Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ concurrency:

jobs:
test:
name: Test on Windows 11 x64
name: Full verification on Windows 11 x64
runs-on: windows-latest
timeout-minutes: 30
env:
Expand Down Expand Up @@ -40,13 +40,22 @@ jobs:
- name: Install frontend dependencies
run: npm ci

- name: Install pinned cargo-about
run: cargo install cargo-about --locked --version 0.9.1 --features cli

- name: Verify license policy and generated artifacts
run: npm run licenses:check

- name: Verify synchronized versions
shell: pwsh
run: .\scripts\verify-version.ps1

- name: Check Rust formatting
run: cargo fmt --manifest-path src-tauri/Cargo.toml --all -- --check

- name: Verify design tokens
run: npm run check:design

- name: Test frontend
run: npm test

Expand All @@ -55,3 +64,6 @@ jobs:

- name: Test Rust
run: cargo test --locked --manifest-path src-tauri/Cargo.toml

- name: Lint Rust
run: cargo clippy --locked --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
82 changes: 82 additions & 0 deletions .github/workflows/compliance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
name: Dependency compliance

on:
workflow_dispatch:
pull_request:
paths:
- ".npmrc"
- "package.json"
- "package-lock.json"
- "src-tauri/Cargo.toml"
- "src-tauri/Cargo.lock"
- "src-tauri/about.toml"
- "scripts/generate-license-report.mjs"
- "scripts/licenses/**"
- "THIRD_PARTY_LICENSES.md"
- "THIRD_PARTY_NOTICES.txt"
- "THIRD_PARTY_SOURCES.md"
- "bom.cyclonedx.json"
- ".github/workflows/compliance.yml"
push:
branches:
- main
paths:
- ".npmrc"
- "package.json"
- "package-lock.json"
- "src-tauri/Cargo.toml"
- "src-tauri/Cargo.lock"
- "src-tauri/about.toml"
- "scripts/generate-license-report.mjs"
- "scripts/licenses/**"
- "THIRD_PARTY_LICENSES.md"
- "THIRD_PARTY_NOTICES.txt"
- "THIRD_PARTY_SOURCES.md"
- "bom.cyclonedx.json"
- ".github/workflows/compliance.yml"

permissions:
contents: read

concurrency:
group: compliance-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
licenses:
name: Verify locked dependency licenses
runs-on: windows-latest
timeout-minutes: 20

steps:
- name: Check out source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
cache: npm

- name: Use pinned npm
shell: pwsh
run: |
$packageManager = node -p "require('./package.json').packageManager"
npm install --global $packageManager

- name: Install frontend dependencies
run: npm ci

- name: Restore pinned cargo-about
id: cargo-about-cache
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5.0.3
with:
path: ~/.cargo/bin/cargo-about.exe
key: cargo-about-0.9.1-windows-x64

- name: Install pinned cargo-about
if: steps.cargo-about-cache.outputs.cache-hit != 'true'
run: cargo install cargo-about --locked --version 0.9.1 --features cli

- name: Verify license policy and generated artifacts
run: npm run licenses:check
70 changes: 70 additions & 0 deletions .github/workflows/frontend.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
name: Frontend checks

on:
workflow_dispatch:
pull_request:
paths:
- "src/**"
- "assets/**"
- "index.html"
- "package.json"
- "package-lock.json"
- ".npmrc"
- "tsconfig*.json"
- "vite.config.*"
- "scripts/check-design-tokens.mjs"
- ".github/workflows/frontend.yml"
push:
branches:
- main
paths:
- "src/**"
- "assets/**"
- "index.html"
- "package.json"
- "package-lock.json"
- ".npmrc"
- "tsconfig*.json"
- "vite.config.*"
- "scripts/check-design-tokens.mjs"
- ".github/workflows/frontend.yml"

permissions:
contents: read

concurrency:
group: frontend-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
frontend:
name: Test and build web UI
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- name: Check out source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version-file: .nvmrc
cache: npm

