From 7f5c7a80433a99a5af1e3c932bb56d16ddba60d9 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:38:22 +0300 Subject: [PATCH 01/12] doc(policies): add security, privacy, accessibility and support documents Rewrite SECURITY.md around the agreed support window: all fixes for the latest major, critical fixes backported to the last minor of the previous major. Add scope, response targets, disclosure, release verification with gh attestation, and security considerations for consumers (chat sanitizer, icon and QR URL fetches, clipboard, CSP). Add PRIVACY.md stating the no-telemetry, no-storage, no-remote-code position and listing the browser capabilities the components touch. Add ACCESSIBILITY.md with the WCAG 2.1 AA target, how axe audits and manual NVDA checks verify it, and how the components work around ARIA relations that cannot cross shadow boundaries with ElementInternals and ARIA element reflection. Add SUPPORT.md and an issue-template config that routes security reports to private vulnerability reporting. --- .github/ISSUE_TEMPLATE/config.yml | 14 +++++ .github/SUPPORT.md | 18 ++++++ ACCESSIBILITY.md | 49 ++++++++++++++++ PRIVACY.md | 32 +++++++++++ SECURITY.md | 92 +++++++++++++++++++++++++------ 5 files changed, 189 insertions(+), 16 deletions(-) create mode 100644 .github/ISSUE_TEMPLATE/config.yml create mode 100644 .github/SUPPORT.md create mode 100644 ACCESSIBILITY.md create mode 100644 PRIVACY.md diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 000000000..7f541a7c1 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,14 @@ +blank_issues_enabled: false +contact_links: + - name: 🔒 Report a security vulnerability + url: https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new + about: Report vulnerabilities privately. Never open a public issue for a security problem. + - name: 💬 Ask a question + url: https://github.com/IgniteUI/igniteui-webcomponents/discussions + about: Questions, ideas and general discussion belong in GitHub Discussions. + - name: 🗨️ Discord community + url: https://discord.gg/39MjrTRqds + about: Chat with other users and the team. + - name: 🏢 Infragistics support + url: https://www.infragistics.com/about-us/contact-us + about: Support for commercial Ignite UI products such as the Grids and Dock Manager. diff --git a/.github/SUPPORT.md b/.github/SUPPORT.md new file mode 100644 index 000000000..280480169 --- /dev/null +++ b/.github/SUPPORT.md @@ -0,0 +1,18 @@ +# Support + +Where to go depending on what you need: + +| I want to... | Go to | +| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------ | +| Report a bug in a component | [Bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml) | +| Request a component or feature | [Component request](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=component.md) | +| Ask a question or share an idea | [GitHub Discussions](https://github.com/IgniteUI/igniteui-webcomponents/discussions) | +| Chat with the community | [Discord](https://discord.gg/39MjrTRqds) | +| Report a security vulnerability | [Private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new). See [SECURITY.md](../SECURITY.md). Never open a public issue for this. | +| Report an accessibility problem | [Bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml). See [ACCESSIBILITY.md](../ACCESSIBILITY.md). | +| Get help with a commercial Ignite UI product | [Infragistics support](https://www.infragistics.com/about-us/contact-us) | +| Read the documentation | [Product documentation](https://www.infragistics.com/products/ignite-ui-web-components) and [Storybook](https://igniteui.github.io/igniteui-webcomponents) | + +Before opening an issue, search the existing [issues](https://github.com/IgniteUI/igniteui-webcomponents/issues) and [discussions](https://github.com/IgniteUI/igniteui-webcomponents/discussions). A bug report with a minimal reproduction, for example on StackBlitz, is resolved much faster than one without. + +Only the [latest major version](../SECURITY.md#supported-versions) receives new fixes; the previous major receives critical security fixes only. diff --git a/ACCESSIBILITY.md b/ACCESSIBILITY.md new file mode 100644 index 000000000..7d579b9d1 --- /dev/null +++ b/ACCESSIBILITY.md @@ -0,0 +1,49 @@ +# Accessibility + +Ignite UI for Web Components is built to be usable with a keyboard, a screen reader and other assistive technology. This document states what the library aims for, how that is verified, where the platform still limits what a Shadow DOM component can express, and how to report a problem. + +## Conformance target + +The components target [WCAG 2.1](https://www.w3.org/TR/WCAG21/) level AA for the parts of a page they render. Interactive components follow the [ARIA Authoring Practices Guide](https://www.w3.org/WAI/ARIA/apg/) patterns for their role, such as combobox, listbox, tablist, tree, dialog and slider, including the keyboard interaction each pattern specifies. + +A component supplies its own semantics, keyboard handling, focus management and contrast within its themes. The host application remains responsible for page-level requirements, such as headings, landmarks, page titles, the text of labels it passes to a component, and the contrast of custom colors it applies through CSS custom properties. + +No formal conformance report (VPAT or ACR) is published for this package. + +## How accessibility is verified + +**Automated audits.** Every component specification runs [axe-core](https://github.com/dequelabs/axe-core) through `chai-a11y-axe` against both the component's light DOM and its shadow DOM, in the states the specification exercises. The audits run with the default axe ruleset, which covers the WCAG 2.0 and 2.1 A and AA success criteria axe can test, the WCAG 2.2 AA rules axe ships, and its best-practice rules. A failing audit fails the test run, so a regression cannot merge. + +Two things about automated audits are worth knowing: + +- Automated tools detect only a portion of accessibility problems. Keyboard operability, focus order, the quality of a name or description, and screen-reader announcements need a person to verify them. +- axe reads ARIA from content attributes. Semantics the components publish through `ElementInternals` or ARIA element reflection are not visible to it, so a small number of rules are disabled for specific components and the real relation is asserted directly in the specification instead. These exceptions live in `src/internals/testing/helpers.spec.ts` and are documented there. + +**Storybook.** The Storybook build includes the accessibility addon, which runs axe against each story and shows the result in the panel. + +**Manual verification.** Components are checked by hand with a keyboard and with screen readers, primarily NVDA with Chrome and Firefox on Windows. Manual checks cover keyboard interaction against the APG pattern, focus visibility, announcements of state changes, and behavior with reduced motion and forced-colors modes. + +## Shadow DOM and the limits of the platform + +The components render in Shadow DOM. This gives them style and markup encapsulation, but ARIA was designed around a single document, and some of its mechanisms do not cross a shadow boundary: + +- **IDREF relations do not cross shadow roots.** Attributes such as `aria-labelledby`, `aria-describedby`, `aria-controls` and `aria-activedescendant` refer to elements by ID, and an ID inside one shadow root is not visible from another. A label element in the page cannot be referenced from an input inside a component's shadow root with an IDREF, and vice versa. +- **Composite roles are hard to split across roots.** Patterns such as a combobox that owns a listbox, or a tablist whose panels live in the page, require relations between elements that end up in different tree scopes. + +Where the platform offers a way around this, the components use it: + +- **`ElementInternals`.** Components attach internals and publish their role and ARIA state through it, so the host element carries the correct semantics without content attributes that a consumer could clobber. A controller in `src/internals/controllers/internals.ts` keeps that state in sync with component properties. Where a tool needs to see the role as a content attribute, it is mirrored there as well. +- **ARIA element reflection.** Relations are set as element references (`ariaLabelledByElements`, `ariaDescribedByElements`, `ariaControlsElements`, `ariaActiveDescendantElement`) rather than IDREF strings. Element reflection resolves across shadow boundaries into ancestor tree scopes, which lets a composite component point at an element the page or another component owns. The projection controller in `src/internals/controllers/aria-projection.ts` carries those references to the native control inside an input-shaped component, since that is the element assistive technology lands on. +- **Delegated focus and roving tabindex** keep a single tab stop per composite and move focus between items inside the shadow root, so keyboard behavior matches the APG pattern regardless of where the items live. + +Some patterns still cannot be expressed exactly, and in those cases the components use the closest semantics the platform supports. Browser support for cross-root ARIA is improving, and the components are updated to use new capabilities as they ship, so behavior will keep improving without changes on the consumer's side. Reference points for the ongoing platform work are the [Accessibility Object Model](https://wicg.github.io/aom/) and the [cross-root ARIA](https://github.com/WICG/webcomponents/issues/917) proposals. + +## What the host application should do + +- Pass a meaningful label to every input-like component, through its `label` property or an element reference, and do not rely on placeholder text. +- Keep the themes' contrast when customizing colors, or verify the result with a contrast checker. +- Test the page with a keyboard and at least one screen reader after composing components, since the composition is where page-level issues appear. + +## Reporting an accessibility problem + +Open a [bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml) and describe the assistive technology, browser and operating system, what was announced or what happened, and what you expected. Accessibility defects are triaged like functional bugs. diff --git a/PRIVACY.md b/PRIVACY.md new file mode 100644 index 000000000..9e610430b --- /dev/null +++ b/PRIVACY.md @@ -0,0 +1,32 @@ +# Privacy + +Ignite UI for Web Components is a library of UI components that runs entirely inside the web application that embeds it. This document describes what the components do with data and which browser capabilities they touch, so that you can account for them in your own privacy assessment. + +## What the library does not do + +- **No telemetry.** The components send no usage data, error reports or analytics anywhere. Nothing in the package contacts Infragistics or any third party at runtime. +- **No cookies or storage.** The components set no cookies and write nothing to `localStorage`, `sessionStorage` or IndexedDB. +- **No fingerprinting.** The components do not collect device, browser or network identifiers. +- **No remote code.** The package contains no code that loads scripts or styles from a remote origin. + +## Browser capabilities the components use + +Some components use browser APIs that can involve user data. Each is triggered only by an explicit call from the host application or by a user action inside the component. + +| Capability | Where | When | +| ----------------------------- | ------------------------------------ | ---------------------------------------------------------------------------------------------- | +| `fetch` of an application URL | Icon registry (`registerIcon`) | Only for the URL the host application passes when registering an icon. | +| `fetch` of an application URL | QR code export with an embedded image| Only for the image URL the host application passes to the export call. | +| Clipboard write | Color picker, chat message actions | Only when the user activates a copy control. The clipboard is never read. | +| Locale and time zone | Date and time components | Read through `Intl` to format and parse values. Nothing is transmitted. | +| Reduced-motion preference | Animations | Read through `matchMedia('(prefers-reduced-motion)')` to shorten or skip animations. | + +Data your application passes into a component, such as chat messages, form values or dates, stays in the page. The components render it and expose it back through their properties and events, and nowhere else. + +## Hosted sites + +The [Storybook](https://igniteui.github.io/igniteui-webcomponents) and the [product documentation](https://www.infragistics.com/products/ignite-ui-web-components) are separate websites operated by Infragistics. They are not part of the npm package and are covered by the [Infragistics privacy statement](https://www.infragistics.com/legal/privacy). + +## Questions + +Open a [discussion](https://github.com/IgniteUI/igniteui-webcomponents/discussions) for questions about this document. Report anything that looks like a privacy defect in the components as a bug, or privately through the [security policy](SECURITY.md) if it could expose user data. diff --git a/SECURITY.md b/SECURITY.md index c8dc4f993..7e1461db4 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,26 +1,86 @@ # Security Policy -## Supported Versions +Ignite UI for Web Components is a client-side UI library published to npm as [`igniteui-webcomponents`](https://www.npmjs.com/package/igniteui-webcomponents). This document explains which versions receive security fixes, how to report a vulnerability, what happens after a report, and how consumers can verify what they install. -We provide security support for the **latest major version** of the package only. All previous major versions are considered deprecated and will not receive security updates. +## Supported versions -For critical security vulnerabilities, we will backport fixes to the **last relevant minor version** of the current major version to ensure users can apply security patches without upgrading to a new minor release. +Security fixes are released for the **latest major version**. The **previous major version** receives fixes for **critical** vulnerabilities only, published as a patch on its last minor release. Older major versions receive no security updates. -**Current package version: 7.3.x** +| Version | Support | +| ------------------- | ---------------------------------------------------- | +| Latest major | All security fixes | +| Previous major | Critical vulnerabilities only, on the last minor | +| Older majors | None; upgrade to a supported version | -| Version | Supported | -| ------- | ------------------ | -| 7.x.x | :white_check_mark: | -| 6.x.x | :white_check_mark: | -| < 6.0.0 | :x: | +The current major version is listed on the [npm package page](https://www.npmjs.com/package/igniteui-webcomponents?activeTab=versions) and in the [CHANGELOG](CHANGELOG.md). -### Examples +## Scope -- **Version 7.x.x** (current): Fully supported with security updates. -- **Version 6.x.x**: ✅ Will receive backported fixes for critical security vulnerabilities, but recommended to upgrade to the latest version. -- **Version < 6.x.x**: ❌ Deprecated - no security updates provided. +In scope: -## Reporting a Vulnerability +- The `igniteui-webcomponents` npm package and all of its entry points, including `igniteui-webcomponents/extras`. +- The build and release pipeline in this repository, including the workflows under `.github/workflows` and the scripts under `scripts`. -If you have discovered a security vulnerability in this project, please report it privately. -**Do not disclose it as a public issue**. This gives us time to work with you to fix the issue before public exposure, reducing the chance that the exploit will be used before a patch is released. Please disclose it at [security advisory](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new). +Out of scope: + +- The hosted [Storybook](https://igniteui.github.io/igniteui-webcomponents) and the [product documentation](https://www.infragistics.com/products/ignite-ui-web-components) sites. Report issues with those to [Infragistics support](https://www.infragistics.com/about-us/contact-us). +- Vulnerabilities in third-party dependencies that do not affect this package. Report those to the upstream project. If a dependency vulnerability is reachable through this package, report it here as well. +- Commercial Ignite UI for Web Components packages such as `igniteui-webcomponents-grids` and `igniteui-dockmanager`. Report those through [Infragistics support](https://www.infragistics.com/about-us/contact-us). + +## Reporting a vulnerability + +Report vulnerabilities privately through [GitHub private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new). **Do not open a public issue, discussion or pull request for a security problem.