Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ jobs:
cache: npm
- run: npm ci
- run: npm run format:check -- --base=${{ github.event.pull_request.base.sha }}
- run: npx nx run icons:check-manifest
- run: npx nx affected --target=scsslint --base=${{ github.event.pull_request.base.sha }}
- run: npx nx affected --target=lint --base=${{ github.event.pull_request.base.sha }}

Expand Down
266 changes: 266 additions & 0 deletions Process.md

Large diffs are not rendered by default.

115 changes: 111 additions & 4 deletions libs/icons/README.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,116 @@
# Covalent icons

## Provenance and legal review

Every SVG must have a matching entry under `icons` in `icons.manifest.json`.
Use the SVG path relative to this directory as the key, for example
`svgs/sample.svg`. Outlined and filled variants are separate files and require
separate entries.

Use these value rules consistently:

- Use a string only for a verified value.
- Use `null` when a string value is not known or does not exist. Do not use an
empty string, `false`, or a placeholder such as `TBD`.
- Use `true` or `false` for `is3rdParty` only after ownership has been
confirmed. (Using `null` right now while it is unknown).

The current entries marked `is3rdParty: false` are a provisional first-party
prefill. A spreadsheet still needs to be created and presented to the Design
team to confirm that these icons are owned by Teradata and are not third-party
assets. Until that review is complete, an `approved` verdict with the note
`Needs confirmation by the Design team.` and `verdictAuthor` set to
`ProvisionalAuthor` must not be treated as final Design or Legal/OSS approval.

### Manifest fields

| Field | Value | Meaning |
| -------------------- | -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `figmaUrl` | URL or `null` | Direct link to the Figma component or node. |
| `sourceUrl` | URL or `null` | Authoritative location where the original artwork was published or obtained. For third-party icons, it must point to the authoritative external source. |
| `retrievedOn` | Date | Date formatted as `YYYY-MM-DD`. Existing entries use the repository introduction commit date as a provisional proxy because the original retrieval date was not recorded. |
| `originalAuthor` | String or `null` | Original creator of the artwork. May remain `null` when Legal/OSS confirms that the creator cannot be determined. |
| `copyrightHolder` | String or `null` | Person or organization that owns the artwork copyright. Required for third-party icons. |
| `prUrl` | URL or `null` | Pull request that introduced the SVG to this repository. |
| `commitHash` | String | Commit that introduced the SVG to this repository. |
| `commitAuthor` | String | Author of that commit |
| `is3rdParty` | `true`, `false`, or `null` | Whether the artwork is owned by a party other than Teradata. `null` means ownership has not been confirmed. |
| `license` | SPDX identifier or `null` | Copyright license for the original artwork. Prefer identifiers such as `MIT`, `Apache-2.0`, `CC-BY-4.0`, `CC-BY-SA-4.0`, `CC0-1.0`, or `OFL-1.1`. |
| `licenseUrl` | URL or `null` | Authoritative page or file containing the applicable license. |
| `copyrightUrl` | URL or `null` | Authoritative copyright notice for the original artwork. |
| `trademarkUrl` | URL or `null` | Authoritative trademark notice for the represented brand. |
| `brandGuidelinesUrl` | URL or `null` | Official rules for using the brand or logo. Brand guidelines are not a copyright license. |
| `verdict` | Status | Legal/OSS decision: `approved`, `restricted`, `rejected`, `pending`, or `unknown`. Use `pending` when a review is expected and `unknown` when review status is not known. |
| `verdictNotes` | String or `null` | Conditions, restrictions, reasoning, or other context supplied by Legal/OSS. |
| `verdictAuthor` | String or `null` | Person who supplied the Legal/OSS verdict. `ProvisionalAuthor` is a temporary placeholder, not a person's name or final approval. |

Example entry:

```json
"svgs/sample.svg": {
"figmaUrl": null,
"sourceUrl": "https://example.com/official-assets/sample.svg",
"retrievedOn": "2026-09-22",
"originalAuthor": null,
"copyrightHolder": "Example Organization",
"prUrl": "https://github.com/Teradata/covalent/pull/1234",
"commitHash": "0123456789abcdef0123456789abcdef01234567",
"commitAuthor": "Example Contributor",
"is3rdParty": true,
"license": null,
"licenseUrl": null,
"copyrightUrl": null,
"trademarkUrl": null,
"brandGuidelinesUrl": null,
"verdict": "pending",
"verdictNotes": null,
"verdictAuthor": null
}
```

Third-party brand marks require legal/OSS approval before they are added to or
replaced in the font. A copied Figma component, existing repository SVG, image
search result, or font extraction is not sufficient original provenance. Do
not proceed while the verdict is `pending` or `unknown`.

