Skip to content

license: remove GPL-family build tooling path #531

Description

@seonghobae

Problem

Noema commercial dependency baseline does not accept GPL/LGPL/AGPL-family tooling paths as ordinary inbound dependencies. The historical protected lockfile path wrangler → miniflare → sharp → @img/sharp-libvips-* carried LGPL-family metadata. Apache-2.0 source licensing does not relicense or waive third-party tooling obligations.

Current protected authority — 2026-09-10 KST

Fresh protected source is GitHub-verified main@b946d04236613544ceedb2160ed68b4e6d855dd8 after normal #582 integration. Source remediation from merged #540 remains protected history; it is not an active candidate and must not be reimplemented.

Current protected executable contract test/cloudflare-toolchain-license-boundary.test.ts still requires Wrangler, Miniflare, Sharp and @img/sharp-libvips-* to be absent from the committed dependency graph, pins direct esbuild@0.28.1 and workerd@1.20260625.1, requires deployment through scripts/cloudflare-worker-deploy.mjs, and rejects GPL/LGPL/AGPL-family lockfile metadata. It also verifies local development uses pinned workerd and does not reintroduce Wrangler/Miniflare. This is current source evidence, not immutable release evidence.

The former #540 exact candidate 05bc2d47c3899ebe17538070f9a30172f90307ac reached its unchanged-head CI/reviewer/Security/image evidence before normal integration. Subsequent protected work, including #542 durable runtime, #550 work-conserving workflow concurrency, #566 patch-validator image/runtime repair, #570/#573 lane-ordering repair, and #574–#582 lifecycle/operability work, has not reopened the retired dependency path.

Fresh Noema GitHub Release inventory on 2026-09-10 remains 0 releases. Therefore source remediation is protected, but immutable released-artifact rights/provenance evidence is still absent. Current Draft #583 is documentation-authority repair only and does not own this licensing/publication boundary.

Completion criteria

  • Remove the Wrangler/Miniflare/Sharp/Libvips dependency path from protected source.
  • Pin the direct workerd/esbuild contract and preserve deterministic lock/license evidence.
  • Preserve work-conserving concurrency, durable runtime source and reviewer/package authority during ordinary/non-force convergence.
  • Reach one unchanged fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 exact head with terminal-success CI, reviewer-ci, required Security Scan and patch-validator-image evidence and clean review authority.
  • Normal protected merge completed and the removal remains enforced by a current protected executable contract.
  • Bind the exact then-current protected release candidate to package/SBOM/provenance/reproducibility evidence and an immutable release before distribution/acquisition readiness is claimed.
  • Preserve third-party NOTICE/attribution and obtain explicit outbound-rights/transfer evidence for the actual released artifact; automation does not choose that legal authority.

Keep this issue open only for the release/publication/legal evidence class above. Source remediation itself is protected and must not be recreated in a successor lane.

Guardrails

Do not hide dependency/license metadata, mutate lock digests for apparent compliance, reuse PR-head checks as release evidence, choose outbound licensing authority by automation, weaken required gates, or recreate the retired tooling path. Publication/release evidence remains distinct from source integration and is coordinated with #36/#5/#66.

Related: #5, #27, #30, #36, #66, #558, #583.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingpriority: highHigh-priority or P1 worktype: bugDefect or incorrect behavior

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions