Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,10 +17,12 @@ The bundled font files are redistributed unmodified. ARSAS does not rename the I

## External intellectual-property boundary

No source code, binary, header, generated binding, wrapper, example, test, API layer, executable, manual, brochure, help file, screenshot, icon, logo, product photo, report template, UI resource, database, capture, or extracted asset from an unrelated external implementation or proprietary engineering product is included or directly required by this application repository.
Project policy prohibits including source code, binary, header, generated binding, wrapper, example, test, API layer, executable, manual, brochure, help file, screenshot, icon, logo, product photo, report template, UI resource, database, capture, or extracted asset copied from an unrelated external implementation or proprietary engineering product.

Interoperability testing with separately licensed tools does not make those tools application dependencies and does not authorize copying their software, documentation, visual design, reports, resources, or confidential data.

Tracked visual and font assets are inventoried in [docs/ASSET_PROVENANCE_REGISTER.md](docs/ASSET_PROVENANCE_REGISTER.md) and its machine-readable manifest. An inventory entry or passing source-clean check is not a certification of authorship, license clearance, or visual independence; unresolved origin/rights review remains explicitly recorded there.

## Assets and releases

All application icons, screenshots, illustrations, UI resources, and marketing images included in a release must be project-owned or separately licensed for that use. Screenshots must be generated from ARSAS itself using synthetic or sanitized data.
Expand Down
6 changes: 4 additions & 2 deletions docs/ASSET_PROVENANCE_REGISTER.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,12 @@ This register supports the [independent implementation and provenance policy](IN

## Audited snapshot

- Repository: `masarray/arsas`; tracked recursive Git tree at `d656aa4faf141ede084f2063bca3c091ca1021e5` (2026-09-25).
- Full recursive tree response: not truncated; 1,026 tracked blobs.
- Repository: `masarray/arsas`; tracked recursive Git tree at `61ad333c2f61784ee49fda04b47f036206265cbc` (2026-09-25).
- Full recursive tree response: not truncated; 1,028 tracked blobs.
- Extension inventory: 67 `.png`, `.jpg`/`.jpeg`, `.webp`, `.ico`, `.svg`, `.ttf`, `.otf`, `.woff2` or `.gif` blobs.
- This is a *path and Git-blob metadata inventory*, not an image-content, source-license, hidden-metadata, or legal review. The separately maintained source-clean gate scans tracked paths and supported text contents; it does not establish binary-image provenance.
- The machine-readable [per-file asset manifest](asset-provenance-manifest.json) records all 67 tracked asset paths, their Git blob SHA, byte size, exact-duplicate relationship and explicit review status. There are 44 unique asset blobs; 23 duplicate groups are byte-for-byte deployments of the same Git blob at two paths.
- CI validates that every tracked asset in this extension scope is represented and that its blob SHA still matches the manifest. Changing or adding an asset therefore requires an explicit provenance-manifest update rather than silently entering the tree.

| Category | Count | Scope | Origin/rights disposition |
| --- | ---: | --- | --- |
Expand Down
Loading
Loading