Replies: 5 comments
Technical Provenance Analysis:
|
|
@lgagamel The analysis from @somuai is spot on. Using Combined with |
|
Native SWC Packages (@next/swc-linux-x64-gnu & @next/swc-linux-x64-musl @ 16.3.6) Supported Procedure to Derive It: Check out commit a758ffc in the vercel/next.js repository. Navigate to the binding crate directory at crates/napi. Filter out dev/build-only workspace dependencies and isolate the actual runtime component tree for your target platform: Bash Marker Packages (server-only & client-only @ 0.0.1) License & Provenance: The authoritative copyright notice and full MIT license text reside in the root LICENSE file of the facebook/react repository. Because these 0.0.1 packages serve purely as lightweight import guards exported during the React build pipeline, the standalone license file was omitted from the published npm tarballs themselves, but provenance points back to Meta's React repository. |
|
I checked the release inputs against the Match the build features first. The In particular, git clone --depth 1 --branch v16.3.6 --filter=blob:none --sparse https://github.com/vercel/next.js
cd next.js
git sparse-checkout set --no-cone /Cargo.toml /Cargo.lock /.cargo/ /rust-toolchain.toml \
/crates/ /turbopack/crates/ /turbopack/xtask/ /scripts/send-trace-to-jaeger/
RUSTUP_TOOLCHAIN=stable RUSTFLAGS='--cfg=tokio_unstable' \
cargo tree -p next-napi-bindings --locked \
--target x86_64-unknown-linux-gnu -e normal \
--features image-extended,tracing/release_max_level_trace \
--prefix none --format '{p} {l}' \
| sed 's/ (\*)$//' | sort -uThe pinned Crate license metadata alone does not cover all bundled native code. The pinned For |
|
Hi @lgagamel, Here is the exact provenance breakdown and derivation procedure for both questions: 1. Native SWC Packages (
|
Uh oh!
There was an error while loading. Please reload this page.
Summary
I am collecting source and third-party notice evidence for the unmodified npm packages
@next/swc-linux-x64-gnuand@next/swc-linux-x64-muslat 16.3.6, plusserver-onlyandclient-onlyat 0.0.1.For SWC, the registry provenance subjects match the exact package integrity values and report Next.js commit
a758ffcf501f6f1ddb03175bd1033508424c261e. I have the pinned root license, native binding manifest, Cargo.lock and release workflow. The workspace lockfile contains target/build/dev dependencies, so I have not assumed it is the component list for either distributed native binary. Is there a release-specific native component/third-party notice manifest, or an authoritative supported procedure for deriving it from the release build?For the two 0.0.1 marker packages, npm metadata declares MIT but the published packages omit the license text and a source revision. The current documentation and RFC explain their behavior, but I have not found the original source/copyright notice for these exact versions. Can you point to that source or the appropriate package maintainer? This asks for provenance evidence, not a legal opinion or a change to the packages.
Additional information
No response
Example
No response
All reactions