Skip to content

Commit 6bddbff

Browse files
Tsvetan StoychevTsvetan Stoychev
authored andcommitted
Document bundled Boomerang provenance
1 parent 74ae79f commit 6bddbff

8 files changed

Lines changed: 69 additions & 17 deletions

File tree

‎Makefile‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,7 @@ composer-audit:
9292
conventions:
9393
sh tools/verify-ascii-hyphens.sh
9494
sh tools/verify-version-consistency.sh
95+
sh tools/verify-boomerang-provenance.sh
9596

9697
translations:
9798
$(COMPOSE) run --rm --no-deps --user "$$(id -u):$$(id -g)" -e HOME=/tmp -w $(WPCLI_PLUGIN_WORKDIR) $(WPCLI_SERVICE) sh /tools/update-translations.sh .

‎README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ The plugin header version, `BASICRUM_VERSION`, WordPress `Stable tag`, top chang
6161

6262
Read [CONTRIBUTING.md](CONTRIBUTING.md) before opening a pull request. Report suspected vulnerabilities privately according to [SECURITY.md](SECURITY.md), not through a public issue.
6363

64-
Basicrum-owned code is available under the [MIT License](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.md).
64+
Basicrum-owned code is available under the [MIT License](LICENSE). Bundled third-party software retains its upstream license; see the plugin's [third-party notices](plugins/basicrum/THIRD-PARTY-NOTICES.txt).
6565

6666
## Contributors
6767

‎plugins/basicrum/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ This directory contains the installable Basicrum WordPress plugin. Runtime PHP,
99
- `src/Assets.php` controls frontend monitoring injection.
1010
- `src/Admin/Settings/` contains settings rendering and validation.
1111
- `readme.txt` is the canonical WordPress.org user documentation and changelog.
12-
- `THIRD-PARTY-NOTICES.md` records bundled software with separate licenses.
12+
- `THIRD-PARTY-NOTICES.txt` records bundled software with separate licenses.
1313
- `.distignore` defines development files excluded from releases.
1414

1515
## Development

‎plugins/basicrum/THIRD-PARTY-NOTICES.md‎

Lines changed: 0 additions & 12 deletions
This file was deleted.
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
# Third-Party Notices
2+
3+
Basicrum-owned code is licensed under the MIT License in `LICENSE.md`. The plugin also distributes the following third-party software under its own license.
4+
5+
## Boomerang 1.815.60
6+
7+
- Project: [Akamai Boomerang](https://github.com/akamai/boomerang)
8+
- Bundled file: `assets/js/boomr/boomerang-1.815.60.cutting-edge.min.js`
9+
- License: BSD License
10+
- License text: `assets/js/boomr/LICENSE.txt`
11+
- Source: commit `ead2783a33a2ce91205fe34f8fc992433faba9a2` in the `master` branch of [github.com/basicrum/boomerang](https://github.com/basicrum/boomerang), a fork of upstream [github.com/akamai/boomerang](https://github.com/akamai/boomerang)
12+
- Reproducible build: Node 12 (`.nvmrc`), `npm ci` against the committed lockfile (uglify-js 3.19.3), then `grunt clean build --build-flavor=cutting-edge --build-number=815` reproduces the bundled file byte for byte (SHA-256 `90e8a1c85949b10d43e441efc3f0545f95e4384e26ee3042344a8b2b4110589c`)
13+
- Version banner note: the banner inside the bundled file stamps the parent commit `564759ed70de7801bb64de5e2025fb6ac049ff5f` because the final source change was uncommitted when the shipped file was generated; the code content matches `ead2783a` exactly
14+
- Fork changes vs upstream: maintained commits that remove Long Tasks monitoring, remove the deprecated FID metric and rework Time to First Interaction, drop unused utility functions, and add the Basicrum configuration bootstrap
15+
16+
The Boomerang copyright notice and license remain applicable to the bundled Boomerang file. Basicrum does not relicense that file under the Basicrum MIT License.

‎plugins/basicrum/readme.txt‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,9 @@ Yes. Enable HTTP Strictness under Basicrum's Developer Settings to preserve HTTP
8686

