Vendor pinned prettier/format toolchain from prompts scaffold (closes #203)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
Replace the unpinned `npx prettier --tab-width 4` in `script/fmt` with the canonical toolchain vendored from `sneak/prompts`: `.prettierrc` (tabWidth 4, proseWrap always), pinned `package.json` + `yarn.lock` (prettier 3.8.1), and a `.prettierignore` that unions the scaffold entries with the repo's `*.min.js` line. `script/bootstrap` now installs a pinned node/yarn via a hash-verified nvm release archive (never curl-pipe-sh), so prettier stops being an unpinned host tool. `script/fmt` runs the pinned prettier via `.prettierrc` over `static/js/*.js` and `**/*.md`, keeping gofmt/goimports. All existing markdown is reflowed to house style; `static/js/alpine.min.js` stays byte-identical. Model: opus-4-8
This commit is contained in:
+80
-2
@@ -5,8 +5,12 @@
|
||||
# or apk (detected in that order); assumes NOTHING is present (not git,
|
||||
# make, or go). goimports is installed with `go install` at a pinned
|
||||
# version (integrity via the Go module checksum database) into
|
||||
# /usr/local/bin so it is on PATH. The linter is not installed here: it
|
||||
# runs only in Docker via script/lint, so docker is its sole prerequisite.
|
||||
# /usr/local/bin so it is on PATH. Node is used directly if installed;
|
||||
# otherwise it is installed at a pinned version via nvm (installing nvm
|
||||
# itself first, from a hash-verified release archive, never curl | sh),
|
||||
# then the pinned prettier from yarn.lock. The linter is not installed
|
||||
# here: it runs only in Docker via script/lint, so docker is its sole
|
||||
# prerequisite.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
@@ -15,6 +19,12 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
# golang.org/x/tools goimports, 2026-08-13. v0.49.0 requires Go 1.25 (matches
|
||||
# go.mod); v0.50.0 needs Go 1.26. Integrity via the Go module checksum database.
|
||||
GOIMPORTS_VERSION="v0.49.0"
|
||||
# Node/yarn toolchain, 2026-07-06.
|
||||
NODE_VERSION="22.17.0"
|
||||
NVM_VERSION="0.40.3"
|
||||
# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz
|
||||
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
|
||||
YARN_VERSION="1.22.22"
|
||||
|
||||
PKGMGR=""
|
||||
SUDO=""
|
||||
@@ -56,6 +66,21 @@ missing() {
|
||||
! command -v "$1" >/dev/null 2>&1
|
||||
}
|
||||
|
||||
# verify_sha256 <file> <expected-hash>
|
||||
verify_sha256() {
|
||||
if command -v sha256sum >/dev/null 2>&1; then
|
||||
actual="$(sha256sum "$1" | cut -d' ' -f1)"
|
||||
else
|
||||
actual="$(shasum -a 256 "$1" | cut -d' ' -f1)"
|
||||
fi
|
||||
if [ "$actual" != "$2" ]; then
|
||||
echo "bootstrap: sha256 mismatch for $1" >&2
|
||||
echo " expected: $2" >&2
|
||||
echo " actual: $actual" >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
# goimports is not packaged uniformly across nix/apt/brew/apk, so install it
|
||||
# with `go install` at a pinned version and place the binary in /usr/local/bin
|
||||
# so it is on PATH regardless of shell config. Requires go, which main
|
||||
@@ -69,6 +94,54 @@ ensure_goimports() {
|
||||
rm -rf "$tmp"
|
||||
}
|
||||
|
||||
# nvm is a bash script; run a command in a bash with nvm loaded
|
||||
nvm_sh() {
|
||||
bash -c ". \"\$HOME/.nvm/nvm.sh\" && $*"
|
||||
}
|
||||
|
||||
ensure_nvm() {
|
||||
[ -s "$HOME/.nvm/nvm.sh" ] && return 0
|
||||
# nvm prerequisites; nvm itself requires bash
|
||||
if missing bash; then pkg_install bash bash bash bash; fi
|
||||
if missing curl; then pkg_install curl curl curl curl; fi
|
||||
if missing git; then pkg_install git git git git; fi
|
||||
tmp="$(mktemp -d)"
|
||||
curl -fsSL -o "$tmp/nvm.tar.gz" \
|
||||
"https://github.com/nvm-sh/nvm/archive/refs/tags/v${NVM_VERSION}.tar.gz"
|
||||
verify_sha256 "$tmp/nvm.tar.gz" "$NVM_SHA256"
|
||||
mkdir -p "$HOME/.nvm"
|
||||
tar -xzf "$tmp/nvm.tar.gz" -C "$HOME/.nvm" --strip-components=1
|
||||
rm -rf "$tmp"
|
||||
}
|
||||
|
||||
ensure_node() {
|
||||
if ! missing node; then return 0; fi
|
||||
ensure_nvm
|
||||
nvm_sh "nvm install $NODE_VERSION"
|
||||
}
|
||||
|
||||
ensure_yarn() {
|
||||
if ! missing yarn; then return 0; fi
|
||||
if ! missing corepack; then
|
||||
corepack enable
|
||||
corepack prepare "yarn@$YARN_VERSION" --activate
|
||||
elif [ -s "$HOME/.nvm/nvm.sh" ]; then
|
||||
nvm_sh "nvm use $NODE_VERSION >/dev/null && corepack enable && \
|
||||
corepack prepare yarn@$YARN_VERSION --activate"
|
||||
else
|
||||
npm install -g "yarn@$YARN_VERSION"
|
||||
fi
|
||||
}
|
||||
|
||||
install_js_deps() {
|
||||
if missing yarn && [ -s "$HOME/.nvm/nvm.sh" ]; then
|
||||
nvm_sh "nvm use $NODE_VERSION >/dev/null && cd \"$ROOT\" && \
|
||||
yarn install --frozen-lockfile"
|
||||
else
|
||||
yarn install --frozen-lockfile
|
||||
fi
|
||||
}
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
|
||||
@@ -80,6 +153,11 @@ main() {
|
||||
if missing go; then pkg_install go golang go go; fi
|
||||
ensure_goimports
|
||||
|
||||
# Node toolchain and pinned prettier
|
||||
ensure_node
|
||||
ensure_yarn
|
||||
install_js_deps
|
||||
|
||||
# The linter runs only in Docker (script/lint). Warn, don't fail: the
|
||||
# rest of the repo works without it.
|
||||
if missing docker; then
|
||||
|
||||
Reference in New Issue
Block a user