** Private reporting gives us time to prepare a fix before the details become public. + +A useful report includes: + +- The affected component or module and the package version. +- Steps or a minimal reproduction that demonstrates the problem. +- The impact you believe it has, for example script execution in the host page or exposure of data the host page passed to a component. + +## What to expect + +| Step | Target | +| ------------------- | ------------------------------------------------------------- | +| Acknowledgement | Within 3 business days of the report | +| Triage and severity | Within 10 business days, communicated in the advisory thread | +| Fix and release | Within 90 days for confirmed vulnerabilities, sooner for critical ones | +| Disclosure | Coordinated with the reporter, at release or after the fix has had time to propagate | + +Severity follows the [CVSS](https://www.first.org/cvss/) rating GitHub attaches to the advisory. We credit reporters in the advisory unless they ask not to be named. + +## Disclosure + +Fixed vulnerabilities are published as a [GitHub security advisory](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories) with a CVE identifier where applicable, and recorded under a `Security` heading in the [CHANGELOG](CHANGELOG.md) entry of the release that carries the fix. + +## Verifying a release + +Every release published from this repository ships with supply-chain evidence attached to the [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases): + +- The exact tarball that was published to npm, with SHA-256 and SHA-512 digests. +- A CycloneDX 1.6 SBOM describing the delivered dependency closure, and a supplementary SBOM of the build environment. +- Signed build-provenance and SBOM attestations produced with GitHub artifact attestations. + +The package is published with an OIDC token, so npm records provenance for it. To verify the tarball you install matches the one that was built and attested, run: + +```bash +npm pack igniteui-webcomponents@ +gh attestation verify igniteui-webcomponents-.tgz --repo IgniteUI/igniteui-webcomponents +gh attestation verify igniteui-webcomponents-.tgz --repo IgniteUI/igniteui-webcomponents --predicate-type https://cyclonedx.org/bom +``` + +The SBOM README attached to each release describes how the SBOM was generated and how to re-validate it. + +## Security considerations for consumers + +The components render inside the host page and inherit its origin, so the host application remains responsible for the data it passes in. Points worth knowing: + +- **Chat markdown rendering.** The optional chat markdown renderer in `igniteui-webcomponents/extras` converts message text to HTML and sanitizes it with [DOMPurify](https://github.com/cure53/DOMPurify) before rendering. The `sanitizer` option replaces DOMPurify; if you supply your own, it must reject scripts, event handlers and dangerous URLs. Without the extras renderer, message text is rendered as text and not as HTML. +- **Icons.** `registerIcon(name, url)` fetches the URL you pass and renders the response as inline SVG in the component's shadow root. Only register icons from origins you control or trust, and prefer `registerIconFromText` with SVG you have already vetted. +- **QR code export.** Exporting a QR code with an embedded image fetches the image URL you pass to draw it on a canvas. Only supply URLs you trust. +- **Clipboard.** The color picker and chat components write to the clipboard when the user activates a copy control. Nothing is read from the clipboard. +- **No network or storage otherwise.** The components make no network requests of their own, set no cookies and write nothing to web storage. See [PRIVACY.md](PRIVACY.md). +- **Content Security Policy.** The library uses no `eval` or string-to-code APIs. Styles are attached through constructable stylesheets in each component's shadow root. Test your CSP against the components you use before relying on a strict policy. + +## Dependencies + +Runtime dependencies are kept to a minimum and are listed in [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md). Dependabot raises security updates for npm dependencies daily and version updates for GitHub Actions weekly. CI runs CodeQL analysis and the OpenSSF Scorecard; results are visible in the repository's Security tab. The release workflow pins every action to a commit SHA and grants each job only the permissions it needs. From 124f7c40f8f7691f06ecb89fa001880ecc513b84 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:39:06 +0300 Subject: [PATCH 02/12] build(notices): generate third-party license notices and ship them Add scripts/build-notices.mjs, which reads the runtime and optional peer dependencies from the published manifest, collects each package's license text from node_modules, and writes THIRD-PARTY-NOTICES.md. lit and @lit/context are BSD-3-Clause, which requires notice reproduction. The file records declared version ranges rather than installed versions, so `check-notices` (picked up by `npm run check`) fails only when a dependency is added, removed or relicensed, not on patch bumps. `build:publish` regenerates the file and copies it into dist next to LICENSE. --- THIRD-PARTY-NOTICES.md | 866 ++++++++++++++++++++++++++++++++++++++ package.json | 4 +- scripts/build-notices.mjs | 219 ++++++++++ scripts/build.mjs | 1 + 4 files changed, 1089 insertions(+), 1 deletion(-) create mode 100644 THIRD-PARTY-NOTICES.md create mode 100644 scripts/build-notices.mjs diff --git a/THIRD-PARTY-NOTICES.md b/THIRD-PARTY-NOTICES.md new file mode 100644 index 000000000..752a4bfe9 --- /dev/null +++ b/THIRD-PARTY-NOTICES.md @@ -0,0 +1,866 @@ +# Third-party notices + +Ignite UI for Web Components is released under the [MIT License](LICENSE). This file lists the +third-party packages the published `igniteui-webcomponents` package depends on at runtime, together +with their license terms, so that anyone redistributing an application built with this library can +meet the attribution requirements of those licenses. + +Only direct runtime dependencies and optional peer dependencies are listed. They are not bundled +into this package; a consuming application resolves them from npm. The full transitive dependency +closure, with license identifiers for every package, is recorded in the CycloneDX SBOM attached to +each [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases). + +This file is generated by `npm run build:notices` from the installed packages. Do not edit it by +hand; regenerate it when a dependency is added, removed or relicensed. + +## Summary + +| Package | Version range | Relationship | License | Source | +| --- | --- | --- | --- | --- | +| `@floating-ui/dom` | `^1.8.0` | dependency | MIT | | +| `@lit/context` | `^1.1.0` | dependency | BSD-3-Clause | | +| `dompurify` | `^3.4.0` | optional peer dependency | (MPL-2.0 OR Apache-2.0) | | +| `igniteui-i18n-core` | `^1.0.5` | dependency | MIT | | +| `igniteui-i18n-resources` | `^1.0.5` | optional peer dependency | MIT | | +| `lit` | `^3.3.0` | dependency | BSD-3-Clause | | +| `marked` | `^18.0.0` | optional peer dependency | MIT | | +| `marked-shiki` | `^1.2.0` | optional peer dependency | MIT | | +| `shiki` | `^4.3.0` | optional peer dependency | MIT | | + +## License texts + +### @floating-ui/dom + +- License: MIT +- Source: + +```text +MIT License + +Copyright (c) 2021-present Floating UI contributors + +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software is furnished to do so, +subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS +FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR +COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER +IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. +``` + +### @lit/context + +- License: BSD-3-Clause +- Source: + +```text +BSD 3-Clause License + +Copyright (c) 2021 Google LLC. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +1. Redistributions of source code must retain the above copyright notice, this + list of conditions and the following disclaimer. + +2. Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. + +3. Neither the name of the copyright holder nor the names of its + contributors may be used to endorse or promote products derived from + this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER +CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, +OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +``` + +### dompurify + +- License: (MPL-2.0 OR Apache-2.0) +- Source: + +#### LICENSE + +```text +Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +``` + +#### LICENSE-MPL + +```text +Mozilla Public License Version 2.0 +================================== + +1. Definitions +-------------- + +1.1. "Contributor" + means each individual or legal entity that creates, contributes to + the creation of, or owns Covered Software. + +1.2. "Contributor Version" + means the combination of the Contributions of others (if any) used + by a Contributor and that particular Contributor's Contribution. + +1.3. "Contribution" + means Covered Software of a particular Contributor. + +1.4. "Covered Software" + means Source Code Form to which the initial Contributor has attached + the notice in Exhibit A, the Executable Form of such Source Code + Form, and Modifications of such Source Code Form, in each case + including portions thereof. + +1.5. "Incompatible With Secondary Licenses" + means + + (a) that the initial Contributor has attached the notice described + in Exhibit B to the Covered Software; or + + (b) that the Covered Software was made available under the terms of + version 1.1 or earlier of the License, but not also under the + terms of a Secondary License. + +1.6. "Executable Form" + means any form of the work other than Source Code Form. + +1.7. "Larger Work" + means a work that combines Covered Software with other material, in + a separate file or files, that is not Covered Software. + +1.8. "License" + means this document. + +1.9. "Licensable" + means having the right to grant, to the maximum extent possible, + whether at the time of the initial grant or subsequently, any and + all of the rights conveyed by this License. + +1.10. "Modifications" + means any of the following: + + (a) any file in Source Code Form that results from an addition to, + deletion from, or modification of the contents of Covered + Software; or + + (b) any new file in Source Code Form that contains any Covered + Software. + +1.11. "Patent Claims" of a Contributor + means any patent claim(s), including without limitation, method, + process, and apparatus claims, in any patent Licensable by such + Contributor that would be infringed, but for the grant of the + License, by the making, using, selling, offering for sale, having + made, import, or transfer of either its Contributions or its + Contributor Version. + +1.12. "Secondary License" + means either the GNU General Public License, Version 2.0, the GNU + Lesser General Public License, Version 2.1, the GNU Affero General + Public License, Version 3.0, or any later versions of those + licenses. + +1.13. "Source Code Form" + means the form of the work preferred for making modifications. + +1.14. "You" (or "Your") + means an individual or a legal entity exercising rights under this + License. For legal entities, "You" includes any entity that + controls, is controlled by, or is under common control with You. For + purposes of this definition, "control" means (a) the power, direct + or indirect, to cause the direction or management of such entity, + whether by contract or otherwise, or (b) ownership of more than + fifty percent (50%) of the outstanding shares or beneficial + ownership of such entity. + +2. License Grants and Conditions +-------------------------------- + +2.1. Grants + +Each Contributor hereby grants You a world-wide, royalty-free, +non-exclusive license: + +(a) under intellectual property rights (other than patent or trademark) + Licensable by such Contributor to use, reproduce, make available, + modify, display, perform, distribute, and otherwise exploit its + Contributions, either on an unmodified basis, with Modifications, or + as part of a Larger Work; and + +(b) under Patent Claims of such Contributor to make, use, sell, offer + for sale, have made, import, and otherwise transfer either its + Contributions or its Contributor Version. + +2.2. Effective Date + +The licenses granted in Section 2.1 with respect to any Contribution +become effective for each Contribution on the date the Contributor first +distributes such Contribution. + +2.3. Limitations on Grant Scope + +The licenses granted in this Section 2 are the only rights granted under +this License. No additional rights or