Run these checks after changing an SVG or the manifest:

```sh
npx nx run icons:check-manifest
```

The check treats `svgs/` as the source inventory because those files are the
original assets for which provenance is recorded. It fails when an SVG is
missing from the manifest, when a manifest entry has no matching SVG, or when
an icon's verdict is not `approved`. Third-party entries must also include a
`sourceUrl`, `retrievedOn`, and `copyrightHolder`. Entries with `pending`,
`restricted`, `rejected`, `unknown`, or a missing verdict do not pass the
compliance gate.

The generated font variables are not used as the provenance inventory. Their
names can differ during font generation and should be validated separately as
part of the font build workflow.

### Third-party notices

`THIRD-PARTY-NOTICES.md` is distributed with the package and summarizes the
third-party assets for consumers. While an entry remains under review, the
notice must identify it as pending and must not claim a license, permission, or
approval that Legal/OSS has not confirmed.

After Legal/OSS completes a review, update both `icons.manifest.json` and the
corresponding notice section with the approved license, attribution, policy
links, usage restrictions, and disposition. The manifest is the structured
source for CI; the notice is the human-readable document shipped in the npm
package.

## Adding custom covalent icons

To integrate new custom Covalent icons, follow these steps::
After the provenance gate is complete, follow these steps:

### Upload the svg icon

1. Begin by uploading the new icon SVG file to the [svgs](https://github.com/Teradata/covalent/tree/main/libs/icons/svgs) folder. All SVG files must be stripped of extra content, including fill color. The SVG should only contain one path. Here is an example of an accepted SVG:
1. Add the approved icon SVG file to the [svgs](https://github.com/Teradata/covalent/tree/main/libs/icons/svgs) folder and complete its manifest entry. All SVG files must be stripped of extra content, including fill color. The SVG should only contain one path. Here is an example of an accepted SVG:

```css
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 16a4 4 0 1 0 0-8 4 4 0 0 0 0 8Z"/></svg>
Expand All @@ -30,7 +134,10 @@ To integrate new custom Covalent icons, follow these steps::
```css
@font-face {
font-family: 'covalent-icons';
src: url('./covalent-icons.ttf?sn0lb0') format('truetype'), url('./covalent-icons.woff?sn0lb0') format('woff'), url('./covalent-icons.svg?sn0lb0#covalent-icons') format('svg');
src:
url('./covalent-icons.ttf?sn0lb0') format('truetype'),
url('./covalent-icons.woff?sn0lb0') format('woff'),
url('./covalent-icons.svg?sn0lb0#covalent-icons') format('svg');
font-weight: normal;
font-style: normal;
font-display: block;
Expand Down Expand Up @@ -71,7 +178,7 @@ Example:

To explore the usage of the icons in Storybook:

1. Add the icon names to the `COV_ICON_LIST` in this [file](https://github.com/Teradata/covalent/blob/main/libs/components/src/icon/icon.stories.js)
1. Add the icon names to `COV_ICON_LIST` in [icon-list.ts](./icon-list.ts).

2. Run storybook

Expand Down
121 changes: 121 additions & 0 deletions libs/icons/THIRD-PARTY-NOTICES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
# Third-Party Notices

This document identifies third-party brand assets currently included in
`@covalent/icons`.

> **Status: Pending Legal/OSS review.** This file is an inventory and review
> template. It does not grant permission, establish ownership, or indicate that
> any listed use has been approved. Refer to `icons.manifest.json` for the
> current review status of each asset.

The source SVGs are converted to monochrome glyphs and distributed as part of
an icon font. Legal/OSS review must confirm whether each asset may be copied,
modified, converted to a monochrome font glyph, and redistributed in an npm
package.

## Amazon

Assets:

- `svgs/data_source_type_amazon.svg`
- `svgs/data_source_type_amazon_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Microsoft Azure

Assets:

- `svgs/data_source_type_azure.svg`
- `svgs/data_source_type_azure_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Cloudera

Assets:

- `svgs/data_source_type_cloudera.svg`
- `svgs/data_source_type_cloudera_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Git

Asset:

- `svgs/git_icon.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Microsoft HDInsight

Assets:

- `svgs/data_source_type_hdinsight.svg`
- `svgs/data_source_type_hdinsight_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Microsoft

Assets:

- `svgs/data_source_type_microsoft.svg`
- `svgs/data_source_type_microsoft_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## JupyterHub

Assets:

- `svgs/product_jupyterhub.svg`
- `svgs/product_jupyterhub_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## OpenID

Assets:

- `svgs/product_openid.svg`
- `svgs/product_openid_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Python

Asset:

- `svgs/language_python.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## SAML

Assets:

- `svgs/product_saml.svg`
- `svgs/product_saml_outlined.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**

## Slack

Asset:

- `svgs/slack.svg`

License, copyright notice, trademark policy, brand guidelines, required
attribution, and permitted usage: **Pending Legal/OSS review.**
Loading
Loading