Skip to content

release(compliance): ship third-party notices and SBOM with the next desktop release #871

Description

@qnbs

CURRENT AUTHORITATIVE STATE — v1.29.1 release evidence — 2026-09-29

This block supersedes older “exact v1.29 candidate/tag” wording below where it refers to the release that will actually publish.

v1.29.0 was tagged but never published as a GitHub/Desktop release. Therefore this issue remains open for fresh exact-v1.29.1 candidate/tag evidence.

Required closure evidence:

  • exact v1.29.1 three-target build;
  • regenerated notices + CycloneDX SBOM bound to the exact candidate SHA;
  • exact-artifact collection/count dry run;
  • after tag/publication, verification of the actual GitHub Release notice/SBOM assets against exact tag/SHA/version identity.

v1.29.0 pre-tag evidence remains historical precedent and must not be used to close this issue.


Exact-candidate release contract — 2026-09-29

Implementation is complete on main. This issue remains open only for release evidence tied to the exact v1.29 candidate/tag.

Before tag, #872 must prove on the frozen candidate:

  • the three admitted tauri-build.yml dispatch targets succeed;
  • each target generates a non-empty third-party notice artifact and CycloneDX SBOM;
  • artifact/version/SHA identity is recorded;
  • release collection/count logic is dry-run against those dispatch artifacts with the expected 3 notices + 3 SBOMs;
  • candidate CHANGELOG release-note extraction is dry-run validated.

The dispatch build is build-equivalent, not publication-equivalent. Mark these as TAG_ONLY_PENDING until an explicitly authorized tag exists:

  • updater .sig files;
  • latest.json;
  • actual GitHub Release attachment/publication.

Close #871 only after the published v1.29 assets are verified against the exact tag/SHA. Do not reopen #881 implementation unless candidate qualification exposes a real defect.

#906 is a separate post-release functional packaged-state harness owner and does not change this compliance contract.


Current implementation status — 2026-09-29 09:41 CEST

Implementation PR #881 is merged.

Final PR head c2de4eaa6900c9d70b66d2910724529e53ae2bd2 completed:

  • CI/CD SUCCESS;
  • CodeQL SUCCESS;
  • Reviewer Governance Trust Boundary SUCCESS;
  • Tauri desktop build run 36504123786 SUCCESS across the release matrix.

The substantive proc-macro traversal, installer-less-release, documentation and CodeScene findings were corrected before merge.

Resulting main after #881 was f408cdcccd718eaace7dc52e03577f3d00347118, with CI/CD + CodeQL green and Production READY.

Disposition: implementation complete / release verification pending. Keep this owner open only for exact v1.29 release evidence that the third-party notices and CycloneDX SBOM are actually present/coherent in the published desktop release assets. Candidate/tag execution itself is owned by #872.


Current implementation status — 2026-09-29

Implementation PR #881 is merged.

Terminal implementation evidence:

  • final reviewed PR head: c2de4eaa6900c9d70b66d2910724529e53ae2bd2;
  • fresh exact-head Tauri qualification run 36504123786: SUCCESS across the admitted Linux/Windows/macOS matrix;
  • the final correction wave fixed proc-macro traversal scope, installer-less release publication semantics, documentation ordering and the last CodeScene complexity finding;
  • feat(release): ship third-party notices and CycloneDX SBOM with desktop builds (#871) #881 merged normally to resulting main f408cdcccd718eaace7dc52e03577f3d00347118;
  • resulting-main CI/CD and CodeQL were terminal green;
  • Vercel Production was READY on that exact resulting-main SHA before dependency convergence continued.

The current-Tauri notices/SBOM implementation gate is satisfied for candidate preparation. Keep this issue open until the v1.29.0 tagged release actually publishes and verifies the notice/SBOM release assets; publication/asset exact-SHA proof is owned by #872.

Do not reopen #881 implementation work unless candidate/release qualification exposes a real defect.

Context

#575 owns the broad long-lived distribution-compliance contract. The 2026-09-28 deep audit identified a narrower current-release gap that should not wait for future Qt work:

  • WorldScript already publishes Tauri desktop installers;
  • repository evidence does not currently show a generated bundled third-party notice artifact;
  • release workflows do not currently publish a CycloneDX/SPDX SBOM for the desktop release set;
  • current web provenance does not substitute for native-distribution license/notice inventory.

This issue is the bounded implementation slice for the current Tauri distribution, under #575.