licenses will be implied from the +distribution or licensing of Covered Software under this License. +Notwithstanding Section 2.1(b) above, no patent license is granted by a +Contributor: + +(a) for any code that a Contributor has removed from Covered Software; + or + +(b) for infringements caused by: (i) Your and any other third party's + modifications of Covered Software, or (ii) the combination of its + Contributions with other software (except as part of its Contributor + Version); or + +(c) under Patent Claims infringed by Covered Software in the absence of + its Contributions. + +This License does not grant any rights in the trademarks, service marks, +or logos of any Contributor (except as may be necessary to comply with +the notice requirements in Section 3.4). + +2.4. Subsequent Licenses + +No Contributor makes additional grants as a result of Your choice to +distribute the Covered Software under a subsequent version of this +License (see Section 10.2) or under the terms of a Secondary License (if +permitted under the terms of Section 3.3). + +2.5. Representation + +Each Contributor represents that the Contributor believes its +Contributions are its original creation(s) or it has sufficient rights +to grant the rights to its Contributions conveyed by this License. + +2.6. Fair Use + +This License is not intended to limit any rights You have under +applicable copyright doctrines of fair use, fair dealing, or other +equivalents. + +2.7. Conditions + +Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted +in Section 2.1. + +3. Responsibilities +------------------- + +3.1. Distribution of Source Form + +All distribution of Covered Software in Source Code Form, including any +Modifications that You create or to which You contribute, must be under +the terms of this License. You must inform recipients that the Source +Code Form of the Covered Software is governed by the terms of this +License, and how they can obtain a copy of this License. You may not +attempt to alter or restrict the recipients' rights in the Source Code +Form. + +3.2. Distribution of Executable Form + +If You distribute Covered Software in Executable Form then: + +(a) such Covered Software must also be made available in Source Code + Form, as described in Section 3.1, and You must inform recipients of + the Executable Form how they can obtain a copy of such Source Code + Form by reasonable means in a timely manner, at a charge no more + than the cost of distribution to the recipient; and + +(b) You may distribute such Executable Form under the terms of this + License, or sublicense it under different terms, provided that the + license for the Executable Form does not attempt to limit or alter + the recipients' rights in the Source Code Form under this License. + +3.3. Distribution of a Larger Work + +You may create and distribute a Larger Work under terms of Your choice, +provided that You also comply with the requirements of this License for +the Covered Software. If the Larger Work is a combination of Covered +Software with a work governed by one or more Secondary Licenses, and the +Covered Software is not Incompatible With Secondary Licenses, this +License permits You to additionally distribute such Covered Software +under the terms of such Secondary License(s), so that the recipient of +the Larger Work may, at their option, further distribute the Covered +Software under the terms of either this License or such Secondary +License(s). + +3.4. Notices + +You may not remove or alter the substance of any license notices +(including copyright notices, patent notices, disclaimers of warranty, +or limitations of liability) contained within the Source Code Form of +the Covered Software, except that You may alter any license notices to +the extent required to remedy known factual inaccuracies. + +3.5. Application of Additional Terms + +You may choose to offer, and to charge a fee for, warranty, support, +indemnity or liability obligations to one or more recipients of Covered +Software. However, You may do so only on Your own behalf, and not on +behalf of any Contributor. You must make it absolutely clear that any +such warranty, support, indemnity, or liability obligation is offered by +You alone, and You hereby agree to indemnify every Contributor for any +liability incurred by such Contributor as a result of warranty, support, +indemnity or liability terms You offer. You may include additional +disclaimers of warranty and limitations of liability specific to any +jurisdiction. + +4. Inability to Comply Due to Statute or Regulation +--------------------------------------------------- + +If it is impossible for You to comply with any of the terms of this +License with respect to some or all of the Covered Software due to +statute, judicial order, or regulation then You must: (a) comply with +the terms of this License to the maximum extent possible; and (b) +describe the limitations and the code they affect. Such description must +be placed in a text file included with all distributions of the Covered +Software under this License. Except to the extent prohibited by statute +or regulation, such description must be sufficiently detailed for a +recipient of ordinary skill to be able to understand it. + +5. Termination +-------------- + +5.1. The rights granted under this License will terminate automatically +if You fail to comply with any of its terms. However, if You become +compliant, then the rights granted under this License from a particular +Contributor are reinstated (a) provisionally, unless and until such +Contributor explicitly and finally terminates Your grants, and (b) on an +ongoing basis, if such Contributor fails to notify You of the +non-compliance by some reasonable means prior to 60 days after You have +come back into compliance. Moreover, Your grants from a particular +Contributor are reinstated on an ongoing basis if such Contributor +notifies You of the non-compliance by some reasonable means, this is the +first time You have received notice of non-compliance with this License +from such Contributor, and You become compliant prior to 30 days after +Your receipt of the notice. + +5.2. If You initiate litigation against any entity by asserting a patent +infringement claim (excluding declaratory judgment actions, +counter-claims, and cross-claims) alleging that a Contributor Version +directly or indirectly infringes any patent, then the rights granted to +You by any and all Contributors for the Covered Software under Section +2.1 of this License shall terminate. + +5.3. In the event of termination under Sections 5.1 or 5.2 above, all +end user license agreements (excluding distributors and resellers) which +have been validly granted by You or Your distributors under this License +prior to termination shall survive termination. + +************************************************************************ +* * +* 6. Disclaimer of Warranty * +* ------------------------- * +* * +* Covered Software is provided under this License on an "as is" * +* basis, without warranty of any kind, either expressed, implied, or * +* statutory, including, without limitation, warranties that the * +* Covered Software is free of defects, merchantable, fit for a * +* particular purpose or non-infringing. The entire risk as to the * +* quality and performance of the Covered Software is with You. * +* Should any Covered Software prove defective in any respect, You * +* (not any Contributor) assume the cost of any necessary servicing, * +* repair, or correction. This disclaimer of warranty constitutes an * +* essential part of this License. No use of any Covered Software is * +* authorized under this License except under this disclaimer. * +* * +************************************************************************ + +************************************************************************ +* * +* 7. Limitation of Liability * +* -------------------------- * +* * +* Under no circumstances and under no legal theory, whether tort * +* (including negligence), contract, or otherwise, shall any * +* Contributor, or anyone who distributes Covered Software as * +* permitted above, be liable to You for any direct, indirect, * +* special, incidental, or consequential damages of any character * +* including, without limitation, damages for lost profits, loss of * +* goodwill, work stoppage, computer failure or malfunction, or any * +* and all other commercial damages or losses, even if such party * +* shall have been informed of the possibility of such damages. This * +* limitation of liability shall not apply to liability for death or * +* personal injury resulting from such party's negligence to the * +* extent applicable law prohibits such limitation. Some * +* jurisdictions do not allow the exclusion or limitation of * +* incidental or consequential damages, so this exclusion and * +* limitation may not apply to You. * +* * +************************************************************************ + +8. Litigation +------------- + +Any litigation relating to this License may be brought only in the +courts of a jurisdiction where the defendant maintains its principal +place of business and such litigation shall be governed by laws of that +jurisdiction, without reference to its conflict-of-law provisions. +Nothing in this Section shall prevent a party's ability to bring +cross-claims or counter-claims. + +9. Miscellaneous +---------------- + +This License represents the complete agreement concerning the subject +matter hereof. If any provision of this License is held to be +unenforceable, such provision shall be reformed only to the extent +necessary to make it enforceable. Any law or regulation which provides +that the language of a contract shall be construed against the drafter +shall not be used to construe this License against a Contributor. + +10. Versions of the License +--------------------------- + +10.1. New Versions + +Mozilla Foundation is the license steward. Except as provided in Section +10.3, no one other than the license steward has the right to modify or +publish new versions of this License. Each version will be given a +distinguishing version number. + +10.2. Effect of New Versions + +You may distribute the Covered Software under the terms of the version +of the License under which You originally received the Covered Software, +or under the terms of any subsequent version published by the license +steward. + +10.3. Modified Versions + +If you create software not governed by this License, and you want to +create a new license for such software, you may create and use a +modified version of this License if you rename the license and remove +any references to the name of the license steward (except to note that +such modified license differs from this License). + +10.4. Distributing Source Code Form that is Incompatible With Secondary +Licenses + +If You choose to distribute Source Code Form that is Incompatible With +Secondary Licenses under the terms of this version of the License, the +notice described in Exhibit B of this License must be attached. + +Exhibit A - Source Code Form License Notice +------------------------------------------- + + This Source Code Form is subject to the terms of the Mozilla Public + License, v. 2.0. If a copy of the MPL was not distributed with this + file, You can obtain one at http://mozilla.org/MPL/2.0/. + +If it is not possible or desirable to put the notice in a particular +file, then You may include the notice in a location (such as a LICENSE +file in a relevant directory) where a recipient would be likely to look +for such a notice. + +You may add additional accurate notices of copyright ownership. + +Exhibit B - "Incompatible With Secondary Licenses" Notice +--------------------------------------------------------- + + This Source Code Form is "Incompatible With Secondary Licenses", as + defined by the Mozilla Public License, v. 2.0. +``` + +### igniteui-i18n-core + +- License: MIT +- Source: + +```text +MIT License + +Copyright (c) 2025 INFRAGISTICS + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. +``` + +### igniteui-i18n-resources + +- License: MIT +- Source: + +```text +MIT License + +Copyright (c) 2025 INFRAGISTICS + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. +``` + +### lit + +- License: BSD-3-Clause +- Source: + +```text +BSD 3-Clause License + +Copyright (c) 2017 Google LLC. All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions are met: + +1. Redistributions of source code must retain the above copyright notice, this + list of conditions and the following disclaimer. + +2. Redistributions in binary form must reproduce the above copyright notice, + this list of conditions and the following disclaimer in the documentation + and/or other materials provided with the distribution. + +3. Neither the name of the copyright holder nor the names of its + contributors may be used to endorse or promote products derived from + this software without specific prior written permission. + +THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" +AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE +IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE +DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE +FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL +DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR +SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER +CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, +OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE +OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. +``` + +### marked + +- License: MIT +- Source: + +```text +# License information + +## Contribution License Agreement + +If you contribute code to this project, you are implicitly allowing your code +to be distributed under the MIT license. You are also implicitly verifying that +all code is your original work. `` + +## Marked + +Copyright (c) 2018+, MarkedJS (https://github.com/markedjs/) +Copyright (c) 2011-2018, Christopher Jeffrey (https://github.com/chjj/) + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. + +## Markdown + +Copyright © 2004, John Gruber +http://daringfireball.net/ +All rights reserved. + +Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: + +* Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. +* Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. +* Neither the name “Markdown” nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. + +This software is provided by the copyright holders and contributors “as is” and any express or implied warranties, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose are disclaimed. In no event shall the copyright owner or contributors be liable for any direct, indirect, incidental, special, exemplary, or consequential damages (including, but not limited to, procurement