8787
== Third-party software ==
8888

89-
Basicrum-owned code is licensed under the MIT License. The bundled Boomerang 1.815.60 library retains its upstream BSD license and copyright notices. See `THIRD-PARTY-NOTICES.md` and `assets/js/boomr/LICENSE.txt` in the plugin package.
89+
Basicrum-owned code is licensed under the MIT License. The bundled Boomerang 1.815.60 library retains its upstream BSD license and copyright notices. See `THIRD-PARTY-NOTICES.txt` and `assets/js/boomr/LICENSE.txt` in the plugin package.
90+
91+
The bundled file `assets/js/boomr/boomerang-1.815.60.cutting-edge.min.js` is a minified build of the open source Boomerang project by Akamai ([github.com/akamai/boomerang](https://github.com/akamai/boomerang)). It is byte-for-byte reproducible from public source: commit `ead2783a33a2ce91205fe34f8fc992433faba9a2` on the `master` branch of [github.com/basicrum/boomerang](https://github.com/basicrum/boomerang), built with Node 12 and the repository's Grunt tooling (`grunt clean build --build-flavor=cutting-edge --build-number=815`). The version banner inside the file stamps the parent commit `564759ed70de7801bb64de5e2025fb6ac049ff5f` because the final source change was uncommitted when the shipped file was generated; the code content matches `ead2783a` exactly. The Basicrum fork differs from upstream Boomerang by a small set of maintained commits that remove Long Tasks monitoring, remove the deprecated FID metric and rework Time to First Interaction, drop unused utility functions, and add the Basicrum configuration bootstrap.
9092

9193
== Changelog ==
9294

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
#!/bin/sh
2+
# Verify that the source commit stamped inside the bundled Boomerang build
3+
# matches the commit documented for reviewers in THIRD-PARTY-NOTICES.txt and
4+
# readme.txt, and that the version in the bundle header matches the bundled
5+
# file name. Keeps the guideline-4 source-access statement from drifting when
6+
# the bundle is upgraded.
7+
set -eu
8+
9+
PLUGIN_DIR="plugins/basicrum"
10+
BUNDLE=$(find "$PLUGIN_DIR/assets/js/boomr" -name 'boomerang-*.min.js' | head -n 1)
11+
12+
if [ -z "$BUNDLE" ]; then
13+
printf '%s\n' 'No bundled Boomerang build found.' >&2
14+
exit 1
15+
fi
16+
17+
HEADER_LINE=$(grep -m 1 'Boomerang Version:' "$BUNDLE" || true)
18+
HEADER_VERSION=$(printf '%s\n' "$HEADER_LINE" | sed -n 's/.*Boomerang Version: \([0-9.]*\) .*/\1/p')
19+
HEADER_COMMIT=$(printf '%s\n' "$HEADER_LINE" | grep -oE '[0-9a-f]{40}' | head -n 1)
20+
21+
if [ -z "$HEADER_VERSION" ] || [ -z "$HEADER_COMMIT" ]; then
22+
printf '%s\n' 'Bundled Boomerang header does not carry a version and source commit.' >&2
23+
exit 1
24+
fi
25+
26+
FILE_VERSION=$(basename "$BUNDLE" | sed -n 's/^boomerang-\([0-9.]*\)\..*/\1/p')
27+
28+
if [ "$HEADER_VERSION" != "$FILE_VERSION" ]; then
29+
printf 'Bundled Boomerang version mismatch: header %s, file name %s.\n' "$HEADER_VERSION" "$FILE_VERSION" >&2
30+
exit 1
31+
fi
32+
33+
for DOC in "$PLUGIN_DIR/THIRD-PARTY-NOTICES.txt" "$PLUGIN_DIR/readme.txt"; do
34+
if ! grep -q "$HEADER_COMMIT" "$DOC"; then
35+
printf 'Documented Boomerang source commit is stale: %s does not mention %s.\n' "$DOC" "$HEADER_COMMIT" >&2
36+
exit 1
37+
fi
38+
done
39+
40+
if [ ! -f "$PLUGIN_DIR/assets/js/boomr/LICENSE.txt" ]; then
41+
printf '%s\n' 'Boomerang LICENSE.txt is missing next to the bundled build.' >&2
42+
exit 1
43+
fi
44+
45+
printf 'Boomerang provenance check passed: %s %s.\n' "$HEADER_VERSION" "$HEADER_COMMIT"

‎tools/verify-release.sh‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ require_entry 'basicrum/basicrum.php'
3737
require_entry 'basicrum/uninstall.php'
3838
require_entry 'basicrum/readme.txt'
3939
require_entry 'basicrum/LICENSE.md'
40-
require_entry 'basicrum/THIRD-PARTY-NOTICES.md'
40+
require_entry 'basicrum/THIRD-PARTY-NOTICES.txt'
4141
require_entry 'basicrum/src/Plugin.php'
4242
require_entry 'basicrum/src/Assets.php'
4343
require_entry 'basicrum/src/ConsentIntegration.php'
@@ -107,7 +107,7 @@ if ! unzip -p "$ARCHIVE_PATH" basicrum/assets/js/boomr/LICENSE.txt | grep -Fq 'C
107107
exit 1
108108
fi
109109

110-
if ! unzip -p "$ARCHIVE_PATH" basicrum/THIRD-PARTY-NOTICES.md | grep -Fq 'Boomerang 1.815.60'; then
110+
if ! unzip -p "$ARCHIVE_PATH" basicrum/THIRD-PARTY-NOTICES.txt | grep -Fq 'Boomerang 1.815.60'; then
111111
printf '%s\n' 'Bundled software notice is incomplete.' >&2
112112
exit 1
113113
fi

0 commit comments

Comments
 (0)