Commit the Alpine.js tarball in 3p/ and extract it at build time (closes #345)

The build no longer downloads Alpine.js. Its npm package tarball is
committed as 3p/alpinejs-3.14.9.tgz; its sha256 matches the value
script/fetch-assets pinned, and the cdn.min.js inside it matches the
value static/vendor.sha256 pinned.

make assets extracts package/dist/cdn.min.js to the ignored
static/js/alpine.min.js. make test, check, build and dev run it first,
and the Dockerfile builds through make test and make build.
script/fetch-assets, its Dockerfile step, static/vendor.sha256 and
static/vendor_test.go are removed, along with bootstrap's curl install.

Model: opus-5-5
This commit is contained in:
2026-09-29 10:19:37 +00:00
parent 8ad2a86e4b
commit 4df11f5de8
11 changed files with 62 additions and 277 deletions
+8 -5
View File
@@ -27,10 +27,13 @@ bootstrap:
setup:
@script/setup
# Alpine.js is committed as its npm package tarball in 3p/. This extracts
# the browser build from it to where go:embed reads it; the extracted file
# is not committed.
assets:
@script/fetch-assets
tar -xzOf 3p/alpinejs-3.14.9.tgz package/dist/cdn.min.js >static/js/alpine.min.js
test:
test: assets
@script/test
lint:
@@ -42,16 +45,16 @@ fmt:
fmt-check:
@script/fmt-check
check:
check: assets
@script/check
build:
build: assets
go build -ldflags '$(strip -X main.version=$(VERSION) $(GO_LDFLAGS))' -o bin/webhooker ./cmd/webhooker
run: build
./bin/webhooker
dev:
dev: assets
go run ./cmd/webhooker
deps: