chore: re-vendor canonical files from prompts at dd4027b (closes #472)
check / check (push) Successful in 7m32s
e2e / e2e-chrome (push) Successful in 5m30s
e2e / e2e-firefox (push) Successful in 3m56s

Copies .dockerignore, .gitignore, .prettierignore, check.yml and
REPO_POLICIES.md from sneak/prompts at dd4027b. The repo's own entries
(dist/, release/, yarn files) are kept after the canonical content.

The Dockerfile gets separate lint and test phases. Its last stage
depends on both, checks the git describe version and runs make build.
script/lint, test, check, cibuild and docker are the canonical models.
check-censored moves into the lint phase and test-verify-build into the
test phase. fmt and fmt-check fall back to the nvm-installed node. The
e2e image builds are uncached. Comments that cited the old 20-second
test cap now say 60.

Model: opus-5-5
This commit is contained in:
2026-10-06 03:44:35 +00:00
parent 88c79e7e05
commit c28e27d509
26 changed files with 708 additions and 279 deletions
+2 -2
View File
@@ -12,8 +12,8 @@
// interactive parameters, which the module hardcodes. The parameters are not
// weakened or overridden anywhere in this file — they are pinned by the "key
// derivation cost" tests, since they are the vault's only defence against an
// offline attack on a stolen blob. The suite is kept inside script/test's
// 30-second budget by sharing one encrypted fixture across the tamper cases
// offline attack on a stolen blob. The suite is kept inside the 60-second
// make test cap by sharing one encrypted fixture across the tamper cases
// instead of re-encrypting per test.
const sodium = require("libsodium-wrappers-sumo");