Files
regex-tools/SOURCE.md

1.9 KiB

Source identity

The release ZIP is generated from the tagged repository with:

npm ci
npm run release:artifact

The build uses only pinned npm packages from package-lock.json. It performs no runtime or build-time CDN fetch. Complete preferred-form source is the tagged repository. The release archive contains compiled static assets plus legal, source-identity and attribution documents.

The engine-pack inputs and rebuild gates are documented in docs/ENGINE_BUILDS.md.

  • PCRE2 source is not vendored: the gate accepts only the pinned, clean official 10.47 checkout and Emscripten 6.0.4 compiler.
  • The Python pack is copied from the exact pinned Pyodide 314.0.3 npm package and contains its CPython 3.14.2 runtime, Python standard library, loader, WebAssembly module, metadata, checksums and licence material.
  • The Java bridge source is under engines/java/. Its bundled module is compiled against TeaVM 0.15.0's java.util.regex class library and is identified as TeaVM rather than OpenJDK.

Generated staging is ignored. Only verified runtime packs with deterministic metadata, closed file sets, checksums and exact licence/notice material are installed under public/engines/ and included in the application source and build.

The v0.3.0 release includes native browser ECMAScript, PCRE2 10.47, CPython 3.14.2 re through Pyodide 314.0.3 and TeaVM 0.15.0 java.util.regex. Go, Rust, .NET and legacy PCRE remain unimplemented. Earlier releases remain available under their historical tags and artifact coordinates. A future public artifact must bump package, manifest, tag and source identity together; it must not reuse v0.3.0.