- name: Use pinned npm
run: |
package_manager="$(node -p "require('./package.json').packageManager")"
npm install --global "$package_manager"

- name: Install frontend dependencies
run: npm ci

- name: Verify design tokens
run: npm run check:design

- name: Test frontend
run: npm test

- name: Build frontend
run: npm run build:web
53 changes: 53 additions & 0 deletions .github/workflows/native.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
name: Native checks

on:
workflow_dispatch:
pull_request:
paths:
- "src-tauri/**"
- "rust-toolchain.toml"
- "scripts/verify-version.ps1"
- ".github/workflows/native.yml"
push:
branches:
- main
paths:
- "src-tauri/**"
- "rust-toolchain.toml"
- "scripts/verify-version.ps1"
- ".github/workflows/native.yml"

permissions:
contents: read

concurrency:
group: native-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
native:
name: Test and lint Rust backend
runs-on: windows-latest
timeout-minutes: 30
env:
CMAKE_POLICY_VERSION_MINIMUM: "3.5"

steps:
- name: Check out source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Install required Rust components
run: rustup component add rustfmt clippy

- name: Verify synchronized versions
shell: pwsh
run: .\scripts\verify-version.ps1

- name: Check Rust formatting
run: cargo fmt --manifest-path src-tauri/Cargo.toml --all -- --check

- name: Test Rust
run: cargo test --locked --manifest-path src-tauri/Cargo.toml

- name: Lint Rust
run: cargo clippy --locked --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
7 changes: 5 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,9 @@ jobs:
- name: Install frontend dependencies
run: npm ci

- name: Install pinned cargo-about
run: cargo install cargo-about --locked --version 0.9.1 --features cli

- name: Verify tag and application versions
id: version
shell: pwsh
Expand All @@ -58,8 +61,8 @@ jobs:
- name: Test Rust
run: cargo test --locked --manifest-path src-tauri/Cargo.toml

- name: Generate third-party license report
run: node .\scripts\generate-license-report.mjs
- name: Verify third-party license policy and reports
run: npm run licenses:check

- name: Build NSIS installer and executable
run: npm run build
Expand Down
2 changes: 2 additions & 0 deletions .npmrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
registry=https://registry.npmjs.org/
replace-registry-host=always
20 changes: 20 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ and this project follows [Semantic Versioning](https://semver.org/spec/v2.0.0.ht

### Added

- Added a bilingual contribution guide covering privacy-safe fixtures,
architecture boundaries, focused pull requests, and proportionate checks.
- Added generated third-party notices, a CycloneDX SBOM, an MPL dependency
source archive, and license files in both Windows distribution formats.

- Added privacy-safe local diagnostic event logs for recording, audio recovery,
imports, ASR, and LLM generation, with typed metadata, correlation IDs, UTC
timestamps, bounded rotation, and no automatic upload.
Expand All @@ -21,12 +26,27 @@ and this project follows [Semantic Versioning](https://semver.org/spec/v2.0.0.ht

### Changed

- Split contribution CI into path-scoped frontend, native, and dependency
compliance checks, while keeping executable and installer builds exclusive
to tagged releases.
- Made generated dependency inventories and SBOM component ordering independent
of the host locale and installed-package repository metadata for reproducible
local and CI verification.
- Standardized locked frontend dependency downloads and CI installs on the
official npm registry for reproducible public builds.
- Added locked dependency license policy gates for Rust, production npm, and
the vendored libopus snapshot; release packaging now fails on stale or
missing compliance artifacts.

- Licensed Nota under the MIT License with copyright held by `kwp-lab`.
- Replaced speculative meeting-ended detection with a capture-health reminder
shown only when selected-application audio capture cannot be rebuilt for 15
continuous seconds; successful recovery dismisses it automatically.

### Fixed

- Updated the Vite build chain's transitive PostCSS and nanoid dependencies to
patched releases, clearing the known npm security advisories.
- Prevented screen sharing, window/PID changes, minimization, and silence from
being interpreted as evidence that a meeting ended; prolonged silence is
reported only as an observable audio condition.
Expand Down
Loading