s=CHANGED\n' "$key"
fi
done
echo '== Test references to requested evidence =='
rg -n -C 2 'LICENSE|MIT|NOTICE|OFL|Noto|package\.json|license|files|src/fonts' src/licenseBoundary.test.tsLength of output: 10800 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/inkspan'
head='b2c6b6eb7b9638051688939b722a1094c97da013'
echo '== Exact-head GitHub Actions runs =='
for run_id in 31590591645 31590591555 31590591516; do
gh api "repos/${repo}/actions/runs/${run_id}" \
--jq '[.id, .name, .head_sha, .status, .conclusion] | `@tsv`'
done
echo '== Retained OFL text has no changes from the protected base =='
git diff --quiet a430b1c153702de3b6439def801732d7453b4940 "$head" -- src/fonts/OFL.txt \
&& echo 'ofl-unchanged-from-base=yes' \
|| echo 'ofl-unchanged-from-base=no'Length of output: 1082 🤖 web_search executed:
Length of output: 10588 🏁 Script executed: #!/bin/bash
set -euo pipefail
reference="$(mktemp)"
repository_terms="$(mktemp)"
reference_terms="$(mktemp)"
trap 'rm -f "$reference" "$repository_terms" "$reference_terms"' EXIT
curl --fail --silent --show-error --location \
'https://openfontlicense.org/open-font-license-official-text/OFL.txt' \
-o "$reference"
echo '== Official reference identity =='
sed -n '1,20p' "$reference"
echo '== Compare standard OFL-1.1 terms =='
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
src/fonts/OFL.txt > "$repository_terms"
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
"$reference" > "$reference_terms"
if diff -u "$reference_terms" "$repository_terms"; then
echo 'ofl-standard-terms-exact=yes'
else
echo 'ofl-standard-terms-exact=no'
fiLength of output: 1154 🏁 Script executed: #!/bin/bash
set -euo pipefail
page="$(mktemp)"
trap 'rm -f "$page"' EXIT
curl --fail --silent --show-error --location \
--user-agent 'Mozilla/5.0 (compatible; CodeRabbit review)' \
'https://openfontlicense.org/open-font-license-official-text/' \
-o "$page"
echo '== Official OFL page title and text-download candidates =='
rg -n -i -C 1 '<title>|OFL\.txt|plaintext|plain text|download' "$page" | head -n 120Length of output: 6977 🏁 Script executed: #!/bin/bash
set -euo pipefail
reference="$(mktemp)"
repository_terms="$(mktemp)"
reference_terms="$(mktemp)"
trap 'rm -f "$reference" "$repository_terms" "$reference_terms"' EXIT
curl --fail --silent --show-error --location \
--user-agent 'Mozilla/5.0 (compatible; CodeRabbit review)' \
'https://openfontlicense.org/documents/OFL.txt' \
-o "$reference"
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
src/fonts/OFL.txt > "$repository_terms"
sed -n '/^SIL OPEN FONT LICENSE Version 1\.1 - 26 February 2007$/,$p' \
"$reference" > "$reference_terms"
echo '== Official reference header =='
sed -n '1,16p' "$reference"
echo '== Exact standard-terms comparison =='
if diff -u "$reference_terms" "$repository_terms"; then
echo 'ofl-standard-terms-exact=yes'
else
echo 'ofl-standard-terms-exact=no'
fiLength of output: 2344 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== Trailing whitespace in bundled OFL text =='
rg -n '[ \t]+$' src/fonts/OFL.txt || trueLength of output: 379
I reviewed
I kept this review distinct from protected-main verification and approval authority, as required by the repository guidance. 🧠 Learnings used
|
Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Restacked onto current protected Validation at
The real emitted npm tarball contains canonical root MIT text plus separate bundled-font NOTICE and OFL evidence; no license terms or runtime behavior changed. @codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Remove the duplicated Python support contract changes from this license branch. PR #405 remains the single writer while this branch keeps its repository license correction. Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> Commit-Message-Assisted-by: Claude (via Claude Code)
|
@coderabbitai review Please review exact head |
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 846c6d318d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-current-head read-only review request for Review only the two-path effective delta ( @codex review |
|
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Current exact-head integration update
This section supersedes mutable head/check statements from earlier branch snapshots.
face112af438c023ff256600e04c26afd6a175ea.f1906d5c97915f522742c4cfa4b69fb8900a27a1, not on an unprotected copy of owner code.846c6d318dbf4ccaab0c8707a36a698f679e7ee5; no force update or destructive rebase was used.ahead 14 / behind 0with the parent as merge base. The effective child delta remains exactly two paths: rootLICENSEandsrc/licenseBoundary.test.ts.LICENSEis exact canonical MIT text. Existing Noto Sans attribution and complete OFL-1.1 terms remain separately insrc/fonts/NOTICEandsrc/fonts/OFL.txt. The npm manifest remainslicense: MITand packages both rootLICENSEandsrc/fonts. This does not change or invent rights.LICENSE, fontNOTICE, and OFL bytes against their authoritative source files. The complete source and packed OFL are independently pinned to canonical SHA-256eb7f35eae6a733ac55711f933739502c635f98eb19fa7788af92ed83dc3e10f5, so a header-only or truncated license fails closed.npm pack, tar listing, and each tar extraction have direct 30-second subprocess timeouts withSIGKILL; the outer test ceiling is 65 seconds so stalled synchronous children fail before the test runner ceiling.pnpm audit --audit-level=moderatereported no known vulnerabilities;git diff --checkpassed.node_moduleswas a relative symlink. Replacing that test-environment shortcut with a frozen-lockfile offline installation made the unchanged independent-consumer verifier pass. No product or verifier weakening was used.face112af438c023ff256600e04c26afd6a175eaand reported no major issues. CodeRabbit's exact-head re-review was rate-limited. Current unresolved inline threads: 0.Product boundary
This Draft separates the Inkspan software license from bundled-font license evidence without changing either license. It is machine-readable supply-chain evidence and license-file separation, not legal advice.
Test-first lineage
961597fe6431452a8ba89d513b6ae236abcc2e9festablished the intended root/software and bundled-font separation and produced the expected RED result.c3ce70a527e19c06e41b7d82d369ee8fd5fa402dremoved only the appended font prose from rootLICENSE.210284bb30661294a86f413581c26731c25d4b8aremoved unrelated Office edits so their canonical writer remained separate.846c6d318dbf4ccaab0c8707a36a698f679e7ee5preserved that history, inherited feat: prepare TipTap 3 migration and restore Python matrix #402, and repaired the observed full-suite timeout without weakening artifact inspection.face112af438c023ff256600e04c26afd6a175eaadds exact packed-byte evidence and enforceable subprocess timeouts in response to exact-head review.Integration boundary
Keep Draft and unmerged until #402 is integrated or remains the valid live base, all exact-head hosted checks are terminal green, all review threads are resolved, and a qualifying independent approval exists under the live rules. Protected
mainalone defines shipped behavior. After ordinary protected integration, verify GitHub identifies the repository software license as MIT and the packed/published npm artifact retains both MIT and OFL evidence.