Commit the Alpine.js tarball in 3p/ and extract it at build time (closes #345)
check / check (push) Successful in 3m42s
check / check (push) Successful in 3m42s
The build no longer downloads Alpine.js. Its npm package tarball is committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value script/fetch-assets pinned, and the cdn.min.js inside it matches the value static/vendor.sha256 pinned. make assets extracts package/dist/cdn.min.js to the ignored static/js/alpine.min.js. make test, check, build and dev run it first, and the Dockerfile builds through make test and make build. script/fetch-assets, its Dockerfile step, static/vendor.sha256 and static/vendor_test.go are removed, along with bootstrap's curl install. Model: opus-5-5
This commit is contained in:
+2
-4
@@ -3,10 +3,8 @@
|
||||
# stage of the Dockerfile.
|
||||
.git/
|
||||
bin/
|
||||
# Third-party browser assets are fetched and hash-verified inside the build by
|
||||
# script/fetch-assets. Excluding any host copy keeps a developer's working tree
|
||||
# from supplying the bytes that get shipped. The script and its
|
||||
# static/vendor.sha256 manifest stay in the context.
|
||||
# Extracted from 3p/ by `make assets` inside the build; a host copy is not
|
||||
# needed. The tarball in 3p/ must stay in the context.
|
||||
static/js/alpine.min.js
|
||||
*.md
|
||||
LICENSE
|
||||
|
||||
Reference in New Issue
Block a user