of substitute goods or services; loss of use, data, or profits; or business interruption) however caused and on any theory of liability, whether in contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use of this software, even if advised of the possibility of such damage. +``` + +### marked-shiki + +- License: MIT +- Source: + +The package ships no license file. Its manifest declares `MIT`; refer to the source repository for the license text. + +### shiki + +- License: MIT +- Source: + +```text +MIT License + +Copyright (c) 2021 Pine Wu +Copyright (c) 2023 Anthony Fu + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. +``` diff --git a/package.json b/package.json index a94c1cbac..14cffafd6 100644 --- a/package.json +++ b/package.json @@ -27,7 +27,8 @@ }, "scripts": { "start": "npm run storybook", - "build:publish": "npm run cem && node scripts/build.mjs", + "build:publish": "npm run cem && npm run build:notices && node scripts/build.mjs", + "build:notices": "node scripts/build-notices.mjs", "build:sbom": "node scripts/build-sbom.mjs", "cem": "cem analyze --config cem.config.mjs", "cem:watch": "cem analyze --config cem.config.mjs --watch", @@ -40,6 +41,7 @@ "check-scripts": "tsc -p scripts/tsconfig.json", "check-stories": "tsc -p scripts/tsconfig.stories.json", "check-aliases": "node scripts/check-import-aliases.mjs", + "check-notices": "node scripts/build-notices.mjs --check", "check": "concurrently -g \"npm:check-*\"", "clean": "rimraf ./dist ./docs --glob \"src/**/*.css.ts\"", "lint": "concurrently -g \"npm:lint:*\"", diff --git a/scripts/build-notices.mjs b/scripts/build-notices.mjs new file mode 100644 index 000000000..6219bd778 --- /dev/null +++ b/scripts/build-notices.mjs @@ -0,0 +1,219 @@ +import fs from 'node:fs'; +import path from 'node:path'; +import { fileURLToPath } from 'node:url'; + +import getArgs from './get-args.mjs'; +import { log, logError } from './logger.mjs'; + +const CATEGORY = 'notices'; +const OUTPUT_FILE = 'THIRD-PARTY-NOTICES.md'; +const LICENSE_FILE_PATTERN = /^(licen[cs]e|copying|notice)(?![a-z])/i; + +const scriptDir = path.dirname(fileURLToPath(import.meta.url)); +const repoRoot = path.resolve(scriptDir, '..'); +const nodeModules = path.join(repoRoot, 'node_modules'); + +/** + * @param {string} file - Path to a JSON file. + * @returns {any} Parsed content. + */ +function readJson(file) { + return JSON.parse(fs.readFileSync(file, 'utf8')); +} + +/** + * Read a package manifest by path. Several dependencies hide `package.json` + * behind an exports map, so module resolution cannot be used here. + * @param {string} name - Package name. + * @returns {any} The installed manifest. + */ +function readInstalledManifest(name) { + const manifest = path.join(nodeModules, name, 'package.json'); + + if (!fs.existsSync(manifest)) { + throw new Error( + `${name} is not installed under node_modules. Run "npm ci" first.` + ); + } + + return readJson(manifest); +} + +/** + * @param {any} manifest - Installed package manifest. + * @returns {string} Repository or homepage URL, browsable where possible. + */ +function sourceUrl(manifest) { + const repository = + typeof manifest.repository === 'string' + ? manifest.repository + : manifest.repository?.url; + + if (!repository) { + return manifest.homepage ?? ''; + } + + return repository + .replace(/^git\+/, '') + .replace(/^git:\/\//, 'https://') + .replace(/^ssh:\/\/git@/, 'https://') + .replace(/\.git$/, ''); +} + +/** + * @param {any} manifest - Installed package manifest. + * @returns {string} SPDX expression, or the legacy `licenses` array joined. + */ +function licenseExpression(manifest) { + if (typeof manifest.license === 'string') { + return manifest.license; + } + if (manifest.license?.type) { + return manifest.license.type; + } + if (Array.isArray(manifest.licenses)) { + return manifest.licenses.map((entry) => entry.type ?? entry).join(' OR '); + } + return 'UNKNOWN'; +} + +/** + * Every license-like file shipped at the package root, in a stable order. + * @param {string} name - Package name. + * @returns {{ name: string, text: string }[]} License files and their content. + */ +function licenseFiles(name) { + const dir = path.join(nodeModules, name); + + return fs + .readdirSync(dir) + .filter((entry) => LICENSE_FILE_PATTERN.test(entry)) + .sort() + .map((entry) => ({ + name: entry, + text: fs.readFileSync(path.join(dir, entry), 'utf8').trim(), + })); +} + +/** + * @param {string} name - Package name. + * @param {string} range - Declared version range. + * @param {'dependency' | 'optional peer dependency'} kind - Relationship. + * @returns {object} Notice entry. + */ +function collect(name, range, kind) { + const manifest = readInstalledManifest(name); + const files = licenseFiles(name); + + if (files.length === 0) { + log(CATEGORY, `${name} ships no license file; recording its SPDX id only`); + } + + return { + name, + range, + kind, + license: licenseExpression(manifest), + url: sourceUrl(manifest), + files, + }; +} + +/** + * @param {object[]} entries - Collected notice entries. + * @returns {string} The rendered Markdown document. + */ +function render(entries) { + const lines = [ + '# Third-party notices', + '', + 'Ignite UI for Web Components is released under the [MIT License](LICENSE). This file lists the', + 'third-party packages the published `igniteui-webcomponents` package depends on at runtime, together', + 'with their license terms, so that anyone redistributing an application built with this library can', + 'meet the attribution requirements of those licenses.', + '', + 'Only direct runtime dependencies and optional peer dependencies are listed. They are not bundled', + 'into this package; a consuming application resolves them from npm. The full transitive dependency', + 'closure, with license identifiers for every package, is recorded in the CycloneDX SBOM attached to', + 'each [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases).', + '', + 'This file is generated by `npm run build:notices` from the installed packages. Do not edit it by', + 'hand; regenerate it when a dependency is added, removed or relicensed.', + '', + '## Summary', + '', + '| Package | Version range | Relationship | License | Source |', + '| --- | --- | --- | --- | --- |', + ...entries.map( + (entry) => + `| \`${entry.name}\` | \`${entry.range}\` | ${entry.kind} | ${entry.license} | ${entry.url ? `<${entry.url}>` : ''} |` + ), + '', + '## License texts', + '', + ]; + + for (const entry of entries) { + lines.push(`### ${entry.name}`, ''); + lines.push(`- License: ${entry.license}`); + if (entry.url) { + lines.push(`- Source: <${entry.url}>`); + } + lines.push(''); + + if (entry.files.length === 0) { + lines.push( + `The package ships no license file. Its manifest declares \`${entry.license}\`; refer to the source repository for the license text.`, + '' + ); + continue; + } + + for (const file of entry.files) { + if (entry.files.length > 1) { + lines.push(`#### ${file.name}`, ''); + } + lines.push('```text', file.text, '```', ''); + } + } + + return `${lines.join('\n').trimEnd()}\n`; +} + +const args = getArgs(); +const output = path.join(repoRoot, OUTPUT_FILE); + +try { + // The published manifest, not the repository one: it declares what consumers resolve. + const manifest = readJson(path.join(scriptDir, '_package.json')); + const entries = [ + ...Object.entries(manifest.dependencies ?? {}).map(([name, range]) => + collect(name, range, 'dependency') + ), + ...Object.entries(manifest.peerDependencies ?? {}).map(([name, range]) => + collect(name, range, 'optional peer dependency') + ), + ].sort((left, right) => left.name.localeCompare(right.name)); + + const rendered = render(entries); + + if (args.check) { + const current = fs.existsSync(output) + ? fs.readFileSync(output, 'utf8') + : ''; + + if (current !== rendered) { + throw new Error( + `${OUTPUT_FILE} is out of date. Run "npm run build:notices" and commit the result.` + ); + } + + log(CATEGORY, `${OUTPUT_FILE} is up to date (${entries.length} packages)`); + } else { + fs.writeFileSync(output, rendered); + log(CATEGORY, `wrote ${OUTPUT_FILE} (${entries.length} packages)`); + } +} catch (error) { + logError(CATEGORY, 'third-party notices generation failed', error); + process.exitCode = 1; +} diff --git a/scripts/build.mjs b/scripts/build.mjs index 15e93296b..e90ea2a49 100644 --- a/scripts/build.mjs +++ b/scripts/build.mjs @@ -23,6 +23,7 @@ const RELEASE_FILES = [ 'CHANGELOG.md', 'LICENSE', 'README.md', + 'THIRD-PARTY-NOTICES.md', ]; function spin(tag) { From b874b88c626369d804221a9c0235185016f5ff49 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:39:59 +0300 Subject: [PATCH 03/12] ci: add CodeQL and OpenSSF Scorecard workflows and pin actions by SHA CodeQL analyzes the TypeScript sources on push, pull request and weekly, skipping build output and spec/story files. Scorecard runs on push to master, on branch-protection changes and weekly, publishing results so the README badge and API resolve; the job follows the publishing API's workflow restrictions. Pin every action in the CI and Storybook workflows to a commit SHA with the version in a trailing comment, matching the release workflow. Dependabot keeps the pins current. --- .github/workflows/codeql.yml | 57 +++++++++++++++++++++++++++ .github/workflows/gh-pages-deploy.yml | 6 +-- .github/workflows/node.js.yml | 12 +++--- .github/workflows/scorecard.yml | 56 ++++++++++++++++++++++++++ 4 files changed, 122 insertions(+), 9 deletions(-) create mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/scorecard.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 000000000..219edeb9f --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,57 @@ +# Static analysis of the TypeScript sources with CodeQL. Results appear under +# Security > Code scanning. Runs on every change to master and weekly, so that +# newly published queries also cover code that did not change. +name: CodeQL + +permissions: + contents: read + +on: + push: + branches: [master] + pull_request: + branches: [master] + schedule: + # Mondays at 06:17 UTC. + - cron: '17 6 * * 1' + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +jobs: + analyze: + name: Analyze + runs-on: ubuntu-latest + timeout-minutes: 30 + permissions: + security-events: write + contents: read + actions: read + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + with: + languages: javascript-typescript + # TypeScript needs no build for CodeQL to extract it. + build-mode: none + # Compiled output, coverage and Storybook builds are derived from the + # sources and would only duplicate findings. + config: | + paths-ignore: + - dist + - coverage + - storybook-static + - '**/*.spec.ts' + - '**/*.stories.ts' + + - name: Analyze + uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + with: + category: '/language:javascript-typescript' diff --git a/.github/workflows/gh-pages-deploy.yml b/.github/workflows/gh-pages-deploy.yml index d29e7269e..35dad948d 100644 --- a/.github/workflows/gh-pages-deploy.yml +++ b/.github/workflows/gh-pages-deploy.yml @@ -19,14 +19,14 @@ jobs: url: ${{ steps.build-publish.outputs.page_url }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: actions/setup-node@v7 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: '24' - id: build-publish - uses: bitovi/github-actions-storybook-to-github-pages@v1.0.4 + uses: bitovi/github-actions-storybook-to-github-pages@ddd9d35f670cceedd2bfc444be681001b0709730 # v1.0.4 with: path: storybook-static install_command: npm ci diff --git a/.github/workflows/node.js.yml b/.github/workflows/node.js.yml index f203e78f8..a7378ac79 100644 --- a/.github/workflows/node.js.yml +++ b/.github/workflows/node.js.yml @@ -25,8 +25,8 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7.0.1 - - uses: actions/setup-node@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: '24' cache: 'npm' @@ -48,9 +48,9 @@ jobs: # See supported Node.js release schedule at https://nodejs.org/en/about/releases/ steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v7 + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: ${{ matrix.node-version }} cache: 'npm' @@ -62,7 +62,7 @@ jobs: - name: Restore the Playwright browsers id: playwright-cache - uses: actions/cache@v6 + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ~/.cache/ms-playwright key: playwright-${{ runner.os }}-${{ steps.playwright.outputs.version }} @@ -81,7 +81,7 @@ jobs: - name: Publish to coveralls.io if: matrix.node-version == '24.x' - uses: coverallsapp/github-action@v2 + uses: coverallsapp/github-action@8d6379e14d29928660c4ba802d8e85393440b329 # v2.3.8 with: github-token: ${{ github.token }} fail-on-error: false diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml new file mode 100644 index 000000000..64af962b6 --- /dev/null +++ b/.github/workflows/scorecard.yml @@ -0,0 +1,56 @@ +# OpenSSF Scorecard: checks the repository's supply-chain posture (pinned +# dependencies, token permissions, branch protection, code review, and so on) +# and publishes the result to the Scorecard API, which powers the README badge. +# +# The publishing API rejects results from workflows that do not follow its +# rules: no workflow-level env or write permissions, and only the allow-listed +# actions in this job. Keep it as it is. +# https://github.com/ossf/scorecard-action#workflow-restrictions +name: OpenSSF Scorecard + +permissions: read-all + +on: + push: + branches: [master] + # Branch-protection settings change outside of pushes. + branch_protection_rule: + schedule: + # Saturdays at 01:30 UTC. + - cron: '30 1 * * 6' + +jobs: + analysis: + name: Scorecard analysis + runs-on: ubuntu-latest + timeout-minutes: 15 + permissions: + # Upload the SARIF to code scanning. + security-events: write + # OIDC token for publish_results. + id-token: write + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Run analysis + uses: ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4 + with: + results_file: results.sarif + results_format: sarif + publish_results: true + + - name: Upload SARIF artifact + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: scorecard-sarif + path: results.sarif + retention-days: 5 + + - name: Upload to code scanning + uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + with: + sarif_file: results.sarif From 0bcb01bb796743c1ead43b7346c6b629008aa025 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:40:32 +0300 Subject: [PATCH 04/12] doc(contributing): document accessibility, dependency and security rules Move the lint, check, test and Storybook commands from the README into CONTRIBUTING. Add sections on accessibility requirements (axe on both DOM trees, APG keyboard patterns, ElementInternals over IDREF), dependency policy (discuss first, permissive licenses only, both manifests, notices regeneration, SHA-pinned actions), security expectations for changes, and the Keep a Changelog `Security` category. State that no CLA or DCO sign-off is required. Extend the pull request checklist with changelog, accessibility, dependency and security items. --- .github/CONTRIBUTING.md | 92 ++++++++++++++++++++++++++++++++ .github/pull_request_template.md | 4 ++ 2 files changed, 96 insertions(+) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index a7af8ebcb..e3db24bdc 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -14,6 +14,8 @@ For detailed information on issue and pull request statuses, process for testing - **Clone your Fork**: Clone your forked repository to your local machine using Git. This will create a local copy of the project you can work on. - **Create a Branch**: Create a new branch for your specific contribution. This helps keep your changes isolated and organized. +No contributor license agreement or sign-off is required. By submitting a pull request you agree that your contribution is licensed under the project's [MIT License](../LICENSE). + ## Set up You will need at least [Node >= 24.0.0](https://nodejs.org/en) installed on your machine. @@ -30,11 +32,99 @@ npm ci npm start ``` +## Development workflow + +### Linting and formatting + +To scan the project for linting errors, run: + +```sh +npm run lint +``` + +To automatically fix most linting and formatting errors, run: + +```sh +npm run format +``` + +Linting and formatting also run in a pre-commit hook. + +### Type checks and consistency checks + +```sh +npm run check +``` + +This runs every `check-*` script: type checks for the sources, scripts and stories, the import-boundary check, the import-alias check and the third-party notices check. + +### Testing with Web Test Runner + +To run the suite of Web Test Runner tests, run: + +```sh +npm run test +``` + +To run the tests in watch mode, run: + +```sh +npm run test:watch +``` + +### Demoing with Storybook + +To start a local instance of Storybook for your component, run: + +```sh +npm run storybook +``` + +To build a production version of Storybook, run: + +```sh +npm run storybook:build +``` + ## Making Changes - **Code Style**: Follow the [existing code style conventions](./CODING_GUIDELINES.md) used in the project. This might involve specific formatting guidelines or linting tools. Refer to the project's codebase or any existing documentation for details. - **Commit Messages**: Write clear and concise commit messages that describe your changes. - **Testing**: Ensure your contributions include relevant tests to verify their functionality and avoid introducing regressions. +- **Changelog**: Add an entry under `[Unreleased]` in [CHANGELOG.md](../CHANGELOG.md) for every user-visible change. The file follows [Keep a Changelog](https://keepachangelog.com/), so use the `Added`, `Changed`, `Deprecated`, `Removed`, `Fixed` and `Security` categories. A fix for a vulnerability goes under `Security`, with a link to the advisory once it is published. + +## Accessibility + +Accessibility is a requirement, not a feature. See [ACCESSIBILITY.md](../ACCESSIBILITY.md) for the conformance target and the platform constraints that shape how the components expose semantics. + +- Every component specification must audit the component with axe, on both its light DOM and its shadow DOM, in each state the specification exercises: `await expect(el).to.be.accessible()` and `await expect(el).shadowDom.to.be.accessible()`. +- Follow the [ARIA Authoring Practices Guide](https://www.w3.org/WAI/ARIA/apg/) pattern for the component's role, including its keyboard interaction. Add keyboard tests for it. +- Publish semantics through `ElementInternals` and ARIA element reflection rather than IDREF attributes, so that relations work across shadow boundaries. Use the controllers under `src/internals/controllers` instead of setting ARIA attributes by hand. +- Disable an axe rule only when it misreports semantics published through internals or element reflection, assert the real relation in the specification instead, and document the exception next to the shared options in `src/internals/testing/helpers.spec.ts`. +- Verify interactive changes by hand with a keyboard and a screen reader before requesting review. + +## Dependencies + +Runtime dependencies increase the install footprint and the attack surface of every application that uses the library, so they are added rarely and deliberately. + +- **Discuss first.** Open an issue or a discussion before adding a runtime dependency or an optional peer dependency. Prefer a small, focused implementation in `src/internals` over a package that does more than the component needs. +- **Licenses.** Runtime and peer dependencies must be licensed under MIT, BSD-2-Clause, BSD-3-Clause, ISC, Apache-2.0, 0BSD or an equivalent permissive license. Copyleft licenses (GPL, LGPL, AGPL, SSPL) are not accepted for anything that ships to consumers. Dual-licensed packages are accepted when one of the options is permissive. +- **Manifests.** A runtime dependency is declared in both `package.json` and the published manifest `scripts/_package.json`. Optional peer dependencies are declared with `peerDependenciesMeta.optional: true` in the published manifest. +- **Notices.** After changing a runtime or peer dependency, run `npm run build:notices` and commit the regenerated `THIRD-PARTY-NOTICES.md`. CI fails when the file is out of date. +- **Lockfile.** Commit `package-lock.json` changes together with the manifest change. Install with `npm ci`, never `npm install`, so the lockfile stays authoritative. +- **Updates.** Dependabot raises security updates for npm packages daily and version updates for GitHub Actions weekly. Routine npm version bumps are done by maintainers in batches. GitHub Actions are pinned to a commit SHA with the version in a trailing comment; keep that format when adding or updating an action. +- **Dev dependencies** follow the same license rules and are otherwise at the maintainers' discretion. + +## Security + +Never report a vulnerability in a public issue, discussion or pull request. Use [private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new) as described in [SECURITY.md](../SECURITY.md). + +When you contribute code, keep the following in mind: + +- Treat every value that reaches a component from the host page as untrusted. Render text as text; when a feature must render HTML, sanitize it and make the sanitizer replaceable, as the chat markdown renderer does. +- Do not add network requests, storage access or telemetry. The library's [privacy commitments](../PRIVACY.md) depend on this. +- Do not introduce `eval`, `new Function`, string-based timers or other string-to-code paths. +- Changes to the workflows under `.github/workflows` or to the scripts that build and publish the package are reviewed for supply-chain impact. Keep job permissions minimal and actions pinned. ## Contributing Code @@ -48,4 +138,6 @@ npm start - **Clear and Descriptive Titles**: Use clear and descriptive titles for your issue reports to help maintainers understand the problem quickly. - **Provide Details**: In your issue report, provide as much detail as possible to help diagnose the problem. This might include steps to reproduce the issue, error messages, and expected behavior. +See [SUPPORT.md](./SUPPORT.md) for where questions, feature requests, security reports and commercial support requests belong. + Thank you! diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index 384c100dd..9c91b60df 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -31,4 +31,8 @@ Closes # - [ ] My code follows the project's coding standards - [ ] I have tested my changes locally - [ ] I have updated documentation if needed +- [ ] I have added a `CHANGELOG.md` entry under `[Unreleased]` - [ ] Breaking changes are documented in the description +- [ ] Accessibility: axe audits pass on the light and shadow DOM, and keyboard interaction is covered by tests +- [ ] Dependencies: no new runtime or peer dependency, or its license was reviewed and `THIRD-PARTY-NOTICES.md` was regenerated +- [ ] Security: the change adds no network access, storage, telemetry or unsanitized HTML rendering From cf8d64f3e544721de5e0e0f1bf824f4a7b8c7e1a Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:41:05 +0300 Subject: [PATCH 05/12] doc(readme): restructure around quick start and policy links Reorder into quick start, components, browser support, tooling, then short Accessibility, Security and supply chain, Privacy, Contributing, Support and License sections that each link to their document. Add CodeQL, OpenSSF Scorecard and license badges and a table of contents. Development commands now live in CONTRIBUTING. New document links are absolute URLs because the same README ships in the npm package. --- README.md | 169 +++++++++++++++++++++++++++++------------------------- 1 file changed, 92 insertions(+), 77 deletions(-) diff --git a/README.md b/README.md index b9e6222bb..f74e6b624 100644 --- a/README.md +++ b/README.md @@ -5,24 +5,74 @@ [![Node.js CI](https://github.com/IgniteUI/igniteui-webcomponents/workflows/Node.js%20CI/badge.svg)](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/node.js.yml) +[![CodeQL](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/codeql.yml/badge.svg)](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/codeql.yml) +[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/IgniteUI/igniteui-webcomponents/badge)](https://scorecard.dev/viewer/?uri=github.com/IgniteUI/igniteui-webcomponents) [![Coverage Status](https://coveralls.io/repos/github/IgniteUI/igniteui-webcomponents/badge.svg)](https://coveralls.io/github/IgniteUI/igniteui-webcomponents) [![npm version](https://badge.fury.io/js/igniteui-webcomponents.svg)](https://badge.fury.io/js/igniteui-webcomponents) +[![License: MIT](https://img.shields.io/github/license/IgniteUI/igniteui-webcomponents)](https://github.com/IgniteUI/igniteui-webcomponents/blob/master/LICENSE) [![Discord](https://img.shields.io/discord/836634487483269200?logo=discord&logoColor=ffffff)](https://discord.gg/39MjrTRqds) [Ignite UI for Web Components] is a comprehensive library that includes the fastest [Data Grid] on the market, a high-performing [Hierarchical Grid], Pivot Grid, 60+ data [Charts], [Dock Manager], and more. Plus maps, gauges and other reusable feature-rich components to help you create better web apps and modern-day UX experiences. -See the [Storybook Here](https://igniteui.github.io/igniteui-webcomponents) +[Documentation][Ignite UI for Web Components] · [Storybook] · [Changelog] · [Discord](https://discord.gg/39MjrTRqds) -## Browser Support +## Table of contents -| ![chrome_48x48] | ![firefox_48x48] | ![edge_48x48] | ![opera_48x48] | ![safari_48x48] | -| --------------- | ---------------- | ------------- | -------------- | --------------- | -| Latest ✔️ | Latest ✔️ | Latest ✔️ | Latest ✔️ | Latest ✔️ | +- [Quick start](#quick-start) +- [Components](#components) +- [Browser support](#browser-support) +- [Tooling](#tooling) +- [Accessibility](#accessibility) +- [Security and supply chain](#security-and-supply-chain) +- [Privacy](#privacy) +- [Contributing](#contributing) +- [Support](#support) +- [License](#license) -## Overview +## Quick start + +Install the `igniteui-webcomponents` package: + +```sh +npm install igniteui-webcomponents +``` + +Import and register the components you need with the `defineComponents` function: + +```ts +import { + defineComponents, + IgcAvatarComponent, + IgcBadgeComponent, +} from 'igniteui-webcomponents'; + +defineComponents(IgcAvatarComponent, IgcBadgeComponent); +``` + +You can also register every component at once with `defineAllComponents`: + +```ts +import { defineAllComponents } from 'igniteui-webcomponents'; + +defineAllComponents(); +``` + +Registering all components increases the bundle size of your application, so register only the ones you use. + +After the components are registered, use them in your HTML: + +```html + +``` + +See the [documentation][Ignite UI for Web Components] for guides on each component, theming, and framework integration. + +## Components + +All components in this package are released under the MIT License. The table lists the release in which each component first shipped.
-Components +Component list | Components | Status | Documentation | Released Version | License | | :---------------------- | :----: | :----------------------------: | :--------------: | :------------: | @@ -79,7 +129,9 @@ See the [Storybook Here](https://igniteui.github.io/igniteui-webcomponents)
-## Components available in Ignite UI for WebComponents Grids & Grid Lite +### Grids, Grid Lite and Dock Manager + +The grids and the Dock Manager ship in separate packages. Grid Lite is MIT licensed; the others are commercial products. | Components | Status | Documentation | License | Package | | :---------------- | :----: | :----------------------------: | :------------------------------: | :----------------------------------------------------------------------: | @@ -89,11 +141,11 @@ See the [Storybook Here](https://igniteui.github.io/igniteui-webcomponents) | Hierarchical Grid | ✅ | [Docs][Hierarchical Grid Docs] | [Commercial][Commercial License] | [Ignite UI Web Components Grids][Ignite UI for WebComponents Grids] | | Grid Lite | ✅ | [Docs][Grid Lite] | [MIT](LICENSE) | [Ignite UI Web Components Grid Lite][Ignite UI Web Components Grid Lite] | -### The Lightweight Web Components Data Grid and Data Table +#### The Lightweight Web Components Data Grid and Data Table The Ignite UI for Web Components Data Grid and Table are both lightweight and developed to handle high data volumes. The Web Components Grid offers powerful data visualization capabilities and superior performance on any device. With interactive features that users expect. Fast rendering. Unbeatable interactions. And the best possible user experience that you wouldn’t otherwise be able to achieve with so little code on your own. -### Dock Manager - EXCLUSIVE FEATURE +#### Dock Manager - EXCLUSIVE FEATURE ![Dock Manager Picture] @@ -103,43 +155,15 @@ Provide a complete windowing experience, splitting complex layouts into smaller, - License - [Commercial][Commercial License] - Package - [igniteui-dockmanager](https://www.npmjs.com/package/igniteui-dockmanager) -## Usage - -In order to use the Ignite UI Web Components in your application you should install the `igniteui-webcomponents` package: - -```sh -npm install igniteui-webcomponents -``` - -Next you will need to import the components that you want to use. You could import one or more components using the `defineComponents` function like this: - -```ts -import { - defineComponents, - IgcAvatarComponent, - IgcBadgeComponent, -} from 'igniteui-webcomponents'; - -defineComponents(IgcAvatarComponent, IgcBadgeComponent); -``` +## Browser support -You could also import all of the components using the `defineAllComponents` function: - -```ts -import { defineAllComponents } from 'igniteui-webcomponents'; - -defineAllComponents(); -``` - -Please note that importing all of the components will increase the bundle size of your application. That's why we recommend you to import only the components that you are actually using. - -After the components are imported you could use them in your html: +| ![chrome_48x48] | ![firefox_48x48] | ![edge_48x48] | ![opera_48x48] | ![safari_48x48] | +| --------------- | ---------------- | ------------- | -------------- | --------------- | +| Latest ✔️ | Latest ✔️ | Latest ✔️ | Latest ✔️ | Latest ✔️ | -```html - -``` +## Tooling -### Additional tooling +### Editor metadata The package comes with its own [Custom Elements Manifest], [VSCode Custom Data Format] for VSCode and [Web Types] for JetBrains IDEs. Refer to the documentation of your editor of choice to see if you can take advantage of this metadata for linting, intellisense and documentation. @@ -176,54 +200,37 @@ Copy-Item -Recurse node_modules\igniteui-webcomponents\skills\* .github\skills\ See the [AI agent skills guide](skills/README.md) for example prompts, supported workflows, and additional installation locations. -## Contributing - -Follow the [Contribution Guidelines] to setup a development -environment. +## Accessibility -### Linting and Formatting +The components target WCAG 2.1 level AA and follow the ARIA Authoring Practices Guide patterns for their roles. Every component specification runs axe-core audits against both the light DOM and the shadow DOM, and components are verified by hand with a keyboard and screen readers such as NVDA. Because the components render in Shadow DOM, some ARIA relations cannot be expressed with IDREF attributes; the library uses `ElementInternals` and ARIA element reflection instead, and adopts new platform capabilities as browsers ship them. -To scan the project for linting errors, run: +Read [ACCESSIBILITY.md][Accessibility] for the conformance target, the verification process, the platform constraints, and what the host application remains responsible for. -```sh -npm run lint -``` +## Security and supply chain -To automatically fix most linting and formatting errors, run: - -```sh -npm run format -``` +Security fixes are released for the latest major version, and critical fixes are backported to the previous major. Report vulnerabilities privately through [GitHub private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new), never in a public issue. -Linting and formatting are also set to run in a pre-commit hook in the project. +Every release ships with supply-chain evidence attached to the [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases): the published tarball with its digests, a CycloneDX SBOM, and signed provenance and SBOM attestations that you can check with `gh attestation verify`. CI runs CodeQL and the OpenSSF Scorecard, and Dependabot keeps dependencies and actions patched. -### Testing with Web Test Runner +Read [SECURITY.md][Security] for the support policy, the reporting process, response targets, verification steps, and security considerations for consumers. -To run the suite of Web Test Runner tests, run: +## Privacy -```sh -npm run test -``` +The library collects no data. The components send no telemetry, set no cookies, write nothing to web storage, and load no remote code. The few browser capabilities they use, such as fetching an icon URL the host application registers or writing to the clipboard when the user clicks a copy control, are listed in [PRIVACY.md][Privacy]. -To run the tests in watch mode, run: +## Contributing -```sh -npm run test:watch -``` +Contributions are welcome. [CONTRIBUTING.md][Contribution Guidelines] covers setting up a development environment, the linting, testing and Storybook commands, and the accessibility, dependency and security requirements for a change. All contributors are expected to follow the [Code of Conduct][Code of Conduct]. -### Demoing with Storybook +## Support -To start a local instance of Storybook for your component, run: +See [SUPPORT.md][Support] for where to report bugs, ask questions, request components, report security or accessibility problems, and reach Infragistics support for the commercial products. -```sh -npm run storybook -``` +## License -To build a production version of Storybook, run: +The `igniteui-webcomponents` package is released under the [MIT License][License]. Third-party runtime dependencies and their license terms are listed in [THIRD-PARTY-NOTICES.md][Third-party notices]. -```sh -npm run storybook:build -``` +The Grids, Dock Manager and other packages marked *Commercial* above are licensed separately under the [Infragistics commercial license][Commercial License]. [Ignite UI for Web Components]: https://www.infragistics.com/products/ignite-ui-web-components [Indigo.Design Design System]: https://www.infragistics.com/products/appbuilder/ui-toolkit @@ -312,3 +319,11 @@ npm run storybook:build [6.3.0]: https://github.com/IgniteUI/igniteui-webcomponents/releases/tag/6.3.0 [7.1.0]: https://github.com/IgniteUI/igniteui-webcomponents/releases/tag/7.1.0 [7.3.0]: https://github.com/IgniteUI/igniteui-webcomponents/releases/tag/7.3.0 +[Changelog]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/CHANGELOG.md +[Accessibility]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/ACCESSIBILITY.md +[Security]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/SECURITY.md +[Privacy]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/PRIVACY.md +[Support]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/.github/SUPPORT.md +[Code of Conduct]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/CODE_OF_CONDUCT.md +[License]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/LICENSE +[Third-party notices]: https://github.com/IgniteUI/igniteui-webcomponents/blob/master/THIRD-PARTY-NOTICES.md From 8ec84b5ec754f0c8497fa1e51c04bcbc667eeab9 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 13:49:12 +0300 Subject: [PATCH 06/12] ci: rely on CodeQL default setup instead of an advanced workflow GitHub rejects SARIF from a workflow-based CodeQL configuration while default setup is enabled for the repository, and default setup already scans javascript-typescript on every push and pull request. Remove the workflow and its README badge, and describe the default setup in the README and SECURITY.md. --- .github/workflows/codeql.yml | 57 ------------------------------------ README.md | 3 +- SECURITY.md | 2 +- 3 files changed, 2 insertions(+), 60 deletions(-) delete mode 100644 .github/workflows/codeql.yml diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml deleted file mode 100644 index 219edeb9f..000000000 --- a/.github/workflows/codeql.yml +++ /dev/null @@ -1,57 +0,0 @@ -# Static analysis of the TypeScript sources with CodeQL. Results appear under -# Security > Code scanning. Runs on every change to master and weekly, so that -# newly published queries also cover code that did not change. -name: CodeQL - -permissions: - contents: read - -on: - push: - branches: [master] - pull_request: - branches: [master] - schedule: - # Mondays at 06:17 UTC. - - cron: '17 6 * * 1' - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: ${{ github.event_name == 'pull_request' }} - -jobs: - analyze: - name: Analyze - runs-on: ubuntu-latest - timeout-minutes: 30 - permissions: - security-events: write - contents: read - actions: read - - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 - with: - languages: javascript-typescript - # TypeScript needs no build for CodeQL to extract it. - build-mode: none - # Compiled output, coverage and Storybook builds are derived from the - # sources and would only duplicate findings. - config: | - paths-ignore: - - dist - - coverage - - storybook-static - - '**/*.spec.ts' - - '**/*.stories.ts' - - - name: Analyze - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 - with: - category: '/language:javascript-typescript' diff --git a/README.md b/README.md index f74e6b624..d713b53e9 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,6 @@ [![Node.js CI](https://github.com/IgniteUI/igniteui-webcomponents/workflows/Node.js%20CI/badge.svg)](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/node.js.yml) -[![CodeQL](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/codeql.yml/badge.svg)](https://github.com/IgniteUI/igniteui-webcomponents/actions/workflows/codeql.yml) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/IgniteUI/igniteui-webcomponents/badge)](https://scorecard.dev/viewer/?uri=github.com/IgniteUI/igniteui-webcomponents) [![Coverage Status](https://coveralls.io/repos/github/IgniteUI/igniteui-webcomponents/badge.svg)](https://coveralls.io/github/IgniteUI/igniteui-webcomponents) [![npm version](https://badge.fury.io/js/igniteui-webcomponents.svg)](https://badge.fury.io/js/igniteui-webcomponents) @@ -210,7 +209,7 @@ Read [ACCESSIBILITY.md][Accessibility] for the conformance target, the verificat Security fixes are released for the latest major version, and critical fixes are backported to the previous major. Report vulnerabilities privately through [GitHub private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new), never in a public issue. -Every release ships with supply-chain evidence attached to the [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases): the published tarball with its digests, a CycloneDX SBOM, and signed provenance and SBOM attestations that you can check with `gh attestation verify`. CI runs CodeQL and the OpenSSF Scorecard, and Dependabot keeps dependencies and actions patched. +Every release ships with supply-chain evidence attached to the [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases): the published tarball with its digests, a CycloneDX SBOM, and signed provenance and SBOM attestations that you can check with `gh attestation verify`. GitHub's CodeQL default setup scans every push and pull request, the OpenSSF Scorecard runs weekly, and Dependabot keeps dependencies and actions patched. Read [SECURITY.md][Security] for the support policy, the reporting process, response targets, verification steps, and security considerations for consumers. diff --git a/SECURITY.md b/SECURITY.md index 7e1461db4..6f1e0f57d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -83,4 +83,4 @@ The components render inside the host page and inherit its origin, so the host a ## Dependencies -Runtime dependencies are kept to a minimum and are listed in [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md). Dependabot raises security updates for npm dependencies daily and version updates for GitHub Actions weekly. CI runs CodeQL analysis and the OpenSSF Scorecard; results are visible in the repository's Security tab. The release workflow pins every action to a commit SHA and grants each job only the permissions it needs. +Runtime dependencies are kept to a minimum and are listed in [THIRD-PARTY-NOTICES.md](THIRD-PARTY-NOTICES.md). Dependabot raises security updates for npm dependencies daily and version updates for GitHub Actions weekly. GitHub's CodeQL default setup analyzes every push and pull request, and the OpenSSF Scorecard runs weekly; results are visible in the repository's Security tab. The release workflow pins every action to a commit SHA and grants each job only the permissions it needs. From 39055ae3b30fe6308bcb45831a839661e1dce6e5 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Wed, 16 Sep 2026 14:02:13 +0300 Subject: [PATCH 07/12] doc(policies): address review feedback on accuracy and notices coverage Correct claims that did not match the source: only some specifications audit both the light and the shadow DOM, the reduced-motion query is "(prefers-reduced-motion: reduce)", a QR logo loads when logo-src is set and again on export, and the icon registry opens a same-origin BroadcastChannel automatically. Qualify the "no third party" and "nowhere else" statements in PRIVACY.md to the documented host-supplied URL fetches, and note the same-root aria-describedby exception in ACCESSIBILITY.md. Make the notices generator label peers from peerDependenciesMeta instead of assuming every peer is optional, and fail when a package declares a license but ships no license file unless a reviewed copy exists under scripts/license-overrides. Add the MIT text for marked-shiki from its source repository and record the shipped notices file in the changelog. --- .github/CONTRIBUTING.md | 4 +- ACCESSIBILITY.md | 4 +- CHANGELOG.md | 4 ++ PRIVACY.md | 21 ++++---- README.md | 2 +- SECURITY.md | 2 +- THIRD-PARTY-NOTICES.md | 28 ++++++++++- scripts/build-notices.mjs | 70 ++++++++++++++++++-------- scripts/license-overrides/marked-shiki | 21 ++++++++ 9 files changed, 118 insertions(+), 38 deletions(-) create mode 100644 scripts/license-overrides/marked-shiki diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index e3db24bdc..1ed81c82b 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -97,7 +97,7 @@ npm run storybook:build Accessibility is a requirement, not a feature. See [ACCESSIBILITY.md](../ACCESSIBILITY.md) for the conformance target and the platform constraints that shape how the components expose semantics. -- Every component specification must audit the component with axe, on both its light DOM and its shadow DOM, in each state the specification exercises: `await expect(el).to.be.accessible()` and `await expect(el).shadowDom.to.be.accessible()`. +- New and changed component specifications must audit the component with axe, on both its light DOM and its shadow DOM, in each state the specification exercises: `await expect(el).to.be.accessible()` and `await expect(el).shadowDom.to.be.accessible()`. - Follow the [ARIA Authoring Practices Guide](https://www.w3.org/WAI/ARIA/apg/) pattern for the component's role, including its keyboard interaction. Add keyboard tests for it. - Publish semantics through `ElementInternals` and ARIA element reflection rather than IDREF attributes, so that relations work across shadow boundaries. Use the controllers under `src/internals/controllers` instead of setting ARIA attributes by hand. - Disable an axe rule only when it misreports semantics published through internals or element reflection, assert the real relation in the specification instead, and document the exception next to the shared options in `src/internals/testing/helpers.spec.ts`. @@ -110,7 +110,7 @@ Runtime dependencies increase the install footprint and the attack surface of ev - **Discuss first.** Open an issue or a discussion before adding a runtime dependency or an optional peer dependency. Prefer a small, focused implementation in `src/internals` over a package that does more than the component needs. - **Licenses.