Goal

For the next desktop release, generate, validate, package and publish machine-readable SBOM evidence plus human-readable third-party license/notice material covering what WorldScript actually redistributes.

Required inventory

At minimum reconcile:

  • JS/runtime dependencies materially shipped in the web/native bundle;
  • Rust crates linked into the desktop artifacts;
  • vendored/forked code;
  • fonts/icons/assets requiring attribution;
  • bundled or redistributed WASM/native components;
  • installer/runtime redistributables.

Model/download-only artifacts that are not shipped in the installer must be classified explicitly rather than silently mixed into the binary-distribution inventory.

Preferred implementation direction

Evaluate current maintained tooling rather than hard-coding a bespoke license database. A likely shape is:

  • Rust inventory/notice generation using cargo-about or an equivalently maintained tool;
  • JS license collection from the locked pnpm graph using a deterministic collector;
  • deterministic assembly into a bundled human-readable artifact such as THIRDPARTY.html or THIRD_PARTY_NOTICES.html;
  • CycloneDX or SPDX SBOM generation from the exact release tree/lockfiles;
  • CI validation that required generated artifacts are present and non-empty.

Tool choice must be proven against the repository; this issue does not mandate a specific package if a better maintained solution is available.

Packaging and release requirements

Acceptance criteria

  • clean/fresh release checkout can regenerate identical or semantically equivalent notice/SBOM outputs;
  • current Tauri Linux/Windows/macOS release matrix consumes or publishes the outputs;
  • CI fails clearly if generation fails or a materially shipped dependency has unclassified license metadata;
  • release evidence records exact SHA and produced artifacts;
  • documentation points to compliance(distribution): establish third-party license, Qt LGPL/GPL admission, notices & SBOM policy #575 for the durable policy and records this current-Tauri implementation;
  • no Qt-specific admission work is pulled forward unnecessarily.

Related: #575, #529, #574.

Activity

  1. added a commit that references this issue on Sep 29, 2026
  2. qnbs commented on Sep 29, 2026

    @qnbs
    OwnerAuthor

    Successor-release evidence update — 2026-09-29

    The implementation remains complete; the publication target is now v1.29.1, because v1.29.0 was tagged but never published as a GitHub/Desktop release.

    v1.29.0 terminal outcome:

    • GitHub/Desktop release assets: NOT PRODUCED;
    • updater signatures / latest.json: NOT PRODUCED;
    • Docker/GHCR: PUBLISHED;
    • release state: TAGGED, not PUBLISHED/VERIFIED.

    Therefore prior v1.29.0 pre-tag notices/SBOM evidence is precedent only. #871 stays open for fresh exact-v1.29.1 candidate/tag evidence.

    Required before closure:

    1. three-target exact-candidate build succeeds;
    2. notices are non-empty and byte/coherence checked per target;
    3. CycloneDX SBOMs are regenerated/bound to the exact v1.29.1 candidate SHA;
    4. release collection/count logic is dry-run against those exact artifacts;
    5. after the signed tag, the actual published GitHub Release asset set is verified against exact tag/SHA/version identities.

    Do not close #871 from the v1.29.0 qualification alone. #910/#872 own the successor candidate/release execution; this issue remains the compliance evidence owner.

  3. qnbs commented on Sep 30, 2026

    @qnbs
    OwnerAuthor

    Published evidence: v1.29.1 (2026-09-30) is the first desktop release to ship third-party notices and SBOMs.

    • Release assets: three per-target *.third-party-notices.txt and three CycloneDX *.cdx.json for aarch64-apple-darwin, x86_64-pc-windows-msvc and x86_64-unknown-linux-gnu.
    • Bound to the release: each SBOM is bound to the release commit f255d767 / version 1.29.1 (607/589/665 components).
    • Qualified before the tag: the published digests are identical to the pre-tag qualified artifacts.
    • Inside every installer: THIRD_PARTY_NOTICES.txt is byte-identical in all seven formats (.deb, .rpm, .AppImage, NSIS, .msi, .app, .dmg).
    • Fail-closed: the release job requires exactly 3 notices and 3 SBOMs, and inventories alone cannot publish a release. Both negatives were dry-run.

    Implemented by #881; record on #872. The known scope note stays with #575: the JavaScript inventory is the pnpm production graph, a documented superset of the bundled modules. Closing as completed.

  4. added 2 commits that reference this issue on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions