Problem
Noema commercial dependency baseline does not accept GPL/LGPL/AGPL-family tooling paths as ordinary inbound dependencies. The historical protected lockfile path wrangler → miniflare → sharp → @img/sharp-libvips-* carried LGPL-family metadata. Apache-2.0 source licensing does not relicense or waive third-party tooling obligations.
Current protected authority — 2026-09-10 KST
Fresh protected source is GitHub-verified main@b946d04236613544ceedb2160ed68b4e6d855dd8 after normal #582 integration. Source remediation from merged #540 remains protected history; it is not an active candidate and must not be reimplemented.
Current protected executable contract test/cloudflare-toolchain-license-boundary.test.ts still requires Wrangler, Miniflare, Sharp and @img/sharp-libvips-* to be absent from the committed dependency graph, pins direct esbuild@0.28.1 and workerd@1.20260625.1, requires deployment through scripts/cloudflare-worker-deploy.mjs, and rejects GPL/LGPL/AGPL-family lockfile metadata. It also verifies local development uses pinned workerd and does not reintroduce Wrangler/Miniflare. This is current source evidence, not immutable release evidence.
The former #540 exact candidate 05bc2d47c3899ebe17538070f9a30172f90307ac reached its unchanged-head CI/reviewer/Security/image evidence before normal integration. Subsequent protected work, including #542 durable runtime, #550 work-conserving workflow concurrency, #566 patch-validator image/runtime repair, #570/#573 lane-ordering repair, and #574–#582 lifecycle/operability work, has not reopened the retired dependency path.
Fresh Noema GitHub Release inventory on 2026-09-10 remains 0 releases. Therefore source remediation is protected, but immutable released-artifact rights/provenance evidence is still absent. Current Draft #583 is documentation-authority repair only and does not own this licensing/publication boundary.
Completion criteria
Keep this issue open only for the release/publication/legal evidence class above. Source remediation itself is protected and must not be recreated in a successor lane.
Guardrails
Do not hide dependency/license metadata, mutate lock digests for apparent compliance, reuse PR-head checks as release evidence, choose outbound licensing authority by automation, weaken required gates, or recreate the retired tooling path. Publication/release evidence remains distinct from source integration and is coordinated with #36/#5/#66.
Related: #5, #27, #30, #36, #66, #558, #583.
Problem
Noema commercial dependency baseline does not accept GPL/LGPL/AGPL-family tooling paths as ordinary inbound dependencies. The historical protected lockfile path
wrangler → miniflare → sharp → @img/sharp-libvips-*carried LGPL-family metadata. Apache-2.0 source licensing does not relicense or waive third-party tooling obligations.Current protected authority — 2026-09-10 KST
Fresh protected source is GitHub-verified
main@b946d04236613544ceedb2160ed68b4e6d855dd8after normal #582 integration. Source remediation from merged #540 remains protected history; it is not an active candidate and must not be reimplemented.Current protected executable contract
test/cloudflare-toolchain-license-boundary.test.tsstill requires Wrangler, Miniflare, Sharp and@img/sharp-libvips-*to be absent from the committed dependency graph, pins directesbuild@0.28.1andworkerd@1.20260625.1, requires deployment throughscripts/cloudflare-worker-deploy.mjs, and rejects GPL/LGPL/AGPL-family lockfile metadata. It also verifies local development uses pinned workerd and does not reintroduce Wrangler/Miniflare. This is current source evidence, not immutable release evidence.The former #540 exact candidate
05bc2d47c3899ebe17538070f9a30172f90307acreached its unchanged-head CI/reviewer/Security/image evidence before normal integration. Subsequent protected work, including #542 durable runtime, #550 work-conserving workflow concurrency, #566 patch-validator image/runtime repair, #570/#573 lane-ordering repair, and #574–#582 lifecycle/operability work, has not reopened the retired dependency path.Fresh Noema GitHub Release inventory on 2026-09-10 remains 0 releases. Therefore source remediation is protected, but immutable released-artifact rights/provenance evidence is still absent. Current Draft #583 is documentation-authority repair only and does not own this licensing/publication boundary.
Completion criteria
Keep this issue open only for the release/publication/legal evidence class above. Source remediation itself is protected and must not be recreated in a successor lane.
Guardrails
Do not hide dependency/license metadata, mutate lock digests for apparent compliance, reuse PR-head checks as release evidence, choose outbound licensing authority by automation, weaken required gates, or recreate the retired tooling path. Publication/release evidence remains distinct from source integration and is coordinated with #36/#5/#66.
Related: #5, #27, #30, #36, #66, #558, #583.