** Runtime and peer dependencies must be licensed under MIT, BSD-2-Clause, BSD-3-Clause, ISC, Apache-2.0, 0BSD or an equivalent permissive license. Copyleft licenses (GPL, LGPL, AGPL, SSPL) are not accepted for anything that ships to consumers. Dual-licensed packages are accepted when one of the options is permissive. - **Manifests.** A runtime dependency is declared in both `package.json` and the published manifest `scripts/_package.json`. Optional peer dependencies are declared with `peerDependenciesMeta.optional: true` in the published manifest. -- **Notices.** After changing a runtime or peer dependency, run `npm run build:notices` and commit the regenerated `THIRD-PARTY-NOTICES.md`. CI fails when the file is out of date. +- **Notices.** After changing a runtime or peer dependency, run `npm run build:notices` and commit the regenerated `THIRD-PARTY-NOTICES.md`. CI fails when the file is out of date. Generation fails for a package that declares a license but ships no license file; copy the text from the package's source repository into `scripts/license-overrides/` (with `/` replaced by `__` for scoped packages) and note where it came from in the pull request. - **Lockfile.** Commit `package-lock.json` changes together with the manifest change. Install with `npm ci`, never `npm install`, so the lockfile stays authoritative. - **Updates.** Dependabot raises security updates for npm packages daily and version updates for GitHub Actions weekly. Routine npm version bumps are done by maintainers in batches. GitHub Actions are pinned to a commit SHA with the version in a trailing comment; keep that format when adding or updating an action. - **Dev dependencies** follow the same license rules and are otherwise at the maintainers' discretion. diff --git a/ACCESSIBILITY.md b/ACCESSIBILITY.md index 7d579b9d1..eacd9e220 100644 --- a/ACCESSIBILITY.md +++ b/ACCESSIBILITY.md @@ -12,7 +12,7 @@ No formal conformance report (VPAT or ACR) is published for this package. ## How accessibility is verified -**Automated audits.** Every component specification runs [axe-core](https://github.com/dequelabs/axe-core) through `chai-a11y-axe` against both the component's light DOM and its shadow DOM, in the states the specification exercises. The audits run with the default axe ruleset, which covers the WCAG 2.0 and 2.1 A and AA success criteria axe can test, the WCAG 2.2 AA rules axe ships, and its best-practice rules. A failing audit fails the test run, so a regression cannot merge. +**Automated audits.** Component specifications run [axe-core](https://github.com/dequelabs/axe-core) through `chai-a11y-axe` against the component's light DOM, its shadow DOM, or both, in the states they exercise. New and changed specifications audit both trees. The audits run with the default axe ruleset, which covers the WCAG 2.0 and 2.1 A and AA success criteria axe can test, the WCAG 2.2 AA rules axe ships, and its best-practice rules. A failing audit fails the test run, so a regression cannot merge. Two things about automated audits are worth knowing: @@ -33,7 +33,7 @@ The components render in Shadow DOM. This gives them style and markup encapsulat Where the platform offers a way around this, the components use it: - **`ElementInternals`.** Components attach internals and publish their role and ARIA state through it, so the host element carries the correct semantics without content attributes that a consumer could clobber. A controller in `src/internals/controllers/internals.ts` keeps that state in sync with component properties. Where a tool needs to see the role as a content attribute, it is mirrored there as well. -- **ARIA element reflection.** Relations are set as element references (`ariaLabelledByElements`, `ariaDescribedByElements`, `ariaControlsElements`, `ariaActiveDescendantElement`) rather than IDREF strings. Element reflection resolves across shadow boundaries into ancestor tree scopes, which lets a composite component point at an element the page or another component owns. The projection controller in `src/internals/controllers/aria-projection.ts` carries those references to the native control inside an input-shaped component, since that is the element assistive technology lands on. +- **ARIA element reflection.** Relations are set as element references (`ariaLabelledByElements`, `ariaDescribedByElements`, `ariaControlsElements`, `ariaActiveDescendantElement`) rather than IDREF strings. Element reflection resolves across shadow boundaries into ancestor tree scopes, which lets a composite component point at an element the page or another component owns. The projection controller in `src/internals/controllers/aria-projection.ts` carries those references to the native control inside an input-shaped component, since that is the element assistive technology lands on. One exception is deliberate: while no description is projected, the description the component renders itself is referenced with a same-root `aria-describedby` IDREF, because it lives in the same shadow root as the control and a content attribute stays visible to tools that read only attributes. - **Delegated focus and roving tabindex** keep a single tab stop per composite and move focus between items inside the shadow root, so keyboard behavior matches the APG pattern regardless of where the items live. Some patterns still cannot be expressed exactly, and in those cases the components use the closest semantics the platform supports. Browser support for cross-root ARIA is improving, and the components are updated to use new capabilities as they ship, so behavior will keep improving without changes on the consumer's side. Reference points for the ongoing platform work are the [Accessibility Object Model](https://wicg.github.io/aom/) and the [cross-root ARIA](https://github.com/WICG/webcomponents/issues/917) proposals. diff --git a/CHANGELOG.md b/CHANGELOG.md index f1de85424..9d854ff94 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,10 @@ The format is based on [Keep a Changelog](http://keepachangelog.com/) and this project adheres to [Semantic Versioning](http://semver.org/). ## [Unreleased] +### Added +- #### Library + - The npm package now ships `THIRD-PARTY-NOTICES.md` with the license texts of its runtime dependencies, generated at build time. [#2383](https://github.com/IgniteUI/igniteui-webcomponents/pull/2383) + ### Fixed - #### Carousel - Indicators now carry their `aria-label` as a content attribute in addition to `ElementInternals`, thus accessibility tools that do not read internals report the tab name. diff --git a/PRIVACY.md b/PRIVACY.md index 9e610430b..ccfb7afe9 100644 --- a/PRIVACY.md +++ b/PRIVACY.md @@ -4,24 +4,25 @@ Ignite UI for Web Components is a library of UI components that runs entirely in ## What the library does not do -- **No telemetry.** The components send no usage data, error reports or analytics anywhere. Nothing in the package contacts Infragistics or any third party at runtime. +- **No telemetry.** The components send no usage data, error reports or analytics anywhere. Nothing in the package contacts Infragistics or any third party on its own. The only network requests are fetches of URLs your application supplies, listed below. - **No cookies or storage.** The components set no cookies and write nothing to `localStorage`, `sessionStorage` or IndexedDB. - **No fingerprinting.** The components do not collect device, browser or network identifiers. - **No remote code.** The package contains no code that loads scripts or styles from a remote origin. ## Browser capabilities the components use -Some components use browser APIs that can involve user data. Each is triggered only by an explicit call from the host application or by a user action inside the component. +Some components use browser APIs that can involve user data. Network and clipboard operations happen only on an explicit call from the host application or a user action inside the component. The remaining capabilities are read or opened automatically while the components render. -| Capability | Where | When | -| ----------------------------- | ------------------------------------ | ---------------------------------------------------------------------------------------------- | -| `fetch` of an application URL | Icon registry (`registerIcon`) | Only for the URL the host application passes when registering an icon. | -| `fetch` of an application URL | QR code export with an embedded image| Only for the image URL the host application passes to the export call. | -| Clipboard write | Color picker, chat message actions | Only when the user activates a copy control. The clipboard is never read. | -| Locale and time zone | Date and time components | Read through `Intl` to format and parse values. Nothing is transmitted. | -| Reduced-motion preference | Animations | Read through `matchMedia('(prefers-reduced-motion)')` to shorten or skip animations. | +| Capability | Where | When | +| ----------------------------- | ---------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `fetch` of an application URL | Icon registry (`registerIcon`) | Only for the URL the host application passes when registering an icon. | +| Image load of an application URL | QR code with a logo (`logo-src`) | Only for the image URL the host application sets. The image loads when `logo-src` is set, to measure it, and is fetched again by `toBlob()` and `toImage()` to inline it in the export. | +| Clipboard write | Color picker, chat message actions | Only when the user activates a copy control. The clipboard is never read. | +| `BroadcastChannel` | Icon registry | Opened automatically on page show as `ignite-ui-icon-channel`. It publishes the icons and icon references the application registers to other browsing contexts of the same origin, so that an Ignite UI for Angular icon service on the same site sees them, and answers their sync requests. It applies nothing it receives. Nothing leaves the origin. | +| Locale and time zone | Date and time components | Read through `Intl` while formatting and parsing values. Nothing is transmitted. | +| Reduced-motion preference | Animations | Read through `matchMedia('(prefers-reduced-motion: reduce)')` to shorten or skip animations. | -Data your application passes into a component, such as chat messages, form values or dates, stays in the page. The components render it and expose it back through their properties and events, and nowhere else. +Data your application passes into a component, such as chat messages, form values or dates, stays in the page. The components render it and expose it back through their properties and events. Apart from the capabilities in the table above, they hand nothing to other origins or browsing contexts. ## Hosted sites diff --git a/README.md b/README.md index d713b53e9..ee3f8a9ad 100644 --- a/README.md +++ b/README.md @@ -201,7 +201,7 @@ See the [AI agent skills guide](skills/README.md) for example prompts, supported ## Accessibility -The components target WCAG 2.1 level AA and follow the ARIA Authoring Practices Guide patterns for their roles. Every component specification runs axe-core audits against both the light DOM and the shadow DOM, and components are verified by hand with a keyboard and screen readers such as NVDA. Because the components render in Shadow DOM, some ARIA relations cannot be expressed with IDREF attributes; the library uses `ElementInternals` and ARIA element reflection instead, and adopts new platform capabilities as browsers ship them. +The components target WCAG 2.1 level AA and follow the ARIA Authoring Practices Guide patterns for their roles. Component specifications run axe-core audits against the light DOM and the shadow DOM, and components are verified by hand with a keyboard and screen readers such as NVDA. Because the components render in Shadow DOM, some ARIA relations cannot be expressed with IDREF attributes; the library uses `ElementInternals` and ARIA element reflection instead, and adopts new platform capabilities as browsers ship them. Read [ACCESSIBILITY.md][Accessibility] for the conformance target, the verification process, the platform constraints, and what the host application remains responsible for. diff --git a/SECURITY.md b/SECURITY.md index 6f1e0f57d..a8a330ffc 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -76,7 +76,7 @@ The components render inside the host page and inherit its origin, so the host a - **Chat markdown rendering.** The optional chat markdown renderer in `igniteui-webcomponents/extras` converts message text to HTML and sanitizes it with [DOMPurify](https://github.com/cure53/DOMPurify) before rendering. The `sanitizer` option replaces DOMPurify; if you supply your own, it must reject scripts, event handlers and dangerous URLs. Without the extras renderer, message text is rendered as text and not as HTML. - **Icons.** `registerIcon(name, url)` fetches the URL you pass and renders the response as inline SVG in the component's shadow root. Only register icons from origins you control or trust, and prefer `registerIconFromText` with SVG you have already vetted. -- **QR code export.** Exporting a QR code with an embedded image fetches the image URL you pass to draw it on a canvas. Only supply URLs you trust. +- **QR code logo.** Setting `logo-src` loads the image URL you pass in order to measure it, and `toBlob()` and `toImage()` fetch it again to inline it in the export. Only supply URLs you trust. - **Clipboard.** The color picker and chat components write to the clipboard when the user activates a copy control. Nothing is read from the clipboard. - **No network or storage otherwise.** The components make no network requests of their own, set no cookies and write nothing to web storage. See [PRIVACY.md](PRIVACY.md). - **Content Security Policy.