Commit the Alpine.js tarball in 3p/ and extract it at build time (closes #345)
The build no longer downloads Alpine.js. Its npm package tarball is committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value script/fetch-assets pinned, and the cdn.min.js inside it matches the value static/vendor.sha256 pinned. make assets extracts package/dist/cdn.min.js to the ignored static/js/alpine.min.js. make test, check, build and dev run it first, and the Dockerfile builds through make test and make build. script/fetch-assets, its Dockerfile step, static/vendor.sha256 and static/vendor_test.go are removed, along with bootstrap's curl install. Model: opus-5-5
This commit is contained in:
+3
-4
@@ -46,7 +46,6 @@ temp/
|
||||
# CI cache barrier, written into the build context by the check workflow
|
||||
.ci-fingerprint
|
||||
|
||||
# Third-party browser assets, fetched and hash-verified by
|
||||
# script/fetch-assets against static/vendor.sha256. Not committed:
|
||||
# REPO_POLICIES.md forbids minified bundles in version control.
|
||||
/static/js/alpine.min.js
|
||||
# Alpine.js, extracted by `make assets` from its tarball in 3p/, which is
|
||||
# what is committed.
|
||||
/static/js/alpine.min.js
|
||||
|
||||
Reference in New Issue
Block a user