** The library uses no `eval` or string-to-code APIs. Styles are attached through constructable stylesheets in each component's shadow root. Test your CSP against the components you use before relying on a strict policy. diff --git a/THIRD-PARTY-NOTICES.md b/THIRD-PARTY-NOTICES.md index 752a4bfe9..0089bfe52 100644 --- a/THIRD-PARTY-NOTICES.md +++ b/THIRD-PARTY-NOTICES.md @@ -5,7 +5,7 @@ third-party packages the published `igniteui-webcomponents` package depends on a with their license terms, so that anyone redistributing an application built with this library can meet the attribution requirements of those licenses. -Only direct runtime dependencies and optional peer dependencies are listed. They are not bundled +Only direct runtime dependencies and peer dependencies are listed. They are not bundled into this package; a consuming application resolves them from npm. The full transitive dependency closure, with license identifiers for every package, is recorded in the CycloneDX SBOM attached to each [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases). @@ -833,7 +833,31 @@ This software is provided by the copyright holders and contributors “as is” - License: MIT - Source: -The package ships no license file. Its manifest declares `MIT`; refer to the source repository for the license text. +The package ships no license file. Its manifest declares `MIT`; the text below is reproduced from the source repository. + +```text +The MIT License (MIT) + +Copyright (c) 2023-2024 Stilearning (https://stilearning.com) + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. +``` ### shiki diff --git a/scripts/build-notices.mjs b/scripts/build-notices.mjs index 6219bd778..85d1b1a0c 100644 --- a/scripts/build-notices.mjs +++ b/scripts/build-notices.mjs @@ -13,6 +13,13 @@ const scriptDir = path.dirname(fileURLToPath(import.meta.url)); const repoRoot = path.resolve(scriptDir, '..'); const nodeModules = path.join(repoRoot, 'node_modules'); +/** + * Reviewed license texts for packages that declare a license but ship no + * license file. One file per package, named after the package with `/` + * replaced by `__`, copied verbatim from the package's source repository. + */ +const overridesDir = path.join(scriptDir, 'license-overrides'); + /** * @param {string} file - Path to a JSON file. * @returns {any} Parsed content. @@ -79,35 +86,54 @@ function licenseExpression(manifest) { /** * Every license-like file shipped at the package root, in a stable order. + * Falls back to the reviewed override when the package ships none. * @param {string} name - Package name. - * @returns {{ name: string, text: string }[]} License files and their content. + * @returns {{ name: string, text: string, override: boolean }[]} License texts. */ function licenseFiles(name) { const dir = path.join(nodeModules, name); - - return fs + const files = fs .readdirSync(dir) .filter((entry) => LICENSE_FILE_PATTERN.test(entry)) .sort() .map((entry) => ({ name: entry, text: fs.readFileSync(path.join(dir, entry), 'utf8').trim(), + override: false, })); + + if (files.length > 0) { + return files; + } + + const override = path.join(overridesDir, name.replaceAll('/', '__')); + + if (!fs.existsSync(override)) { + throw new Error( + `${name} ships no license file and no reviewed copy exists at ${path.relative(repoRoot, override)}. ` + + 'Copy the license text from the package repository into that file.' + ); + } + + log(CATEGORY, `${name} ships no license file; using the reviewed copy`); + + return [ + { + name: 'LICENSE', + text: fs.readFileSync(override, 'utf8').trim(), + override: true, + }, + ]; } /** * @param {string} name - Package name. * @param {string} range - Declared version range. - * @param {'dependency' | 'optional peer dependency'} kind - Relationship. + * @param {'dependency' | 'peer dependency' | 'optional peer dependency'} kind - Relationship. * @returns {object} Notice entry. */ function collect(name, range, kind) { const manifest = readInstalledManifest(name); - const files = licenseFiles(name); - - if (files.length === 0) { - log(CATEGORY, `${name} ships no license file; recording its SPDX id only`); - } return { name, @@ -115,7 +141,7 @@ function collect(name, range, kind) { kind, license: licenseExpression(manifest), url: sourceUrl(manifest), - files, + files: licenseFiles(name), }; } @@ -132,7 +158,7 @@ function render(entries) { 'with their license terms, so that anyone redistributing an application built with this library can', 'meet the attribution requirements of those licenses.', '', - 'Only direct runtime dependencies and optional peer dependencies are listed. They are not bundled', + 'Only direct runtime dependencies and peer dependencies are listed. They are not bundled', 'into this package; a consuming application resolves them from npm. The full transitive dependency', 'closure, with license identifiers for every package, is recorded in the CycloneDX SBOM attached to', 'each [GitHub release](https://github.com/IgniteUI/igniteui-webcomponents/releases).', @@ -161,15 +187,13 @@ function render(entries) { } lines.push(''); - if (entry.files.length === 0) { - lines.push( - `The package ships no license file. Its manifest declares \`${entry.license}\`; refer to the source repository for the license text.`, - '' - ); - continue; - } - for (const file of entry.files) { + if (file.override) { + lines.push( + `The package ships no license file. Its manifest declares \`${entry.license}\`; the text below is reproduced from the source repository.`, + '' + ); + } if (entry.files.length > 1) { lines.push(`#### ${file.name}`, ''); } @@ -191,7 +215,13 @@ try { collect(name, range, 'dependency') ), ...Object.entries(manifest.peerDependencies ?? {}).map(([name, range]) => - collect(name, range, 'optional peer dependency') + collect( + name, + range, + manifest.peerDependenciesMeta?.[name]?.optional + ? 'optional peer dependency' + : 'peer dependency' + ) ), ].sort((left, right) => left.name.localeCompare(right.name)); diff --git a/scripts/license-overrides/marked-shiki b/scripts/license-overrides/marked-shiki new file mode 100644 index 000000000..c356142af --- /dev/null +++ b/scripts/license-overrides/marked-shiki @@ -0,0 +1,21 @@ +The MIT License (MIT) + +Copyright (c) 2023-2024 Stilearning (https://stilearning.com) + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in +all copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN +THE SOFTWARE. From c9b59c74bdf8220bb44444582028abfa711749fb Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Thu, 24 Sep 2026 16:41:43 +0300 Subject: [PATCH 08/12] doc(policies): apply maintainer review on contributing and support docs Drop the security contact link from the issue chooser, since GitHub adds it by default. Word the contribution licensing line after GitHub Terms of Service D.6, including the right to license the contribution, and remove the SUPPORT.md pointer from CONTRIBUTING.md. Replace the defensive PR checklist items with one item that confirms the contributing guidelines were read. Put the documentation first in SUPPORT.md, merge the bug and accessibility rows, and move the README component table back above the quick start. --- .github/CONTRIBUTING.md | 4 +- .github/ISSUE_TEMPLATE/config.yml | 3 -- .github/SUPPORT.md | 5 +- .github/pull_request_template.md | 4 +- README.md | 78 +++++++++++++++---------------- 5 files changed, 43 insertions(+), 51 deletions(-) diff --git a/.github/CONTRIBUTING.md b/.github/CONTRIBUTING.md index 4cfa08104..6ca7a2d60 100644 --- a/.github/CONTRIBUTING.md +++ b/.github/CONTRIBUTING.md @@ -14,7 +14,7 @@ For detailed information on issue and pull request statuses, process for testing - **Clone your Fork**: Clone your forked repository to your local machine using Git. This will create a local copy of the project you can work on. - **Create a Branch**: Create a new branch for your specific contribution. This helps keep your changes isolated and organized. -No contributor license agreement or sign-off is required. By submitting a pull request you agree that your contribution is licensed under the project's [MIT License](../LICENSE). +No contributor license agreement or sign-off is required. As stated in the [GitHub Terms of Service](https://docs.github.com/en/site-policy/github-terms/github-terms-of-service#6-contributions-under-repository-license), your contribution is licensed under the project's [MIT License](../LICENSE), and by submitting it you agree that you have the right to license it under those terms. ## Set up @@ -153,6 +153,4 @@ When you contribute code, keep the following in mind: - **Clear and Descriptive Titles**: Use clear and descriptive titles for your issue reports to help maintainers understand the problem quickly. - **Provide Details**: In your issue report, provide as much detail as possible to help diagnose the problem. This might include steps to reproduce the issue, error messages, and expected behavior. -See [SUPPORT.md](./SUPPORT.md) for where questions, feature requests, security reports and commercial support requests belong. - Thank you! diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml index 7f541a7c1..7173c50eb 100644 --- a/.github/ISSUE_TEMPLATE/config.yml +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -1,8 +1,5 @@ blank_issues_enabled: false contact_links: - - name: 🔒 Report a security vulnerability - url: https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new - about: Report vulnerabilities privately. Never open a public issue for a security problem. - name: 💬 Ask a question url: https://github.com/IgniteUI/igniteui-webcomponents/discussions about: Questions, ideas and general discussion belong in GitHub Discussions. diff --git a/.github/SUPPORT.md b/.github/SUPPORT.md index 280480169..9770e4ea3 100644 --- a/.github/SUPPORT.md +++ b/.github/SUPPORT.md @@ -4,14 +4,13 @@ Where to go depending on what you need: | I want to... | Go to | | ---------------------------------------------- | ------------------------------------------------------------------------------------------------------ | -| Report a bug in a component | [Bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml) | +| Read the documentation | [Product documentation](https://www.infragistics.com/products/ignite-ui-web-components) and [Storybook](https://igniteui.github.io/igniteui-webcomponents) | +| Report a bug or an accessibility problem | [Bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml). For accessibility, see [ACCESSIBILITY.md](../ACCESSIBILITY.md). | | Request a component or feature | [Component request](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=component.md) | | Ask a question or share an idea | [GitHub Discussions](https://github.com/IgniteUI/igniteui-webcomponents/discussions) | | Chat with the community | [Discord](https://discord.gg/39MjrTRqds) | | Report a security vulnerability | [Private vulnerability reporting](https://github.com/IgniteUI/igniteui-webcomponents/security/advisories/new). See [SECURITY.md](../SECURITY.md). Never open a public issue for this. | -| Report an accessibility problem | [Bug report](https://github.com/IgniteUI/igniteui-webcomponents/issues/new?template=bug_report.yaml). See [ACCESSIBILITY.md](../ACCESSIBILITY.md). | | Get help with a commercial Ignite UI product | [Infragistics support](https://www.infragistics.com/about-us/contact-us) | -| Read the documentation | [Product documentation](https://www.infragistics.com/products/ignite-ui-web-components) and [Storybook](https://igniteui.github.io/igniteui-webcomponents) | Before opening an issue, search the existing [issues](https://github.com/IgniteUI/igniteui-webcomponents/issues) and [discussions](https://github.com/IgniteUI/igniteui-webcomponents/discussions). A bug report with a minimal reproduction, for example on StackBlitz, is resolved much faster than one without. diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index 9c91b60df..293c06e7b 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -33,6 +33,4 @@ Closes # - [ ] I have updated documentation if needed - [ ] I have added a `CHANGELOG.md` entry under `[Unreleased]` - [ ] Breaking changes are documented in the description -- [ ] Accessibility: axe audits pass on the light and shadow DOM, and keyboard interaction is covered by tests -- [ ] Dependencies: no new runtime or peer dependency, or its license was reviewed and `THIRD-PARTY-NOTICES.md` was regenerated -- [ ] Security: the change adds no network access, storage, telemetry or unsanitized HTML rendering +- [ ] I have read the [contributing guidelines](https://github.com/IgniteUI/igniteui-webcomponents/blob/master/.github/CONTRIBUTING.md), including the accessibility, dependency and security rules diff --git a/README.md b/README.md index ee3f8a9ad..e73fa3f2a 100644 --- a/README.md +++ b/README.md @@ -17,8 +17,8 @@ ## Table of contents -- [Quick start](#quick-start) - [Components](#components) +- [Quick start](#quick-start) - [Browser support](#browser-support) - [Tooling](#tooling) - [Accessibility](#accessibility) @@ -28,44 +28,6 @@ - [Support](#support) - [License](#license) -## Quick start - -Install the `igniteui-webcomponents` package: - -```sh -npm install igniteui-webcomponents -``` - -Import and register the components you need with the `defineComponents` function: - -```ts -import { - defineComponents, - IgcAvatarComponent, - IgcBadgeComponent, -} from 'igniteui-webcomponents'; - -defineComponents(IgcAvatarComponent, IgcBadgeComponent); -``` - -You can also register every component at once with `defineAllComponents`: - -```ts -import { defineAllComponents } from 'igniteui-webcomponents'; - -defineAllComponents(); -``` - -Registering all components increases the bundle size of your application, so register only the ones you use. - -After the components are registered, use them in your HTML: - -```html - -``` - -See the [documentation][Ignite UI for Web Components] for guides on each component, theming, and framework integration. - ## Components All components in this package are released under the MIT License. The table lists the release in which each component first shipped. @@ -154,6 +116,44 @@ Provide a complete windowing experience, splitting complex layouts into smaller, - License - [Commercial][Commercial License] - Package - [igniteui-dockmanager](https://www.npmjs.com/package/igniteui-dockmanager) +## Quick start + +Install the `igniteui-webcomponents` package: + +```sh +npm install igniteui-webcomponents +``` + +Import and register the components you need with the `defineComponents` function: + +```ts +import { + defineComponents, + IgcAvatarComponent, + IgcBadgeComponent, +} from 'igniteui-webcomponents'; + +defineComponents(IgcAvatarComponent, IgcBadgeComponent); +``` + +You can also register every component at once with `defineAllComponents`: + +```ts +import { defineAllComponents } from 'igniteui-webcomponents'; + +defineAllComponents(); +``` + +Registering all components increases the bundle size of your application, so register only the ones you use. + +After the components are registered, use them in your HTML: + +```html + +``` + +See the [documentation][Ignite UI for Web Components] for guides on each component, theming, and framework integration. + ## Browser support | ![chrome_48x48] | ![firefox_48x48] | ![edge_48x48] | ![opera_48x48] | ![safari_48x48] | From ad369ee6db2422fd77a43fb8c11d3a4f5a8b89f0 Mon Sep 17 00:00:00 2001 From: Radoslav Karaivanov Date: Thu, 24 Sep 2026 16:57:13 +0300 Subject: [PATCH 09/12] doc(a11y): document the form control naming order and label support Describe the naming order that every form associated component uses, the element references that carry the name to the native control, and label click activation for the checkbox, switch, radio, rating, slider and file input. Note that the own label, like the own description, binds as a same-root IDREF, that the host also mirrors aria-label, and that axe misses ElementInternals ARIA but reads element reflection. State the Chromium wrapping-label limitation and recommend